☰ Contents
AISA v2.0 / Technical documentation / case-runtime-traces.json

case-runtime-traces.json

JSON · 65702 lines · 3,990,823 bytes · wiki path 10 Architecture/ui/case-runtime-traces.json · download the raw file · cited from Case journeys — testing the architecture with real work · Case protocol — requests, records, prompts and results

Same folder: case-journeys.json · gen_wireframes.py

{
  "DC-01": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-01-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c6b892dc2a24b8988b23c09253dab3f15f219705c86de260bb030e3625efee8e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-01-1",
        "parent_task_id": "task-fixture-dc-01-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "11a137f006b6b23fde9f891ba4c4bf7d24bddf22406a1069297dea6574b7da26",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-01-2",
        "parent_task_id": "task-fixture-dc-01-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\nPrepare the bounded work: Repair only the proven stale state, then perform the authorised UI transfer; a validation exception uses the temporary-change path.\nReturn evidence sufficient to test: Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.\nReject this false completion: A REQUESTED row is still active: refuse a blind state flip or second transfer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\nPrepare the bounded work: Repair only the proven stale state, then perform the authorised UI transfer; a validation exception uses the temporary-change path.\nReturn evidence sufficient to test: Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.\nReject this false completion: A REQUESTED row is still active: refuse a blind state flip or second transfer.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "30cf994aac8fdc8c97765b405fb1e9ff9ab67b54a3ca2940fd5af1f0d2dbb85c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-01-3",
        "parent_task_id": "task-fixture-dc-01-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cdefb16a99ded3ac8e5d749179da346f26ab837269b1c32a6a5f6dcf8f29d04d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-01-4",
        "parent_task_id": "task-fixture-dc-01-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repair only the proven stale state, then perform the authorised UI transfer; a validation exception uses the temporary-change path.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repair only the proven stale state, then perform the authorised UI transfer; a validation exception uses the temporary-change path.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d091f8ee1356886ef1e61a03b71b5ad449fbbf7ff5f6d61d10db37706f198df2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-01-5",
        "parent_task_id": "task-fixture-dc-01-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "062e2e968e0baebfcab52c35a0719004dbcf5f738c3ddea312eb237540e87cec",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-01-6",
        "parent_task_id": "task-fixture-dc-01-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-01",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the verified transfer mechanism and trigger; propose a missing diagnostic branch.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the verified transfer mechanism and trigger; propose a missing diagnostic branch.\nCase: fixture-dc-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6bc9fb97b0ec429be274f32882e9b4a566b3bf58ba57d290fb671ffe90ba3257",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-01-executor",
        "parent_task_id": "task-fixture-dc-01-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-01\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-01-Spawn",
        "case_id": "fixture-dc-01",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-01-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Read the policy/annex state, transfer request and MIGR_LOG together; discriminate validation failure, stale request, lost link and infrastructure outage.\nPrepare the bounded work: Repair only the proven stale state, then perform the authorised UI transfer; a validation exception uses the temporary-change path.\nReturn evidence sufficient to test: Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.\nReject this false completion: A REQUESTED row is still active: refuse a blind state flip or second transfer.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-01-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-01-Plan",
        "case_id": "fixture-dc-01",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-01-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-01",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-01-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-01-PlanConfirmation",
        "case_id": "fixture-dc-01",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-01-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-01",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-01-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-01-Result",
        "case_id": "fixture-dc-01",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-01-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-01-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-01-Verdict",
        "case_id": "fixture-dc-01",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-01-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A REQUESTED row is still active: refuse a blind state flip or second transfer.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-01-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Repair only the proven stale state, then perform the authorised UI transfer; a validation exception uses the temporary-change path.",
      "case_specific_proof": "Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00001"
            },
            "body": {
              "module": "support",
              "description": "Stuck or failed IPAL→INSIS transfer",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00002"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00003"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Mapped policy ids and states agree across IPAL and INSIS; the intended policy prints. Reconcile a timed-out transfer before retry."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00004"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00005"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the verified transfer mechanism and trigger; propose a missing diagnostic branch."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00006"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00007"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00008"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00009"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Stuck or failed IPAL→INSIS transfer",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Fetch current transfer evidence before selecting the known branch; do not reset a still-running request."
      }
    ]
  },
  "DC-02": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-02-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "98f1e157c0ef71d8cd4599f93eb917bdc4f1a4eaba3161d2965d738a98ccc846",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-02-1",
        "parent_task_id": "task-fixture-dc-02-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "39b0865f64b0cfdb1758f4fac84df92a86f1dc95376e0bcdfe6c6ba524ba5ae0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-02-2",
        "parent_task_id": "task-fixture-dc-02-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Establish: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\nPrepare the bounded work: Apply the smallest variant-specific repair in ordered system-local operations; any revive owned by Bulstrad IT becomes an external obligation.\nReturn evidence sufficient to test: Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.\nReject this false completion: The last period remains absent although the master prints: the family is not verified.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\nPrepare the bounded work: Apply the smallest variant-specific repair in ordered system-local operations; any revive owned by Bulstrad IT becomes an external obligation.\nReturn evidence sufficient to test: Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.\nReject this false completion: The last period remains absent although the master prints: the family is not verified.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c09478792680151bc205e78c6fe91cf6057a90a90262de52812f3c1e4aad9366",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-02-3",
        "parent_task_id": "task-fixture-dc-02-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bf840da24b51866e09107941a50ae3054f5aca26df65f49e2c1f8ae6267d83ea",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-02-4",
        "parent_task_id": "task-fixture-dc-02-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the smallest variant-specific repair in ordered system-local operations; any revive owned by Bulstrad IT becomes an external obligation.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the smallest variant-specific repair in ordered system-local operations; any revive owned by Bulstrad IT becomes an external obligation.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "08ea82d3956a3b894010aedc170208351d4a58f46261b9adce5441e3b55c1723",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-02-5",
        "parent_task_id": "task-fixture-dc-02-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6871d078099bab35c0027d7337d52087c140a891bbe6c9b1b32be0900f5e1e5e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-02-6",
        "parent_task_id": "task-fixture-dc-02-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-02",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the variant discriminator and full family assertion pack; link confirmed revert-cascade recurrences to Development.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the variant discriminator and full family assertion pack; link confirmed revert-cascade recurrences to Development.\nCase: fixture-dc-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1d2926128e57093c1bd39ca96d168b5e90faaf22fba9dff8fecf8bcde6c7a545",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-02-executor",
        "parent_task_id": "task-fixture-dc-02-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-02\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-02-Spawn",
        "case_id": "fixture-dc-02",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-02-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Enumerate periods 1…N in IPAL, INSIS and MYR_POLICY. Compare states, original ids, register completeness and object pointers; select the evidenced variant.\nPrepare the bounded work: Apply the smallest variant-specific repair in ordered system-local operations; any revive owned by Bulstrad IT becomes an external obligation.\nReturn evidence sufficient to test: Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.\nReject this false completion: The last period remains absent although the master prints: the family is not verified.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-02-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-02-Plan",
        "case_id": "fixture-dc-02",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-02-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-02",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-02-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-02-PlanConfirmation",
        "case_id": "fixture-dc-02",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-02-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-02",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-02-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-02-Result",
        "case_id": "fixture-dc-02",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-02-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-02-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-02-Verdict",
        "case_id": "fixture-dc-02",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-02-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The last period remains absent although the master prints: the family is not verified.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-02-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the smallest variant-specific repair in ordered system-local operations; any revive owned by Bulstrad IT becomes an external obligation.",
      "case_specific_proof": "Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00010"
            },
            "body": {
              "module": "support",
              "description": "Multi-year 4704 family repair",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00011"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00012"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Every period has the required mapped policy/register/object relationships and prints as required; preserve cancelled history and unaffected periods."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00013"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00014"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the variant discriminator and full family assertion pack; link confirmed revert-cascade recurrences to Development."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00015"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00016"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00017"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00018"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Multi-year 4704 family repair",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Run the family inventory first; use the published variant only if its current preconditions match."
      }
    ]
  },
  "DC-03": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-03-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ff250ee6ef156350c1372a6937355bb5aaa79dadd345ea9c8739b16f68d0b54c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-03-1",
        "parent_task_id": "task-fixture-dc-03-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0477e50b4a7f73265841e94516acf91eccede8cbbef4d731ae1cb860f8f7ca29",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-03-2",
        "parent_task_id": "task-fixture-dc-03-0",
        "profile_key": "support.investigator.access",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/access",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Establish: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\nPrepare the bounded work: Perform authorised IPAL provisioning; ask the designated customer to log in in their own session. LDAP work outside scope waits on its owner.\nReturn evidence sufficient to test: Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.\nReject this false completion: LDAP exists but the IPAL account does not: do not report access restored.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.access. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\nPrepare the bounded work: Perform authorised IPAL provisioning; ask the designated customer to log in in their own session. LDAP work outside scope waits on its owner.\nReturn evidence sufficient to test: Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.\nReject this false completion: LDAP exists but the IPAL account does not: do not report access restored.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/access/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "72870e37c4087432a5f0919f7fe2a08081cea59e0f2c158e34975ae21781a252",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-access"
      },
      {
        "task_id": "task-fixture-dc-03-3",
        "parent_task_id": "task-fixture-dc-03-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "303b71ca4b6718394e30a8664259e1b6801f446f1fdf025bce885a857ee0bbb3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-03-4",
        "parent_task_id": "task-fixture-dc-03-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Perform authorised IPAL provisioning; ask the designated customer to log in in their own session. LDAP work outside scope waits on its owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Perform authorised IPAL provisioning; ask the designated customer to log in in their own session. LDAP work outside scope waits on its owner.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9d8817d429ffe1843f0491a01fd93feb4f1d8da8af9d26d76265af9fe143a978",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-03-5",
        "parent_task_id": "task-fixture-dc-03-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "eda59a40691a30baada705991140e4e0f1a354d4e7021cdb01f17e77637a6d94",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-03-6",
        "parent_task_id": "task-fixture-dc-03-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-03",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record which layer was missing and any checklist correction; a routine result can justify no new article.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record which layer was missing and any checklist correction; a routine result can justify no new article.\nCase: fixture-dc-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d767ce2039eb7d13cb40a7afc9855728a28e3fab49d6de2586108c22dc579b5d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-03-executor",
        "parent_task_id": "task-fixture-dc-03-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-03\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-03-Spawn",
        "case_id": "fixture-dc-03",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-03-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.access",
          "profile_version": 1,
          "task_text": "Establish: Resolve the person handle across LDAP, customer master and login layers; check the one-account constraint, branch and lock state.\nPrepare the bounded work: Perform authorised IPAL provisioning; ask the designated customer to log in in their own session. LDAP work outside scope waits on its owner.\nReturn evidence sufficient to test: Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.\nReject this false completion: LDAP exists but the IPAL account does not: do not report access restored.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/access",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-03-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-03-Plan",
        "case_id": "fixture-dc-03",
        "task_path": "root/support-investigator-access",
        "sender": {
          "task_id": "task-fixture-dc-03-2",
          "profile_key": "support.investigator.access",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-03",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-03-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-03-PlanConfirmation",
        "case_id": "fixture-dc-03",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-03-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-03",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-03-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-03-Result",
        "case_id": "fixture-dc-03",
        "task_path": "root/support-investigator-access",
        "sender": {
          "task_id": "task-fixture-dc-03-2",
          "profile_key": "support.investigator.access",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-03-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-03-Verdict",
        "case_id": "fixture-dc-03",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-03-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "LDAP exists but the IPAL account does not: do not report access restored.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-03-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Perform authorised IPAL provisioning; ask the designated customer to log in in their own session. LDAP work outside scope waits on its owner.",
      "case_specific_proof": "Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00019"
            },
            "body": {
              "module": "support",
              "description": "User account create, repair, deactivate",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00020"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00021"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Correct account/branch/role mapping and a successful customer login; no duplicate person account or credential sharing."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00022"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00023"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record which layer was missing and any checklist correction; a routine result can justify no new article."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00024"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00025"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00026"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00027"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: User account create, repair, deactivate",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck account existence and branch membership before reuse; existing identity becomes repair rather than create."
      }
    ]
  },
  "DC-04": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-04-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3720d491ab6a64377340add7a996c1f7e89e29fe97f4bef8b24fbd2b7348ac84",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-04-1",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d476759e8c618f6b8a2bfcdcf969418035b1fea79ea0a9ba35c868a5ad55a8f6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-04-2",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "support.investigator.access",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/access",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\nPrepare the bounded work: Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.\nReturn evidence sufficient to test: Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nReject this false completion: A new office exists but has no usable sequence: no completed provisioning verdict.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.access. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\nPrepare the bounded work: Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.\nReturn evidence sufficient to test: Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nReject this false completion: A new office exists but has no usable sequence: no completed provisioning verdict.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/access/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6514e76a0e9346a3b65f31e3c1b6285fbe088890dfc478cbbd642d1439fbe47d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-access"
      },
      {
        "task_id": "task-fixture-dc-04-3",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "support.investigator.master_data",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/master_data",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\nPrepare the bounded work: Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.\nReturn evidence sufficient to test: Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nReject this false completion: A new office exists but has no usable sequence: no completed provisioning verdict.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.master_data. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\nPrepare the bounded work: Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.\nReturn evidence sufficient to test: Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nReject this false completion: A new office exists but has no usable sequence: no completed provisioning verdict.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/master_data/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "996aed3fc5f3faf751cb4828125ee18dd5f7bfa5cfb31c31a498428d6d974f5a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-master_data"
      },
      {
        "task_id": "task-fixture-dc-04-4",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0a164c7fef441d7e6254f564c80f9055af5dae855a943f7e3e99013ba64e5755",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-04-5",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c1cef5408526b89b48f221512c5591b0e6816ce8f9fc743dcad40301a67773f7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-04-6",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "632c24c69f070d9c63b0a06366d16a140cfaa8e9269be25e94fe5ab649728447",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-04-7",
        "parent_task_id": "task-fixture-dc-04-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-04",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the complete provisioning dependency checklist, with actor ownership and scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the complete provisioning dependency checklist, with actor ownership and scope.\nCase: fixture-dc-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "884be386c04d5f15e213566d5578e0400ed91e1cc32292bb907e062e14b214bf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-04-executor",
        "parent_task_id": "task-fixture-dc-04-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-04\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-04-Spawn",
        "case_id": "fixture-dc-04",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-04-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.access",
          "profile_version": 1,
          "task_text": "Establish: Compare approved office/agent setup with INSIS agent/office records, IPAL branch/account roles and numbering prerequisites.\nPrepare the bounded work: Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.\nReturn evidence sufficient to test: Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.\nReject this false completion: A new office exists but has no usable sequence: no completed provisioning verdict.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/access",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-04-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-04-Plan",
        "case_id": "fixture-dc-04",
        "task_path": "root/support-investigator-access",
        "sender": {
          "task_id": "task-fixture-dc-04-2",
          "profile_key": "support.investigator.access",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-04",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-04-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-04-PlanConfirmation",
        "case_id": "fixture-dc-04",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-04-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-04",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-04-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-04-Result",
        "case_id": "fixture-dc-04",
        "task_path": "root/support-investigator-access",
        "sender": {
          "task_id": "task-fixture-dc-04-2",
          "profile_key": "support.investigator.access",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-04-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-04-Verdict",
        "case_id": "fixture-dc-04",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-04-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A new office exists but has no usable sequence: no completed provisioning verdict.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-04-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Wait for Bulstrad IT's missing INSIS or sequence step; then apply scoped IPAL provisioning and exact role assignments.",
      "case_specific_proof": "Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00028"
            },
            "body": {
              "module": "support",
              "description": "ИП agent, broker, office provisioning and bulk product roles",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00029"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00030"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Broker appears under the intended office and product; numbering/issuance proof uses separately authorised effects."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00031"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00032"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the complete provisioning dependency checklist, with actor ownership and scope."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00033"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00034"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00035"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00036"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: ИП agent, broker, office provisioning and bulk product roles",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect all prerequisite layers and the effective product roles; reuse cannot authorise another employee."
      }
    ]
  },
  "DC-05": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-05-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "01a36c63e7e051b8ca6472d1e19a3cb2387074d36d848aa423eecaf325731e7d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-05-1",
        "parent_task_id": "task-fixture-dc-05-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "75b2c1f2f6ffce38c7a05f7c450eb3fc27a8654dceb7911bd0731a0d242d553e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-05-2",
        "parent_task_id": "task-fixture-dc-05-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Establish: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\nPrepare the bounded work: Obtain the INSIS owner's change when required, then reconcile each IPAL layer in declared order; refresh the cache through a registered effect.\nReturn evidence sufficient to test: Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.\nReject this false completion: Four date layers match but two and the cache remain stale: fail completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\nPrepare the bounded work: Obtain the INSIS owner's change when required, then reconcile each IPAL layer in declared order; refresh the cache through a registered effect.\nReturn evidence sufficient to test: Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.\nReject this false completion: Four date layers match but two and the cache remain stale: fail completion.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7bb0863790190cd1037d4e04d9118d7b79a54e16b98eb830985a3a4095fb6a4d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-05-3",
        "parent_task_id": "task-fixture-dc-05-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f4a326ca90cf6f6ae5bae949ef7d8133051f76f96376b30937740dbc7122ce69",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-05-4",
        "parent_task_id": "task-fixture-dc-05-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Obtain the INSIS owner's change when required, then reconcile each IPAL layer in declared order; refresh the cache through a registered effect.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Obtain the INSIS owner's change when required, then reconcile each IPAL layer in declared order; refresh the cache through a registered effect.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c64c4175c27f26416ab4ed8dd22af2e4ff0961ee41b189bcca09dcc23a5a79f8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-05-5",
        "parent_task_id": "task-fixture-dc-05-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "922ac422141c9cadad4127a889dce14e5fa6853927525cb8011ac42a488405a4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-05-6",
        "parent_task_id": "task-fixture-dc-05-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-05",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the full date matrix and selector predicate; distinguish expiry from synchronisation failure.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the full date matrix and selector predicate; distinguish expiry from synchronisation failure.\nCase: fixture-dc-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4c46d72be64087267ae3d27f18b748402017b160275206ef6504705c4ae6a826",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-05-executor",
        "parent_task_id": "task-fixture-dc-05-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-05\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-05-Spawn",
        "case_id": "fixture-dc-05",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-05-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Inventory framework dates across INSIS, IPAL's six layers and cache; establish the approved new end date and selector window.\nPrepare the bounded work: Obtain the INSIS owner's change when required, then reconcile each IPAL layer in declared order; refresh the cache through a registered effect.\nReturn evidence sufficient to test: Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.\nReject this false completion: Four date layers match but two and the cache remain stale: fail completion.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-05-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-05-Plan",
        "case_id": "fixture-dc-05",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-05-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-05",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-05-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-05-PlanConfirmation",
        "case_id": "fixture-dc-05",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-05-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-05",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-05-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-05-Result",
        "case_id": "fixture-dc-05",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-05-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-05-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-05-Verdict",
        "case_id": "fixture-dc-05",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-05-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Four date layers match but two and the cache remain stale: fail completion.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-05-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Obtain the INSIS owner's change when required, then reconcile each IPAL layer in declared order; refresh the cache through a registered effect.",
      "case_specific_proof": "Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00037"
            },
            "body": {
              "module": "support",
              "description": "Cargo framework 1101 extension and date drift",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00038"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00039"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Every required date relationship holds, the framework appears in the selector, and the declared child-issue proof is obtained under its own authority."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00040"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00041"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the full date matrix and selector predicate; distinguish expiry from synchronisation failure."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00042"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00043"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00044"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00045"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Cargo framework 1101 extension and date drift",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Read the current framework and approved dates, including the selector's lookahead; never choose the largest date as business authority."
      }
    ]
  },
  "DC-06": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-06-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4ffa31752d5798a8ff8d95639eadaad486937ebd9609ac29f7a4f332e839a571",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-06-1",
        "parent_task_id": "task-fixture-dc-06-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a3e1079627fc3c5b124835dc375bb6b3fa16b0157759e9ef66c29ad024719adf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-06-2",
        "parent_task_id": "task-fixture-dc-06-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Establish: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\nPrepare the bounded work: Repoint the approved IPAL family to the confirmed master; stop for the owner's decision on any duplicate. Do not force another transfer.\nReturn evidence sufficient to test: Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.\nReject this false completion: A matching policy number points to a different INSIS master: refuse the shortcut.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\nPrepare the bounded work: Repoint the approved IPAL family to the confirmed master; stop for the owner's decision on any duplicate. Do not force another transfer.\nReturn evidence sufficient to test: Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.\nReject this false completion: A matching policy number points to a different INSIS master: refuse the shortcut.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f3848401fa5614ca3a58ecba8bb2f31843d7c029ac213d1650e7400a90234e1d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-06-3",
        "parent_task_id": "task-fixture-dc-06-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0aaffa430148dcf2d4247dfc816fe82dca286a64d6c988e37a5d99e0c34ae980",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-06-4",
        "parent_task_id": "task-fixture-dc-06-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repoint the approved IPAL family to the confirmed master; stop for the owner's decision on any duplicate. Do not force another transfer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repoint the approved IPAL family to the confirmed master; stop for the owner's decision on any duplicate. Do not force another transfer.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4c65efd9b8d5b92d169bf96394257eee99ffa514d1e6b8506c05ed90e7fd1d8b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-06-5",
        "parent_task_id": "task-fixture-dc-06-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "962d8ac7bc70f134589a55ea7feebb19ec3b12597d4ad2cccd7c828afb91c629",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-06-6",
        "parent_task_id": "task-fixture-dc-06-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-06",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the discriminator and duplicate-handling boundary in the existing sync skill.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the discriminator and duplicate-handling boundary in the existing sync skill.\nCase: fixture-dc-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "90bff88c2cbbeae9672898d6d1bbde4bcba0d94ac17bf1f95c7604b908e83178",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-06-executor",
        "parent_task_id": "task-fixture-dc-06-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-06\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-06-Spawn",
        "case_id": "fixture-dc-06",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-06-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Identify migration-import versus fresh-proposal variant, the authoritative INSIS master, covers, rate dimensions and duplicate applications.\nPrepare the bounded work: Repoint the approved IPAL family to the confirmed master; stop for the owner's decision on any duplicate. Do not force another transfer.\nReturn evidence sufficient to test: Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.\nReject this false completion: A matching policy number points to a different INSIS master: refuse the shortcut.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-06-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-06-Plan",
        "case_id": "fixture-dc-06",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-06-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-06",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-06-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-06-PlanConfirmation",
        "case_id": "fixture-dc-06",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-06-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-06",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-06-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-06-Result",
        "case_id": "fixture-dc-06",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-06-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-06-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-06-Verdict",
        "case_id": "fixture-dc-06",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-06-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A matching policy number points to a different INSIS master: refuse the shortcut.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-06-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Repoint the approved IPAL family to the confirmed master; stop for the owner's decision on any duplicate. Do not force another transfer.",
      "case_specific_proof": "Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00046"
            },
            "body": {
              "module": "support",
              "description": "Cargo framework sync or repoint so a child can issue",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00047"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00048"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Header, annex, covers, participants, rate triad and cache satisfy the framework checklist; authorised child issuance works."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00049"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00050"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the discriminator and duplicate-handling boundary in the existing sync skill."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00051"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00052"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00053"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00054"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Cargo framework sync or repoint so a child can issue",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Re-run the discriminator and full diff before reusing the small repoint operation."
      }
    ]
  },
  "DC-07": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-07-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "477da4646df442ec0d357f335b87b7034dfd2a80972ab6e9c375dd6e54ae5d43",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-07-1",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b9946efbcfc8bb45f16ed95852b92049c83f7ca755256a72d81c5fb958572cee",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-07-2",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Establish: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\nPrepare the bounded work: Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.\nReturn evidence sufficient to test: Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nReject this false completion: Customer wanted an application, not a revived policy: ask before any state transition.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\nPrepare the bounded work: Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.\nReturn evidence sufficient to test: Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nReject this false completion: Customer wanted an application, not a revived policy: ask before any state transition.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b66c2e032304a7d057fe574a41cd267070c5284f5b033036074b1364d5ef73f0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-07-3",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "support.investigator.pricing",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/pricing",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Establish: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\nPrepare the bounded work: Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.\nReturn evidence sufficient to test: Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nReject this false completion: Customer wanted an application, not a revived policy: ask before any state transition.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.pricing. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\nPrepare the bounded work: Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.\nReturn evidence sufficient to test: Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nReject this false completion: Customer wanted an application, not a revived policy: ask before any state transition.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/pricing/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "19e2bbe67ca2bff4bd617f5a1774d369bd2d0a19d321ac704d0217ec2af0a1f3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-pricing"
      },
      {
        "task_id": "task-fixture-dc-07-4",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9c74abb5c54ce639c7336e42d38be2565db826efcffbd49a6f3b58ace5797c37",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-07-5",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5ad4321c047f54236a1ccb02cecb57cbc380354686c809fd89af83d67c84fad9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-07-6",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "aebfc4a279f5ac4812a4bb142e353d1342df0893f2f2bd4bcd63fa24f132a26a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-07-7",
        "parent_task_id": "task-fixture-dc-07-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-07",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain procedure preconditions and the intent discriminator; correct a misleading restore path immediately.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain procedure preconditions and the intent discriminator; correct a misleading restore path immediately.\nCase: fixture-dc-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a9a7b008924368b89523e23200f99c4a5b9eaf650c6c442d10787aad4ace916c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-07-executor",
        "parent_task_id": "task-fixture-dc-07-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-07\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-07-Spawn",
        "case_id": "fixture-dc-07",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-07-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Clarify proposal versus issued policy; inspect claim/payment locks, premium currency, FX basis and transfer status.\nPrepare the bounded work: Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.\nReturn evidence sufficient to test: Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.\nReject this false completion: Customer wanted an application, not a revived policy: ask before any state transition.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-07-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-07-Plan",
        "case_id": "fixture-dc-07",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-07-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-07",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-07-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-07-PlanConfirmation",
        "case_id": "fixture-dc-07",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-07-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-07",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-07-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-07-Result",
        "case_id": "fixture-dc-07",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-07-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-07-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-07-Verdict",
        "case_id": "fixture-dc-07",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-07-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Customer wanted an application, not a revived policy: ask before any state transition.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-07-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Choose the authorised correction/recalculation sequence or external-owner step; record temporary state flips and their restoration.",
      "case_specific_proof": "Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00055"
            },
            "body": {
              "module": "support",
              "description": "Cargo 1103 statement and 1102/1100 certificate corrections",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00056"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00057"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Requested amounts with currency reconcile on both sides; original dates/state are restored as required and the exact document reprints."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00058"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00059"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain procedure preconditions and the intent discriminator; correct a misleading restore path immediately."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00060"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00061"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00062"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00063"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Cargo 1103 statement and 1102/1100 certificate corrections",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check paid/claimed state, currency and current procedure behaviour before using the past sequence."
      }
    ]
  },
  "DC-08": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-08-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ae9d8369f1d3208997f8c3983e995571c0bbb372f5bf0e1162e1bb3c1f231096",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-08-1",
        "parent_task_id": "task-fixture-dc-08-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e1750adeed0e60891ab6f36cd4a0586e5f6c0ab2a99ce6deef19313a38f2158b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-08-2",
        "parent_task_id": "task-fixture-dc-08-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\nPrepare the bounded work: Correct only the authorised participant relationships, using the appropriate annex or guarded row change.\nReturn evidence sufficient to test: Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.\nReject this false completion: One owner prints correctly but a second active owner leaves 200% ownership: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\nPrepare the bounded work: Correct only the authorised participant relationships, using the appropriate annex or guarded row change.\nReturn evidence sufficient to test: Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.\nReject this false completion: One owner prints correctly but a second active owner leaves 200% ownership: fail.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e6d919a14f67bc464d101748ab2323870a302e3cd48094270ec39e6b62b9a94c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-08-3",
        "parent_task_id": "task-fixture-dc-08-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "71ec167148c478aed3c79a7d34161c0c0cb6ed86d306fb6285f6ebdca5787746",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-08-4",
        "parent_task_id": "task-fixture-dc-08-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Correct only the authorised participant relationships, using the appropriate annex or guarded row change.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Correct only the authorised participant relationships, using the appropriate annex or guarded row change.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e0b03f9532f99a36b64edda2e9d1cab46e0ef2cf2e25ec2a741dd4e99230dba4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-08-5",
        "parent_task_id": "task-fixture-dc-08-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f18b90166bed47612d330f885f208e69a00d92913a4e7eee29e1af6ccd438985",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-08-6",
        "parent_task_id": "task-fixture-dc-08-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-08",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the propagation mechanism and an executable participant comparison.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the propagation mechanism and an executable participant comparison.\nCase: fixture-dc-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1ee310307c0cbd95da1b6dd127c49c5b7a3d46037af22caabc972e5fa4b98aaf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-08-executor",
        "parent_task_id": "task-fixture-dc-08-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-08\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-08-Spawn",
        "case_id": "fixture-dc-08",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-08-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Compare participant roles, ownership shares, bank linkage, source ids and annex propagation across both systems.\nPrepare the bounded work: Correct only the authorised participant relationships, using the appropriate annex or guarded row change.\nReturn evidence sufficient to test: Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.\nReject this false completion: One owner prints correctly but a second active owner leaves 200% ownership: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-08-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-08-Plan",
        "case_id": "fixture-dc-08",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-08-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-08",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-08-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-08-PlanConfirmation",
        "case_id": "fixture-dc-08",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-08-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-08",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-08-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-08-Result",
        "case_id": "fixture-dc-08",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-08-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-08-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-08-Verdict",
        "case_id": "fixture-dc-08",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-08-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "One owner prints correctly but a second active owner leaves 200% ownership: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-08-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Correct only the authorised participant relationships, using the appropriate annex or guarded row change.",
      "case_specific_proof": "Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00064"
            },
            "body": {
              "module": "support",
              "description": "Party and participant repair",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00065"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00066"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Policy and debit note show the intended parties; ownership does not exceed the expected total and obsolete active links are absent."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00067"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00068"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the propagation mechanism and an executable participant comparison."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00069"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00070"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00071"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00072"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Party and participant repair",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Rebuild the participant graph from current evidence; do not copy a previous person's ids."
      }
    ]
  },
  "DC-09": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-09-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9920316cb8f0aa4227a2c363e07286c13a0387e512ef1d88f3334a1bfb2048ab",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-09-1",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7f1ad78bf43968a848c58cd50a16781878fe31dc186831563f796eea1c8951d5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-09-2",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "support.investigator.pricing",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/pricing",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Establish: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\nPrepare the bounded work: Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.\nReturn evidence sufficient to test: Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nReject this false completion: INSIS changed but IPAL still shows the old plan: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.pricing. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\nPrepare the bounded work: Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.\nReturn evidence sufficient to test: Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nReject this false completion: INSIS changed but IPAL still shows the old plan: no completion.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/pricing/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8497786602f580d11888063a2be471a21652b9341f8e82a8488faea53583772b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-pricing"
      },
      {
        "task_id": "task-fixture-dc-09-3",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Establish: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\nPrepare the bounded work: Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.\nReturn evidence sufficient to test: Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nReject this false completion: INSIS changed but IPAL still shows the old plan: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\nPrepare the bounded work: Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.\nReturn evidence sufficient to test: Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nReject this false completion: INSIS changed but IPAL still shows the old plan: no completion.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "50dfde2a1e952ab4e33b5c929100beea71a5405f9a7c875663cc073840438470",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-09-4",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "116d7e07b80726eb6840697f5cf586d77f8a8a958f89c50cae2b7e5f5612e23f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-09-5",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5e12e150591bdcc93881d445a8dd4a13376eb58255d347d4945746a343d57bee",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-09-6",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7cf18413ae8bd4bbcf35738dab3dcacfde810d87ac54475a221cec311a7269c9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-09-7",
        "parent_task_id": "task-fixture-dc-09-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-09",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the distinction between the two splitters and the complete date assertion pack.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the distinction between the two splitters and the complete date assertion pack.\nCase: fixture-dc-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "343529967cc651576290d856f548dac54ca987398d63ba474a929a5634326f13",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-09-executor",
        "parent_task_id": "task-fixture-dc-09-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-09\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-09-Spawn",
        "case_id": "fixture-dc-09",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-09-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "task_text": "Establish: Read independent IPAL splitting and INSIS PREM_INST/PREM_INST_FRACT dates, payment state and residual annexes.\nPrepare the bounded work: Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.\nReturn evidence sufficient to test: Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.\nReject this false completion: INSIS changed but IPAL still shows the old plan: no completion.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/pricing",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-09-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-09-Plan",
        "case_id": "fixture-dc-09",
        "task_path": "root/support-investigator-pricing",
        "sender": {
          "task_id": "task-fixture-dc-09-2",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-09",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-09-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-09-PlanConfirmation",
        "case_id": "fixture-dc-09",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-09-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-09",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-09-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-09-Result",
        "case_id": "fixture-dc-09",
        "task_path": "root/support-investigator-pricing",
        "sender": {
          "task_id": "task-fixture-dc-09-2",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-09-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-09-Verdict",
        "case_id": "fixture-dc-09",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-09-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "INSIS changed but IPAL still shows the old plan: no completion.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-09-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the approved installment operation and any required counterpart update; protect paid installments and enumerate all date columns.",
      "case_specific_proof": "Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00073"
            },
            "body": {
              "module": "support",
              "description": "Installment plan and due dates",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00074"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00075"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Amounts sum to the premium in its currency; all required dates align, paid items are preserved and the payment-plan screen works."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00076"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00077"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the distinction between the two splitters and the complete date assertion pack."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00078"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00079"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00080"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00081"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Installment plan and due dates",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recompute the live payment state and scope; a prior four-installment example is not a ready row set."
      }
    ]
  },
  "DC-10": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-10-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bc162d1797e72363c07cfc052edd8fcdb8ba8f3405f43adafb5bac02d2f62a8e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-10-1",
        "parent_task_id": "task-fixture-dc-10-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "489d0d8533ae1e94bdb7acefea75e4e2693a7e1e3c8591c30e8a10e84b5b249c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-10-2",
        "parent_task_id": "task-fixture-dc-10-0",
        "profile_key": "support.investigator.pricing",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/pricing",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Establish: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\nPrepare the bounded work: Deliver a checked explanation when the result is correct; otherwise branch to a scoped data correction or Configuration handover.\nReturn evidence sufficient to test: Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.\nReject this false completion: Treating POL_PREM_RATE as the fed factor yields the wrong cause: reject the answer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.pricing. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\nPrepare the bounded work: Deliver a checked explanation when the result is correct; otherwise branch to a scoped data correction or Configuration handover.\nReturn evidence sufficient to test: Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.\nReject this false completion: Treating POL_PREM_RATE as the fed factor yields the wrong cause: reject the answer.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/pricing/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2f4c193f0baea5c72ae03c5246015f24cf4d79f16daf455957a48c2227fc02cb",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-pricing"
      },
      {
        "task_id": "task-fixture-dc-10-3",
        "parent_task_id": "task-fixture-dc-10-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7663b04339306a78585e5cffdbd7449e38616e5e5eeec0df5f4c8d9627ef0f4f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-10-4",
        "parent_task_id": "task-fixture-dc-10-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Deliver a checked explanation when the result is correct; otherwise branch to a scoped data correction or Configuration handover.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Deliver a checked explanation when the result is correct; otherwise branch to a scoped data correction or Configuration handover.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8895dce37103f4106c93edbe50757adb7c9cf8a42c090f998c700626186dd9f8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-10-5",
        "parent_task_id": "task-fixture-dc-10-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "71df1a2968cf125f9a0d0a971ae5ad00909ea08ee5bb05647d0570f04e7f68ed",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-10-6",
        "parent_task_id": "task-fixture-dc-10-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-10",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record applied-versus-fed factor distinctions and supported calculation examples.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record applied-versus-fed factor distinctions and supported calculation examples.\nCase: fixture-dc-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "117ef1afdd745aa1fcd8fbcb2e5b2d1065d3b0a86722faf5fc4868d0ee35d3ef",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-10-executor",
        "parent_task_id": "task-fixture-dc-10-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-10\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-10-Spawn",
        "case_id": "fixture-dc-10",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-10-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "task_text": "Establish: Reconstruct the fed factors, rating output, loading/discount and recorded premium; replay the current rating request.\nPrepare the bounded work: Deliver a checked explanation when the result is correct; otherwise branch to a scoped data correction or Configuration handover.\nReturn evidence sufficient to test: Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.\nReject this false completion: Treating POL_PREM_RATE as the fed factor yields the wrong cause: reject the answer.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/pricing",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-10-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-10-Plan",
        "case_id": "fixture-dc-10",
        "task_path": "root/support-investigator-pricing",
        "sender": {
          "task_id": "task-fixture-dc-10-2",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-10",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-10-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-10-PlanConfirmation",
        "case_id": "fixture-dc-10",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-10-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-10",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-10-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-10-Result",
        "case_id": "fixture-dc-10",
        "task_path": "root/support-investigator-pricing",
        "sender": {
          "task_id": "task-fixture-dc-10-2",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-10-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-10-Verdict",
        "case_id": "fixture-dc-10",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-10-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Treating POL_PREM_RATE as the fed factor yields the wrong cause: reject the answer.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-10-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Deliver a checked explanation when the result is correct; otherwise branch to a scoped data correction or Configuration handover.",
      "case_specific_proof": "Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00082"
            },
            "body": {
              "module": "support",
              "description": "Discount, loading, deductible on one policy, and „why this premium\"",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00083"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00084"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Expected premium and currency reconcile with the actual factors; a correction also requires the affected print/surface."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00085"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00086"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record applied-versus-fed factor distinctions and supported calculation examples."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00087"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00088"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00089"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00090"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Discount, loading, deductible on one policy, and „why this premium\"",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck current tariff/version and inputs before relying on the previous explanation."
      }
    ]
  },
  "DC-11": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-11-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e6426e9ac73c048c888bbde8eaed2bc247832d7adaa82ed0d94478507d869b71",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-11-1",
        "parent_task_id": "task-fixture-dc-11-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a4d278315774630da46059eedcb819577d00fb9aefde42ecf557f53fb90f9edd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-11-2",
        "parent_task_id": "task-fixture-dc-11-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Establish: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\nPrepare the bounded work: Apply a chain-scoped correction or the authorised annex path; treat any registry update as separately owned work.\nReturn evidence sufficient to test: The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.\nReject this false completion: Only the latest vehicle row is changed while an earlier consumed version remains wrong: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\nPrepare the bounded work: Apply a chain-scoped correction or the authorised annex path; treat any registry update as separately owned work.\nReturn evidence sufficient to test: The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.\nReject this false completion: Only the latest vehicle row is changed while an earlier consumed version remains wrong: fail.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "dad275846de09cf4917fbed22866f6a8a84ee7c7dfb31ec6849d6ef76ff1d215",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-11-3",
        "parent_task_id": "task-fixture-dc-11-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6c7f515637bb570ed8b040828d7edd5b2c365951b5602d36f473c262a918613f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-11-4",
        "parent_task_id": "task-fixture-dc-11-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply a chain-scoped correction or the authorised annex path; treat any registry update as separately owned work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply a chain-scoped correction or the authorised annex path; treat any registry update as separately owned work.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "625c308e5704bb4643a8adc3481f67ca1c7d73f25b9c60a51463ce15b9796544",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-11-5",
        "parent_task_id": "task-fixture-dc-11-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5180b66614e480e31b4ff4bddc80b3b96ecbb08b04fbe80523aa40d929e02a0f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-11-6",
        "parent_task_id": "task-fixture-dc-11-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-11",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the chain traversal and collision discriminators without personal or vehicle identifiers.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the chain traversal and collision discriminators without personal or vehicle identifiers.\nCase: fixture-dc-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "097a93b313888832d501490ef03b832fa8524d6bcff5d3b19628d9f0f4d03e93",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-11-executor",
        "parent_task_id": "task-fixture-dc-11-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-11\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-11-Spawn",
        "case_id": "fixture-dc-11",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-11-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Resolve the vehicle handle across every OBJ_CAR version, SR_OBJECTS mapping and INSIS O_CAR; exclude plate-keyed grafts.\nPrepare the bounded work: Apply a chain-scoped correction or the authorised annex path; treat any registry update as separately owned work.\nReturn evidence sufficient to test: The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.\nReject this false completion: Only the latest vehicle row is changed while an earlier consumed version remains wrong: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-11-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-11-Plan",
        "case_id": "fixture-dc-11",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-11-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-11",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-11-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-11-PlanConfirmation",
        "case_id": "fixture-dc-11",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-11-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-11",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-11-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-11-Result",
        "case_id": "fixture-dc-11",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-11-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-11-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-11-Verdict",
        "case_id": "fixture-dc-11",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-11-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Only the latest vehicle row is changed while an earlier consumed version remains wrong: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-11-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply a chain-scoped correction or the authorised annex path; treat any registry update as separately owned work.",
      "case_specific_proof": "The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00091"
            },
            "body": {
              "module": "support",
              "description": "Vehicle data correction (VIN, reg-no, type)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00092"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00093"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The chain-aware IPAL/INSIS comparison has zero relevant differences and the requested print/registry outcome is evidenced."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00094"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00095"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the chain traversal and collision discriminators without personal or vehicle identifiers."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00096"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00097"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00098"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00099"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Vehicle data correction (VIN, reg-no, type)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Enumerate the current chain again; reusing one row id is never the skill."
      }
    ]
  },
  "DC-12": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-12-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "40a3713e2c1bc047b8f03a22cf077dd9708d7da3e4ffbec9f62057d11528f16b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-12-1",
        "parent_task_id": "task-fixture-dc-12-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "aed55d5a998e88284b36b76bada03c30ef85fce30af0fba19e06c5083a8c628c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-12-2",
        "parent_task_id": "task-fixture-dc-12-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Establish: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\nPrepare the bounded work: Choose the permitted restoration path; where Bulstrad IT must revive INSIS, send a scoped instruction and wait for evidence.\nReturn evidence sufficient to test: The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.\nReject this false completion: External owner says done without the required state/readback: remain waiting for verification.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\nPrepare the bounded work: Choose the permitted restoration path; where Bulstrad IT must revive INSIS, send a scoped instruction and wait for evidence.\nReturn evidence sufficient to test: The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.\nReject this false completion: External owner says done without the required state/readback: remain waiting for verification.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8942ad1d6eff0199fdb0a40b29204d8aaa08362fc73a10b9480d170d552621de",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-12-3",
        "parent_task_id": "task-fixture-dc-12-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d5ee6b77ece2bf23d661b13ddc2f2d9354173c7ba0a2e42efb9d7a0a43f9d713",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-12-4",
        "parent_task_id": "task-fixture-dc-12-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Choose the permitted restoration path; where Bulstrad IT must revive INSIS, send a scoped instruction and wait for evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Choose the permitted restoration path; where Bulstrad IT must revive INSIS, send a scoped instruction and wait for evidence.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e03a3ed0bc156a373f63cbff170eefea73a9f33179e1ab37123772d5252a62a9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-12-5",
        "parent_task_id": "task-fixture-dc-12-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "45cce8c528fdfca07edef92be6a9aebeba9ccee5f65e4766f9c077c84beb4a8a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-12-6",
        "parent_task_id": "task-fixture-dc-12-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-12",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record restoration path preconditions and the original cancellation trigger.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record restoration path preconditions and the original cancellation trigger.\nCase: fixture-dc-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1ed1389fd3c0395cfeebe22468e385db85f073d0a0b0a1a16051f757551101bf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-12-executor",
        "parent_task_id": "task-fixture-dc-12-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-12\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-12-Spawn",
        "case_id": "fixture-dc-12",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-12-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Determine intended application/active state, regulatory ties, payments and whole-family cancellation effects.\nPrepare the bounded work: Choose the permitted restoration path; where Bulstrad IT must revive INSIS, send a scoped instruction and wait for evidence.\nReturn evidence sufficient to test: The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.\nReject this false completion: External owner says done without the required state/readback: remain waiting for verification.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-12-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-12-Plan",
        "case_id": "fixture-dc-12",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-12-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-12",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-12-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-12-PlanConfirmation",
        "case_id": "fixture-dc-12",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-12-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-12",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-12-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-12-Result",
        "case_id": "fixture-dc-12",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-12-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-12-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-12-Verdict",
        "case_id": "fixture-dc-12",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-12-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "External owner says done without the required state/readback: remain waiting for verification.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-12-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Choose the permitted restoration path; where Bulstrad IT must revive INSIS, send a scoped instruction and wait for evidence.",
      "case_specific_proof": "The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00100"
            },
            "body": {
              "module": "support",
              "description": "Restore a policy cancelled by mistake",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00101"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00102"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended business state is consistent across the family and both systems; the relevant customer action/print succeeds."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00103"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00104"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record restoration path preconditions and the original cancellation trigger."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00105"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00106"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00107"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00108"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Restore a policy cancelled by mistake",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck external registration/payment constraints and the requested end state before proposing a known path."
      }
    ]
  },
  "DC-13": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-13-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6729c049d1ec07af8eafe5f7b382bc4afa560ad16e313c83c16c747bc88597ed",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-13-1",
        "parent_task_id": "task-fixture-dc-13-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Classify direction of status/period drift and enumerate all affected header, annex and date layers.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Classify direction of status/period drift and enumerate all affected header, annex and date layers.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f6c539501b516557dfa189fbba06fd1c90d559cbbd25e254e808fc15227b203a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-13-2",
        "parent_task_id": "task-fixture-dc-13-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Establish: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\nPrepare the bounded work: Have the designated owner correct its system, then apply the approved counterpart reconciliation; preserve the original evidence.\nReturn evidence sufficient to test: Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.\nReject this false completion: One-sided period fix leaves the consuming print hierarchy stale: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\nPrepare the bounded work: Have the designated owner correct its system, then apply the approved counterpart reconciliation; preserve the original evidence.\nReturn evidence sufficient to test: Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.\nReject this false completion: One-sided period fix leaves the consuming print hierarchy stale: fail.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d265279fcbd8178b65609c095cbd3ccfb8f015aa5f0377a95e7d89d275962504",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-13-3",
        "parent_task_id": "task-fixture-dc-13-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "86bb1f8a98d7fed1fce63086fa1a214aafa8ce5abed3d25d94e08d3ce0b32184",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-13-4",
        "parent_task_id": "task-fixture-dc-13-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Have the designated owner correct its system, then apply the approved counterpart reconciliation; preserve the original evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Have the designated owner correct its system, then apply the approved counterpart reconciliation; preserve the original evidence.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "49ee0a4fca15768bc5f899110ea072855144ba1de08b0bbe192a52816705924e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-13-5",
        "parent_task_id": "task-fixture-dc-13-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "23b23e01ce439e9b6e680ff559867062621ef76f6a85f916c844f3f2c58c5886",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-13-6",
        "parent_task_id": "task-fixture-dc-13-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-13",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the desynchronisation class and the missing propagation edge.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the desynchronisation class and the missing propagation edge.\nCase: fixture-dc-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3ec1d598a82c7d8ef0b8f392412d38c34bbff23049fa7849757500bf7863c836",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-13-executor",
        "parent_task_id": "task-fixture-dc-13-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-13\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-13-Spawn",
        "case_id": "fixture-dc-13",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-13-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Classify direction of status/period drift and enumerate all affected header, annex and date layers.\nPrepare the bounded work: Have the designated owner correct its system, then apply the approved counterpart reconciliation; preserve the original evidence.\nReturn evidence sufficient to test: Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.\nReject this false completion: One-sided period fix leaves the consuming print hierarchy stale: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-13-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-13-Plan",
        "case_id": "fixture-dc-13",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-13-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-13",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-13-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-13-PlanConfirmation",
        "case_id": "fixture-dc-13",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-13-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-13",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-13-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-13-Result",
        "case_id": "fixture-dc-13",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-13-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-13-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-13-Verdict",
        "case_id": "fixture-dc-13",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-13-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "One-sided period fix leaves the consuming print hierarchy stale: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-13-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Have the designated owner correct its system, then apply the approved counterpart reconciliation; preserve the original evidence.",
      "case_specific_proof": "Mapped states and periods agree on both sides and on the printed document, with every declared layer checked.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00109"
            },
            "body": {
              "module": "support",
              "description": "IPAL↔INSIS status or period desync after a cancel, a termination or a one-sided correction",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00110"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00111"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Mapped states and periods agree on both sides and on the printed document, with every declared layer checked."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00112"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00113"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the desynchronisation class and the missing propagation edge."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00114"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00115"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00116"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00117"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: IPAL↔INSIS status or period desync after a cancel, a termination or a one-sided correction",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Determine which side changed first from current evidence; never pick a system solely because it was authoritative last time."
      }
    ]
  },
  "DC-14": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-14-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b739d738f0c649d6a47d7d60dea219c6a4ec377e6bc768b0497d66e2e8ff06a2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-14-1",
        "parent_task_id": "task-fixture-dc-14-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5b4dfaf88ec881f4e7d31300ef539da0391bb2610d6e31611809440a5552262d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-14-2",
        "parent_task_id": "task-fixture-dc-14-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Establish: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\nPrepare the bounded work: Reconcile the IPAL header, period hierarchy and integration caches to the proven master, or deliver the scoped external packet.\nReturn evidence sufficient to test: IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.\nReject this false completion: The Jira mirror and notification count as two clean uses, or only the header is fixed: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\nPrepare the bounded work: Reconcile the IPAL header, period hierarchy and integration caches to the proven master, or deliver the scoped external packet.\nReturn evidence sufficient to test: IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.\nReject this false completion: The Jira mirror and notification count as two clean uses, or only the header is fixed: reject.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7d2c9827fd9dc58d230b21804259898b1114e884451db81882dba1cc47b7bd16",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-14-3",
        "parent_task_id": "task-fixture-dc-14-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0799f97cf56666614968d417330f03c119940060d6b4561fb7427da4487a5991",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-14-4",
        "parent_task_id": "task-fixture-dc-14-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Reconcile the IPAL header, period hierarchy and integration caches to the proven master, or deliver the scoped external packet.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Reconcile the IPAL header, period hierarchy and integration caches to the proven master, or deliver the scoped external packet.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0f34cfc2e943e311f3ccbdebc4492fd3948b1495c7b4a1d61f819d64d1ddca03",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-14-5",
        "parent_task_id": "task-fixture-dc-14-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "98adeea47abc982e385313e066aea936fd8791ceb9ef6e17d90c5d25057c9676",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-14-6",
        "parent_task_id": "task-fixture-dc-14-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-14",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the timeout mechanism and three-layer assertion pack once per canonical request.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the timeout mechanism and three-layer assertion pack once per canonical request.\nCase: fixture-dc-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "837bff9010b52bd5d3b1c7cc700c3024db5fba985673c7e839a3c078f966fe05",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-14-executor",
        "parent_task_id": "task-fixture-dc-14-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-14\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-14-Spawn",
        "case_id": "fixture-dc-14",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-14-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Deduplicate the OTRS/mail/Jira aliases; identify the real INSIS policy versus its sibling/orphan after GFIRM timeout.\nPrepare the bounded work: Reconcile the IPAL header, period hierarchy and integration caches to the proven master, or deliver the scoped external packet.\nReturn evidence sufficient to test: IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.\nReject this false completion: The Jira mirror and notification count as two clean uses, or only the header is fixed: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-14-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-14-Plan",
        "case_id": "fixture-dc-14",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-14-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-14",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-14-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-14-PlanConfirmation",
        "case_id": "fixture-dc-14",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-14-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-14",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-14-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-14-Result",
        "case_id": "fixture-dc-14",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-14-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-14-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-14-Verdict",
        "case_id": "fixture-dc-14",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-14-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The Jira mirror and notification count as two clean uses, or only the header is fixed: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-14-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Reconcile the IPAL header, period hierarchy and integration caches to the proven master, or deliver the scoped external packet.",
      "case_specific_proof": "IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00118"
            },
            "body": {
              "module": "support",
              "description": "„Куха полица\" (4710 ГФ / GFIRM timeout)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00119"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00120"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: IPAL search shows the intended active policy, all three layers agree and the required registry status is evidenced."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00121"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00122"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the timeout mechanism and three-layer assertion pack once per canonical request."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00123"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00124"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00125"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00126"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: „Куха полица\" (4710 ГФ / GFIRM timeout)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Retrieve through the customer's Bulgarian phrase and trigger, then find the live authoritative sibling again."
      }
    ]
  },
  "DC-15": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-15-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b838803d1946ee856c48b294efb650b10f4ef49c37f1daee6c9c7eb23545f924",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-15-1",
        "parent_task_id": "task-fixture-dc-15-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8944f9cad665b9c3d259fff86bb7b0b9b772d83e16b53680fcd67ce7b57b463e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-15-2",
        "parent_task_id": "task-fixture-dc-15-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Establish: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\nPrepare the bounded work: Send a supported explanation or owner instruction; a necessary period correction branches to its exact gated operation.\nReturn evidence sufficient to test: The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.\nReject this false completion: A stale response is reused as current cover/validity proof: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\nPrepare the bounded work: Send a supported explanation or owner instruction; a necessary period correction branches to its exact gated operation.\nReturn evidence sufficient to test: The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.\nReject this false completion: A stale response is reused as current cover/validity proof: reject.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b73b4e229ecdb037d937ba5c5e3c119c592ec6db3917d6c9128ce81f495368f2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-15-3",
        "parent_task_id": "task-fixture-dc-15-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "495bc7055318ba8e7b9b8f66db2d881c2e4715454f7d4d9ca45e27bad6ec8b78",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-15-4",
        "parent_task_id": "task-fixture-dc-15-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Send a supported explanation or owner instruction; a necessary period correction branches to its exact gated operation.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Send a supported explanation or owner instruction; a necessary period correction branches to its exact gated operation.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d2fe7ecf57eb82b6551a240b01761946c7abaf90a03cb46eac139bf61344793e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-15-5",
        "parent_task_id": "task-fixture-dc-15-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "60bb2578c2e2696e09361a56e90624af71c5fdd7452df63650bc8fc62e687ae8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-15-6",
        "parent_task_id": "task-fixture-dc-15-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-15",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the response-code discriminator and its observed system version.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the response-code discriminator and its observed system version.\nCase: fixture-dc-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0b001b9c9e07e8c985901c12aae26c676c838c1fea9dfe320ece7ed219b5216a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-15-executor",
        "parent_task_id": "task-fixture-dc-15-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-15\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-15-Spawn",
        "case_id": "fixture-dc-15",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-15-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Decode the actual registry response and compare MTPL/green-card/sticker periods and current status.\nPrepare the bounded work: Send a supported explanation or owner instruction; a necessary period correction branches to its exact gated operation.\nReturn evidence sufficient to test: The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.\nReject this false completion: A stale response is reused as current cover/validity proof: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-15-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-15-Plan",
        "case_id": "fixture-dc-15",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-15-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-15",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-15-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-15-PlanConfirmation",
        "case_id": "fixture-dc-15",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-15-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-15",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-15-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-15-Result",
        "case_id": "fixture-dc-15",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-15-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-15-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-15-Verdict",
        "case_id": "fixture-dc-15",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-15-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A stale response is reused as current cover/validity proof: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-15-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Send a supported explanation or owner instruction; a necessary period correction branches to its exact gated operation.",
      "case_specific_proof": "The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00127"
            },
            "body": {
              "module": "support",
              "description": "ГФ / ЕИСОУКР status, duplicate MTPL, green card and sticker validity",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00128"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00129"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The answer reflects current registry evidence; operational resolution requires the promised issue/status outcome."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00130"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00131"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the response-code discriminator and its observed system version."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00132"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00133"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00134"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00135"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: ГФ / ЕИСОУКР status, duplicate MTPL, green card and sticker validity",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Query current status and recheck code meaning; do not infer today's insurance state from an older answer."
      }
    ]
  },
  "DC-16": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-16-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "67f853a8923cec3bc7c38c78b08dc59041669e8b91cac533510a8467794d60d2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-16-1",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "272393560a47ba22ff391fe682fc5c257b60dbf67162b9e2d3aa4e64e30fb991",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-16-2",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "support.investigator.pricing",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/pricing",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\nPrepare the bounded work: Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.\nReturn evidence sufficient to test: Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nReject this false completion: A copied percentage fixes one row but violates the effective rule: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.pricing. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\nPrepare the bounded work: Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.\nReturn evidence sufficient to test: Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nReject this false completion: A copied percentage fixes one row but violates the effective rule: fail.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/pricing/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "23da38ad2eeccc6861b885c54b658c0f8df024f8986ac15796ca71cb55c11304",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-pricing"
      },
      {
        "task_id": "task-fixture-dc-16-3",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "support.investigator.access",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/access",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\nPrepare the bounded work: Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.\nReturn evidence sufficient to test: Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nReject this false completion: A copied percentage fixes one row but violates the effective rule: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.access. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\nPrepare the bounded work: Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.\nReturn evidence sufficient to test: Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nReject this false completion: A copied percentage fixes one row but violates the effective rule: fail.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/access/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "db3971f696a4107ea7166f8331029ebd5f3bf3b12dd97064bc72f3d8e8f799f8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-access"
      },
      {
        "task_id": "task-fixture-dc-16-4",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b07b2a1abd2352ead37842b3a0fe4b84b6411131b70b81dd65649856efacf883",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-16-5",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "525f0219ce9853fe788eb81f0025c2457e005cf4ca8030459bb1a43616a98b4a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-16-6",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "549155d6ed0eaaf896916717437a94bc6ec32e77c0583bf8cf0cab076911b93e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-16-7",
        "parent_task_id": "task-fixture-dc-16-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-16",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record whether the cause was data, missing rule or propagation code; link its durable correction.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record whether the cause was data, missing rule or propagation code; link its durable correction.\nCase: fixture-dc-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "25dca922c0913f0777676977ebdf4a5c1eb6488d57fcb99edf44f1969c7861a3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-16-executor",
        "parent_task_id": "task-fixture-dc-16-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-16\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-16-Spawn",
        "case_id": "fixture-dc-16",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-16-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "task_text": "Establish: Compare IPAL agent attributes, INSIS commission rows, rate rules and the relevant update predicate.\nPrepare the bounded work: Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.\nReturn evidence sufficient to test: Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.\nReject this false completion: A copied percentage fixes one row but violates the effective rule: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/pricing",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-16-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-16-Plan",
        "case_id": "fixture-dc-16",
        "task_path": "root/support-investigator-pricing",
        "sender": {
          "task_id": "task-fixture-dc-16-2",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-16",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-16-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-16-PlanConfirmation",
        "case_id": "fixture-dc-16",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-16-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-16",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-16-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-16-Result",
        "case_id": "fixture-dc-16",
        "task_path": "root/support-investigator-pricing",
        "sender": {
          "task_id": "task-fixture-dc-16-2",
          "profile_key": "support.investigator.pricing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-16-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-16-Verdict",
        "case_id": "fixture-dc-16",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-16-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A copied percentage fixes one row but violates the effective rule: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-16-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply authorised policy-specific commission correction or wait for the owning party; a permanent rule gap goes to Configuration.",
      "case_specific_proof": "Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00136"
            },
            "body": {
              "module": "support",
              "description": "Commission and self-retention",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00137"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00138"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Recomputed commission/self-retention amounts with currency match the approved rule and affected policy records."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00139"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00140"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record whether the cause was data, missing rule or propagation code; link its durable correction."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00141"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00142"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00143"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00144"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Commission and self-retention",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck current agent contract/rate and policy state before using the formula."
      }
    ]
  },
  "DC-17": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-17-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cb3f0f9870731a90cc5ab642952b295bfa53bb2a0a3f5f8a0538e93afee59270",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-17-1",
        "parent_task_id": "task-fixture-dc-17-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "de01fabcca44619c1b4281645baea294fbb9ab7513ccc6a9477cd3fe4de6f27b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-17-2",
        "parent_task_id": "task-fixture-dc-17-0",
        "profile_key": "support.investigator.printing",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/printing",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\nPrepare the bounded work: Repair the proven data gap; configuration registration goes to Configuration and an external BI template stays with its owner.\nReturn evidence sufficient to test: Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.\nReject this false completion: The template is blamed while required source data is absent: reject the route.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.printing. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\nPrepare the bounded work: Repair the proven data gap; configuration registration goes to Configuration and an external BI template stays with its owner.\nReturn evidence sufficient to test: Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.\nReject this false completion: The template is blamed while required source data is absent: reject the route.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/printing/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "37c610efcc8c9af5ae0652102a37cf74b062e00f50e71630bf0000e0e30ba1a0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-printing"
      },
      {
        "task_id": "task-fixture-dc-17-3",
        "parent_task_id": "task-fixture-dc-17-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "800b0806c7de96834ed9a123da7c9481584d20c52938a356303ff274b614282c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-17-4",
        "parent_task_id": "task-fixture-dc-17-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repair the proven data gap; configuration registration goes to Configuration and an external BI template stays with its owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repair the proven data gap; configuration registration goes to Configuration and an external BI template stays with its owner.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0481095591d1d1e9bae11813b717bb86ab9dd9a86317ca373a800975fa6c85b7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-17-5",
        "parent_task_id": "task-fixture-dc-17-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a0460601bfc8f159b37fc6ea772e73b76b98814c68f9ea4b5ddc665f3ef4a55c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-17-6",
        "parent_task_id": "task-fixture-dc-17-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-17",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain invocation-first diagnostics and route the recurring data-population defect to its owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain invocation-first diagnostics and route the recurring data-population defect to its owner.\nCase: fixture-dc-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "85d26d07f981bf622a118558be21c039edb8361500fc7a92c9ed0f0dfc699217",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-17-executor",
        "parent_task_id": "task-fixture-dc-17-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-17\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-17-Spawn",
        "case_id": "fixture-dc-17",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-17-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.printing",
          "profile_version": 1,
          "task_text": "Establish: Prove the print engine was invoked; inspect exact parameters, INSIS data, currency rate, register readiness and template version.\nPrepare the bounded work: Repair the proven data gap; configuration registration goes to Configuration and an external BI template stays with its owner.\nReturn evidence sufficient to test: Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.\nReject this false completion: The template is blamed while required source data is absent: reject the route.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/printing",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-17-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-17-Plan",
        "case_id": "fixture-dc-17",
        "task_path": "root/support-investigator-printing",
        "sender": {
          "task_id": "task-fixture-dc-17-2",
          "profile_key": "support.investigator.printing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-17",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-17-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-17-PlanConfirmation",
        "case_id": "fixture-dc-17",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-17-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-17",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-17-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-17-Result",
        "case_id": "fixture-dc-17",
        "task_path": "root/support-investigator-printing",
        "sender": {
          "task_id": "task-fixture-dc-17-2",
          "profile_key": "support.investigator.printing",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-17-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-17-Verdict",
        "case_id": "fixture-dc-17",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-17-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The template is blamed while required source data is absent: reject the route.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-17-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Repair the proven data gap; configuration registration goes to Configuration and an external BI template stays with its owner.",
      "case_specific_proof": "Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00145"
            },
            "body": {
              "module": "support",
              "description": "The print is right, the data is wrong",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00146"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00147"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Reproduce the exact requested document, with the expected limit/office/rate and no unintended extra documents."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00148"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00149"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain invocation-first diagnostics and route the recurring data-population defect to its owner."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00150"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00151"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00152"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00153"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: The print is right, the data is wrong",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check invocation and current data before considering a template fix."
      }
    ]
  },
  "DC-18": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-18-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e601ac86c47d9d64aecfd97ca3df795822a2f0a080b8ae6b00658b017c37b660",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-18-1",
        "parent_task_id": "task-fixture-dc-18-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b1160a231f602fba8e66e4b0fbe050240ab84aac4d6ac2ddff7fac0e28bccaa6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-18-2",
        "parent_task_id": "task-fixture-dc-18-0",
        "profile_key": "support.investigator.master_data",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/master_data",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Establish: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\nPrepare the bounded work: Use the published BSO/car skill where applicable; product-factor semantics route to Configuration. Shared additions require their full scope gate.\nReturn evidence sufficient to test: The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.\nReject this false completion: The label exists but the dependent value is invisible or wrong for another product: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.master_data. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\nPrepare the bounded work: Use the published BSO/car skill where applicable; product-factor semantics route to Configuration. Shared additions require their full scope gate.\nReturn evidence sufficient to test: The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.\nReject this false completion: The label exists but the dependent value is invisible or wrong for another product: fail.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/master_data/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a2350f97d28ad16c54d5f9628b2c5e83be695e723c4c27c864596a58f5385039",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-master_data"
      },
      {
        "task_id": "task-fixture-dc-18-3",
        "parent_task_id": "task-fixture-dc-18-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5eeaa55874229f4f9deca388d446e6ab0ee64660c867c47ce71a68a24c4f9573",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-18-4",
        "parent_task_id": "task-fixture-dc-18-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Use the published BSO/car skill where applicable; product-factor semantics route to Configuration. Shared additions require their full scope gate.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Use the published BSO/car skill where applicable; product-factor semantics route to Configuration. Shared additions require their full scope gate.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "afeb3b2765a0b111861e3f815c03c7f1993e56721259466a354c315305ac7d7b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-18-5",
        "parent_task_id": "task-fixture-dc-18-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c5f15a1d3196591a4fcb15f87f531697c2fb4a2548e2eb87c7ad019d6c578b46",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-18-6",
        "parent_task_id": "task-fixture-dc-18-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-18",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record catalogue dependencies and any missing check in the owned skill.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record catalogue dependencies and any missing check in the owned skill.\nCase: fixture-dc-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0933dcdd390c664719148ba77f27e7377196d49de7c4d68b3c02305eced80fc5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-18-executor",
        "parent_task_id": "task-fixture-dc-18-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-18\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-18-Spawn",
        "case_id": "fixture-dc-18",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-18-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "task_text": "Establish: Check existing values, business keys, dependent catalogues, label scope and applicable external nomenclatures.\nPrepare the bounded work: Use the published BSO/car skill where applicable; product-factor semantics route to Configuration. Shared additions require their full scope gate.\nReturn evidence sufficient to test: The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.\nReject this false completion: The label exists but the dependent value is invisible or wrong for another product: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/master_data",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-18-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-18-Plan",
        "case_id": "fixture-dc-18",
        "task_path": "root/support-investigator-master_data",
        "sender": {
          "task_id": "task-fixture-dc-18-2",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-18",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-18-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-18-PlanConfirmation",
        "case_id": "fixture-dc-18",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-18-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-18",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-18-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-18-Result",
        "case_id": "fixture-dc-18",
        "task_path": "root/support-investigator-master_data",
        "sender": {
          "task_id": "task-fixture-dc-18-2",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-18-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-18-Verdict",
        "case_id": "fixture-dc-18",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-18-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The label exists but the dependent value is invisible or wrong for another product: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-18-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Use the published BSO/car skill where applicable; product-factor semantics route to Configuration. Shared additions require their full scope gate.",
      "case_specific_proof": "The intended value appears under the correct dependency and works in the consuming action; duplicates are absent.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00154"
            },
            "body": {
              "module": "support",
              "description": "Master-data adds: BSO ranges, vehicle make/model, LOV and pricing-factor values, авариен комисар, НКИД",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00155"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00156"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended value appears under the correct dependency and works in the consuming action; duplicates are absent."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00157"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00158"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record catalogue dependencies and any missing check in the owned skill."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00159"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00160"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00161"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00162"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Master-data adds: BSO ranges, vehicle make/model, LOV and pricing-factor values, авариен комисар, НКИД",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Search by business key and context first; an already-present value may need visibility repair, not insertion."
      }
    ]
  },
  "DC-19": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-19-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "af37b65b0d6d41873b35c42701e5aab6ddcba2cf220272156d8cf14b5193f115",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-19-1",
        "parent_task_id": "task-fixture-dc-19-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b14cf7c2041d6fd97d88ba751bc1ebac7095e99c8d22c1741f378912c7312beb",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-19-2",
        "parent_task_id": "task-fixture-dc-19-0",
        "profile_key": "support.resolution",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/methodologies",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Establish: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\nPrepare the bounded work: Persist and review the relax/action/restore chain before applying; await the operator's authorised transfer and restore under H7.\nReturn evidence sufficient to test: The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.\nReject this false completion: Deadline expires or the customer disappears: restoration remains a live obligation.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.resolution. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\nPrepare the bounded work: Persist and review the relax/action/restore chain before applying; await the operator's authorised transfer and restore under H7.\nReturn evidence sufficient to test: The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.\nReject this false completion: Deadline expires or the customer disappears: restoration remains a live obligation.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/methodologies/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b6769175d772430778da0d39938bc23d56fe0d9658b26c3362bdb1c137d64ef3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-resolution"
      },
      {
        "task_id": "task-fixture-dc-19-3",
        "parent_task_id": "task-fixture-dc-19-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f053fa16617311f67aaaae157cb35a86cc2e9e617547541d5bd970f45d696660",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-19-4",
        "parent_task_id": "task-fixture-dc-19-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Persist and review the relax/action/restore chain before applying; await the operator's authorised transfer and restore under H7.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Persist and review the relax/action/restore chain before applying; await the operator's authorised transfer and restore under H7.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c431b1bf4cab426dd3c05424a5cd6b289fad2b9d5eb5656a5c23f7e0045e4a0e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-19-5",
        "parent_task_id": "task-fixture-dc-19-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7314dde6f11cb54c53fe1b9a8e1f5402f307ae69738ed757113af8598d175220",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-19-6",
        "parent_task_id": "task-fixture-dc-19-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-19",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the repeated rule/trigger and link a proposed permanent Configuration or Development correction.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the repeated rule/trigger and link a proposed permanent Configuration or Development correction.\nCase: fixture-dc-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1c4fe4222c1c91cebdce67d613b14af6cc721a0aeb055914ee2641d20fc43782",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-19-executor",
        "parent_task_id": "task-fixture-dc-19-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-19\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-19-Spawn",
        "case_id": "fixture-dc-19",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-19-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "task_text": "Establish: Identify the actual blocking IPAL/ABACUS rule and its full audience, including existing bypasses.\nPrepare the bounded work: Persist and review the relax/action/restore chain before applying; await the operator's authorised transfer and restore under H7.\nReturn evidence sufficient to test: The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.\nReject this false completion: Deadline expires or the customer disappears: restoration remains a live obligation.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/methodologies",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-19-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-19-Plan",
        "case_id": "fixture-dc-19",
        "task_path": "root/support-resolution",
        "sender": {
          "task_id": "task-fixture-dc-19-2",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-19",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-19-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-19-PlanConfirmation",
        "case_id": "fixture-dc-19",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-19-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-19",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-19-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-19-Result",
        "case_id": "fixture-dc-19",
        "task_path": "root/support-resolution",
        "sender": {
          "task_id": "task-fixture-dc-19-2",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-19-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-19-Verdict",
        "case_id": "fixture-dc-19",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-19-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Deadline expires or the customer disappears: restoration remains a live obligation.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-19-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Persist and review the relax/action/restore chain before applying; await the operator's authorised transfer and restore under H7.",
      "case_specific_proof": "The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00163"
            },
            "body": {
              "module": "support",
              "description": "Validation threshold relax and revert — the desk-executed configuration cell",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00164"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00165"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended action succeeds and the original baseline is restored; verify the twin rule and any shared impact."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00166"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00167"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the repeated rule/trigger and link a proposed permanent Configuration or Development correction."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00168"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00169"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00170"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00171"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Validation threshold relax and revert — the desk-executed configuration cell",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check earlier exceptions and their permanent-fix status; do not silently accumulate another indefinite relaxation."
      }
    ]
  },
  "DC-20": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-20-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The consuming search returns the right business entity and no dangling references or unintended deletions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The consuming search returns the right business entity and no dangling references or unintended deletions remain.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "304050efe69291560918e8c391f18ac86602eca4c024787a384d697bac2b7a39",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-20-1",
        "parent_task_id": "task-fixture-dc-20-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "866a33160a6f9379125b30a29466bb9725ff5f0d925710dc2ad206ebf95ee008",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-20-2",
        "parent_task_id": "task-fixture-dc-20-0",
        "profile_key": "support.investigator.master_data",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/master_data",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\nPrepare the bounded work: Propose the minimal authorised merge/delete only after dependency counts and survivor identity are proved.\nReturn evidence sufficient to test: The consuming search returns the right business entity and no dangling references or unintended deletions remain.\nReject this false completion: Zero local footprint or a changed dependent count invalidates the old packet.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.master_data. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\nPrepare the bounded work: Propose the minimal authorised merge/delete only after dependency counts and survivor identity are proved.\nReturn evidence sufficient to test: The consuming search returns the right business entity and no dangling references or unintended deletions remain.\nReject this false completion: Zero local footprint or a changed dependent count invalidates the old packet.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/master_data/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "be28f796ddbf73992308e426ebda92072bce38eb8d1034936eef2c28c2f1d7e2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-master_data"
      },
      {
        "task_id": "task-fixture-dc-20-3",
        "parent_task_id": "task-fixture-dc-20-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The consuming search returns the right business entity and no dangling references or unintended deletions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The consuming search returns the right business entity and no dangling references or unintended deletions remain.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e06fbcfb06de1cc3657e53190dafab39ac11b4fc2f59c0b2f5e0fbbf7d81da12",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-20-4",
        "parent_task_id": "task-fixture-dc-20-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Propose the minimal authorised merge/delete only after dependency counts and survivor identity are proved.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Propose the minimal authorised merge/delete only after dependency counts and survivor identity are proved.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "101a930bb7e6b908b3fd39ced310a1aee02947d8dd3576645760b36e5ce58b2c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-20-5",
        "parent_task_id": "task-fixture-dc-20-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The consuming search returns the right business entity and no dangling references or unintended deletions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The consuming search returns the right business entity and no dangling references or unintended deletions remain.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d6dfb7951f07442bf60b87db4469af8b7aa639927318655663f3d61347d09b4a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-20-6",
        "parent_task_id": "task-fixture-dc-20-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-20",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the footprint-first procedure and any changed duplicate discriminator.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the footprint-first procedure and any changed duplicate discriminator.\nCase: fixture-dc-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "43e0704f771baecc1b26372d4dcd069286ebfaae0eae469038ad51f314cb7849",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-20-executor",
        "parent_task_id": "task-fixture-dc-20-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-20\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-20-Spawn",
        "case_id": "fixture-dc-20",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-20-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "task_text": "Establish: Read the full customer footprint and consuming seek query; distinguish a real duplicate from a harmless INSIS mirror.\nPrepare the bounded work: Propose the minimal authorised merge/delete only after dependency counts and survivor identity are proved.\nReturn evidence sufficient to test: The consuming search returns the right business entity and no dangling references or unintended deletions remain.\nReject this false completion: Zero local footprint or a changed dependent count invalidates the old packet.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/master_data",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-20-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-20-Plan",
        "case_id": "fixture-dc-20",
        "task_path": "root/support-investigator-master_data",
        "sender": {
          "task_id": "task-fixture-dc-20-2",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-20",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-20-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-20-PlanConfirmation",
        "case_id": "fixture-dc-20",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-20-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-20",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-20-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-20-Result",
        "case_id": "fixture-dc-20",
        "task_path": "root/support-investigator-master_data",
        "sender": {
          "task_id": "task-fixture-dc-20-2",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-20-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-20-Verdict",
        "case_id": "fixture-dc-20",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-20-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Zero local footprint or a changed dependent count invalidates the old packet.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-20-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Propose the minimal authorised merge/delete only after dependency counts and survivor identity are proved.",
      "case_specific_proof": "The consuming search returns the right business entity and no dangling references or unintended deletions remain.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00172"
            },
            "body": {
              "module": "support",
              "description": "Customer master duplicate and person data",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00173"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00174"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The consuming search returns the right business entity and no dangling references or unintended deletions remain."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00175"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00176"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the footprint-first procedure and any changed duplicate discriminator."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00177"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00178"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00179"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00180"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Customer master duplicate and person data",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Requery the footprint; an INSIS merge is evidence, not an instruction to mirror deletion blindly."
      }
    ]
  },
  "DC-21": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-21-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Per-item transfer and target-policy proof; already-completed items are not transferred again.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Per-item transfer and target-policy proof; already-completed items are not transferred again.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0d6da0478df7af7d715e654afc6dcbc831eef82690e5b9f002e5243fd1211b47",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-21-1",
        "parent_task_id": "task-fixture-dc-21-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ce2baab4da63d05222f4807b00b5e7e26bd766b7115fb67640c67d8947fe6180",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-21-2",
        "parent_task_id": "task-fixture-dc-21-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Establish: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\nPrepare the bounded work: Ask the authorised operator to perform routine UI transfers; isolate exceptions into their appropriate repair path.\nReturn evidence sufficient to test: Per-item transfer and target-policy proof; already-completed items are not transferred again.\nReject this false completion: One success is used to close all 45 items: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\nPrepare the bounded work: Ask the authorised operator to perform routine UI transfers; isolate exceptions into their appropriate repair path.\nReturn evidence sufficient to test: Per-item transfer and target-policy proof; already-completed items are not transferred again.\nReject this false completion: One success is used to close all 45 items: reject.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c53b7f2dc1b56d6fdfb09f2c5870c8d0b7f7f5bbd5b4dabbf9896d202330a397",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-21-3",
        "parent_task_id": "task-fixture-dc-21-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Per-item transfer and target-policy proof; already-completed items are not transferred again.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Per-item transfer and target-policy proof; already-completed items are not transferred again.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "908499ea0dd5724eccc0d3e80dbddaec78e58bdf5878cfd378f781764882386a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-21-4",
        "parent_task_id": "task-fixture-dc-21-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Ask the authorised operator to perform routine UI transfers; isolate exceptions into their appropriate repair path.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Ask the authorised operator to perform routine UI transfers; isolate exceptions into their appropriate repair path.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a270342b4865a5aa5f9e51168e4f1843a2e1273544a2d5e9a72c006f8781ca70",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-21-5",
        "parent_task_id": "task-fixture-dc-21-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Per-item transfer and target-policy proof; already-completed items are not transferred again.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Per-item transfer and target-policy proof; already-completed items are not transferred again.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "005b493151df8e3421fd0f25db2fdbdec0d01629ee33307b5da26a6a971d15ba",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-21-6",
        "parent_task_id": "task-fixture-dc-21-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-21",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the backlog classifications and per-item outcome; routine success can teach nothing new.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the backlog classifications and per-item outcome; routine success can teach nothing new.\nCase: fixture-dc-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c8d159ded6643ad3b38a130826d78585f52b25157fcd604394f985f44c2265d3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-21-executor",
        "parent_task_id": "task-fixture-dc-21-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-21\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-21-Spawn",
        "case_id": "fixture-dc-21",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-21-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Classify each backlog item as routine second signature, active transfer, validation failure or outage residue.\nPrepare the bounded work: Ask the authorised operator to perform routine UI transfers; isolate exceptions into their appropriate repair path.\nReturn evidence sufficient to test: Per-item transfer and target-policy proof; already-completed items are not transferred again.\nReject this false completion: One success is used to close all 45 items: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-21-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-21-Plan",
        "case_id": "fixture-dc-21",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-21-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-21",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-21-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-21-PlanConfirmation",
        "case_id": "fixture-dc-21",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-21-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-21",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-21-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-21-Result",
        "case_id": "fixture-dc-21",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-21-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-21-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-21-Verdict",
        "case_id": "fixture-dc-21",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-21-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "One success is used to close all 45 items: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-21-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Ask the authorised operator to perform routine UI transfers; isolate exceptions into their appropriate repair path.",
      "case_specific_proof": "Per-item transfer and target-policy proof; already-completed items are not transferred again.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00181"
            },
            "body": {
              "module": "support",
              "description": "Routine transfer and backlog reconciliation",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00182"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00183"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Per-item transfer and target-policy proof; already-completed items are not transferred again."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00184"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00185"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the backlog classifications and per-item outcome; routine success can teach nothing new."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00186"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00187"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00188"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00189"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Routine transfer and backlog reconciliation",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Retrieve the classifier and recheck every current item, rather than applying one batch state flip."
      }
    ]
  },
  "DC-22": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-22-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cd852e012ca53f6e408599470898dbcbf4ae9acc9e07defdc1d65f6fccc48f62",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-22-1",
        "parent_task_id": "task-fixture-dc-22-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Retrieve the relevant active precedent and check the current system/version and the exact customer question.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Retrieve the relevant active precedent and check the current system/version and the exact customer question.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f00e46c8afd2fcaa5f7317f0f3bbe272ac9d507a9cd6fe203b3bed8b6d820849",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-22-2",
        "parent_task_id": "task-fixture-dc-22-0",
        "profile_key": "support.resolution",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/methodologies",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Establish: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\nPrepare the bounded work: Deliver the checked answer through the send gate; if a customer action is required, persist its waiting/proof obligation.\nReturn evidence sufficient to test: The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.\nReject this false completion: The old article is found but its current precondition is false: investigate instead.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.resolution. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\nPrepare the bounded work: Deliver the checked answer through the send gate; if a customer action is required, persist its waiting/proof obligation.\nReturn evidence sufficient to test: The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.\nReject this false completion: The old article is found but its current precondition is false: investigate instead.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/methodologies/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6265a9915da9b91fc67fa7c843adb611ee0d571e96e0a4789fb5136c45332f18",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-resolution"
      },
      {
        "task_id": "task-fixture-dc-22-3",
        "parent_task_id": "task-fixture-dc-22-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "92ac92804abfc8f17768abf3442d9f95103e262bad1e498e9d93b7ea476542f1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-22-4",
        "parent_task_id": "task-fixture-dc-22-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Deliver the checked answer through the send gate; if a customer action is required, persist its waiting/proof obligation.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Deliver the checked answer through the send gate; if a customer action is required, persist its waiting/proof obligation.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2ec48bd56cd28d5ff3bcef3a3fe56bd3d320fcf13a51930ff4c2c15744416679",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-22-5",
        "parent_task_id": "task-fixture-dc-22-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "14b7ce6b05f3a96f77fda359e65f4910a2a9f7963c0ffe90a26e5dceaee6f14c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-22-6",
        "parent_task_id": "task-fixture-dc-22-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-22",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record successful use or contradiction and a justified no-new-knowledge decision where appropriate.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record successful use or contradiction and a justified no-new-knowledge decision where appropriate.\nCase: fixture-dc-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "68b86a75546ceaa36dcee2b41b147dd1bde6883ed91537e78353f65c25b4252c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-22-executor",
        "parent_task_id": "task-fixture-dc-22-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-22\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-22-Spawn",
        "case_id": "fixture-dc-22",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-22-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "task_text": "Establish: Retrieve the relevant active precedent and check the current system/version and the exact customer question.\nPrepare the bounded work: Deliver the checked answer through the send gate; if a customer action is required, persist its waiting/proof obligation.\nReturn evidence sufficient to test: The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.\nReject this false completion: The old article is found but its current precondition is false: investigate instead.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/methodologies",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-22-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-22-Plan",
        "case_id": "fixture-dc-22",
        "task_path": "root/support-resolution",
        "sender": {
          "task_id": "task-fixture-dc-22-2",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-22",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-22-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-22-PlanConfirmation",
        "case_id": "fixture-dc-22",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-22-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-22",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-22-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-22-Result",
        "case_id": "fixture-dc-22",
        "task_path": "root/support-resolution",
        "sender": {
          "task_id": "task-fixture-dc-22-2",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-22-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-22-Verdict",
        "case_id": "fixture-dc-22",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-22-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The old article is found but its current precondition is false: investigate instead.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-22-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Deliver the checked answer through the send gate; if a customer action is required, persist its waiting/proof obligation.",
      "case_specific_proof": "The answer's current factual basis is retained; action requests additionally require the declared outcome evidence.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00190"
            },
            "body": {
              "module": "support",
              "description": "Answers from memory: how-to, cannot reproduce, explanation, lookup",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00191"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00192"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The answer's current factual basis is retained; action requests additionally require the declared outcome evidence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00193"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00194"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record successful use or contradiction and a justified no-new-knowledge decision where appropriate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00195"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00196"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00197"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00198"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Answers from memory: how-to, cannot reproduce, explanation, lookup",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Start with the reviewed precedent, then repeat the smallest necessary staleness check."
      }
    ]
  },
  "DC-23": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-23-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The promised annex, print or commission result exists; earlier successful steps were not duplicated.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The promised annex, print or commission result exists; earlier successful steps were not duplicated.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "64fb760abb9226b4ae41aa8fae6d1896c666232be87629a55d4781aac05456b1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-23-1",
        "parent_task_id": "task-fixture-dc-23-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a022ae403aedffe8a2d2ef60e6381a782a4f1811be07ec63eaa11641c9c756b5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-23-2",
        "parent_task_id": "task-fixture-dc-23-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Establish: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\nPrepare the bounded work: Repair only the missing step under its own permission; replay nothing merely because the earlier automation stopped.\nReturn evidence sufficient to test: The promised annex, print or commission result exists; earlier successful steps were not duplicated.\nReject this false completion: Re-running the whole batch duplicates an existing document or registration: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\nPrepare the bounded work: Repair only the missing step under its own permission; replay nothing merely because the earlier automation stopped.\nReturn evidence sufficient to test: The promised annex, print or commission result exists; earlier successful steps were not duplicated.\nReject this false completion: Re-running the whole batch duplicates an existing document or registration: reject.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "37919fa8768ddfb0276358161daaeaf71717c9922af264c607295680e521bc16",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-23-3",
        "parent_task_id": "task-fixture-dc-23-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The promised annex, print or commission result exists; earlier successful steps were not duplicated.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The promised annex, print or commission result exists; earlier successful steps were not duplicated.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "881cd6a023e6b31b5f81ecb1aa132378f65ccde295926bb207115a9a53ea2c96",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-23-4",
        "parent_task_id": "task-fixture-dc-23-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repair only the missing step under its own permission; replay nothing merely because the earlier automation stopped.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Repair only the missing step under its own permission; replay nothing merely because the earlier automation stopped.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "163e38da62420ff937f68c6818dd8d7fcb3741f59228230177f24f7cba7ec526",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-23-5",
        "parent_task_id": "task-fixture-dc-23-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The promised annex, print or commission result exists; earlier successful steps were not duplicated.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The promised annex, print or commission result exists; earlier successful steps were not duplicated.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "05262efa56062101cf25e6875c880cb741804e953ea3366efede9a67a276a15e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-23-6",
        "parent_task_id": "task-fixture-dc-23-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-23",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the automation's partial-effect mechanism and the missing completion assertion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record the automation's partial-effect mechanism and the missing completion assertion.\nCase: fixture-dc-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9f9cf37c267ab56249dc1eb3fcf6efc362bfbd0813fc43cc515f8af4edac236a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-23-executor",
        "parent_task_id": "task-fixture-dc-23-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-23\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-23-Spawn",
        "case_id": "fixture-dc-23",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-23-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Inspect the Beth operation batch, completed steps and missing downstream work; determine what already landed.\nPrepare the bounded work: Repair only the missing step under its own permission; replay nothing merely because the earlier automation stopped.\nReturn evidence sufficient to test: The promised annex, print or commission result exists; earlier successful steps were not duplicated.\nReject this false completion: Re-running the whole batch duplicates an existing document or registration: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-23-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-23-Plan",
        "case_id": "fixture-dc-23",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-23-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-23",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-23-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-23-PlanConfirmation",
        "case_id": "fixture-dc-23",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-23-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-23",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-23-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-23-Result",
        "case_id": "fixture-dc-23",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-23-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-23-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-23-Verdict",
        "case_id": "fixture-dc-23",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-23-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Re-running the whole batch duplicates an existing document or registration: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-23-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Repair only the missing step under its own permission; replay nothing merely because the earlier automation stopped.",
      "case_specific_proof": "The promised annex, print or commission result exists; earlier successful steps were not duplicated.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00199"
            },
            "body": {
              "module": "support",
              "description": "Repair after a Beth-executed change",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00200"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00201"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The promised annex, print or commission result exists; earlier successful steps were not duplicated."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00202"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00203"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record the automation's partial-effect mechanism and the missing completion assertion."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00204"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00205"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00206"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00207"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Repair after a Beth-executed change",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Reconcile the actual operation log before selecting a recovery step."
      }
    ]
  },
  "DC-24": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dc-24-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f354fcff8633a15f84d2d8dc5714747e0da5e52e04eb2723ed2cd5f780310078",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dc-24-1",
        "parent_task_id": "task-fixture-dc-24-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bae9ac4c876482216f42225213fe0929780b9b52bac22ac84d37f8411d9c0656",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dc-24-2",
        "parent_task_id": "task-fixture-dc-24-0",
        "profile_key": "support.investigator.transfers",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/transfers",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Establish: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\nPrepare the bounded work: Wait for healthy dependencies, then repair each affected policy/workflow using current preconditions and its own effect identity.\nReturn evidence sufficient to test: Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.\nReject this false completion: A green service probe closes half-written policies without reconciliation: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.transfers. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\nPrepare the bounded work: Wait for healthy dependencies, then repair each affected policy/workflow using current preconditions and its own effect identity.\nReturn evidence sufficient to test: Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.\nReject this false completion: A green service probe closes half-written policies without reconciliation: reject.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/transfers/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d366b4374fd39ac3c11e05e9fed4968ff58bda4ee45d1b670423b04b8d63b8f8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-transfers"
      },
      {
        "task_id": "task-fixture-dc-24-3",
        "parent_task_id": "task-fixture-dc-24-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cf99e9abcc825c6049a9094ff71affc27d6c114e0c72d852e01968d038cfacc5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dc-24-4",
        "parent_task_id": "task-fixture-dc-24-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Wait for healthy dependencies, then repair each affected policy/workflow using current preconditions and its own effect identity.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Wait for healthy dependencies, then repair each affected policy/workflow using current preconditions and its own effect identity.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9778a11797eebe8fc041313efdbda01550ad63ed208303184783e8f2b65e3e76",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dc-24-5",
        "parent_task_id": "task-fixture-dc-24-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c697682d4a490e3f7dd739b2dd247dc832c2b1c992a4a696c9f2efeefcf5925e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dc-24-6",
        "parent_task_id": "task-fixture-dc-24-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DC-24",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the incident trigger and recovery classifier; keep infrastructure and per-policy outcomes distinct.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the incident trigger and recovery classifier; keep infrastructure and per-policy outcomes distinct.\nCase: fixture-dc-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 40 Support/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3a79d8b9b568a78e79a32f382e12e7eeb385462fa05f6fa8b13a6ee0e4389075",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dc-24-executor",
        "parent_task_id": "task-fixture-dc-24-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dc-24\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dc-24-Spawn",
        "case_id": "fixture-dc-24",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-24-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "task_text": "Establish: Confirm infrastructure recovery through its owner and classify per-policy partial effects from the outage.\nPrepare the bounded work: Wait for healthy dependencies, then repair each affected policy/workflow using current preconditions and its own effect identity.\nReturn evidence sufficient to test: Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.\nReject this false completion: A green service probe closes half-written policies without reconciliation: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/transfers",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dc-24-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dc-24-Plan",
        "case_id": "fixture-dc-24",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-24-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-24",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dc-24-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dc-24-PlanConfirmation",
        "case_id": "fixture-dc-24",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-dc-24-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dc-24",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dc-24-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dc-24-Result",
        "case_id": "fixture-dc-24",
        "task_path": "root/support-investigator-transfers",
        "sender": {
          "task_id": "task-fixture-dc-24-2",
          "profile_key": "support.investigator.transfers",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dc-24-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dc-24-Verdict",
        "case_id": "fixture-dc-24",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dc-24-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A green service probe closes half-written policies without reconciliation: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dc-24-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Wait for healthy dependencies, then repair each affected policy/workflow using current preconditions and its own effect identity.",
      "case_specific_proof": "Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00208"
            },
            "body": {
              "module": "support",
              "description": "Aftermath of an infrastructure incident",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00209"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00210"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Every declared item has policy/workflow and customer-surface proof; service health alone does not satisfy it."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00211"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00212"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the incident trigger and recovery classifier; keep infrastructure and per-policy outcomes distinct."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00213"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00214"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00215"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00216"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Aftermath of an infrastructure incident",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check current incident state and reconcile each item before applying the recovery skill."
      }
    ]
  },
  "DV-01": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-01-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4687cc7600026111c49f82f9ef96b7197459807a05f82c09564bf751fa10f6f5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-01-1",
        "parent_task_id": "task-fixture-dv-01-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5190a4f587f22f407b2d6c76ef3e44277f2fdfb87d6baa0d8b319e872016dd1b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-01-2",
        "parent_task_id": "task-fixture-dv-01-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5624cc1f427e34b4d35877db99027d97fa9cea80ceb1d0993606ece534aee05b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-01-3",
        "parent_task_id": "task-fixture-dv-01-2",
        "profile_key": "source.camunda_developer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\nPrepare the bounded work: Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.\nReturn evidence sufficient to test: The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nReject this false completion: The image is new but Camunda still serves the old process: no delivery.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.camunda_developer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\nPrepare the bounded work: Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.\nReturn evidence sufficient to test: The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nReject this false completion: The image is new but Camunda still serves the old process: no delivery.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b595bb64c1088e42d4f95b9c154c7da92edf592a1056a2747d7491aded686bed",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-camunda_developer"
      },
      {
        "task_id": "task-fixture-dv-01-4",
        "parent_task_id": "task-fixture-dv-01-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\nPrepare the bounded work: Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.\nReturn evidence sufficient to test: The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nReject this false completion: The image is new but Camunda still serves the old process: no delivery.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\nPrepare the bounded work: Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.\nReturn evidence sufficient to test: The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nReject this false completion: The image is new but Camunda still serves the old process: no delivery.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a51c8d209ea2c6ae68cefd99fac719a4ae537511d549f527179fc6302c0e47db",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-01-5",
        "parent_task_id": "task-fixture-dv-01-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "858e4e0a5513e67f34c2b4d17872e5b729e6b3ee967579e5b356db35415f18bd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-01-6",
        "parent_task_id": "task-fixture-dv-01-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "889107d2a92a854ac8396549b095ada27160b2cd693dafa409a585c76d11f930",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-01-7",
        "parent_task_id": "task-fixture-dv-01-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6a1212de14eece6aff4cca2bad1627cee06b2157051eb0374410069df1329149",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-01-8",
        "parent_task_id": "task-fixture-dv-01-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-01",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain process placement and deployment/version traps under the backend owner; propose missing process checks.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain process placement and deployment/version traps under the backend owner; propose missing process checks.\nCase: fixture-dv-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "23d5d06c942dc363d7471beb02c907c3d88c393dea4dff630aaa341133563f24",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-01-tests",
        "parent_task_id": "task-fixture-dv-01-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-01-executor",
        "parent_task_id": "task-fixture-dv-01-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-01\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-01-Spawn",
        "case_id": "fixture-dv-01",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-01-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.camunda_developer",
          "profile_version": 1,
          "task_text": "Establish: Pin the product's actual process, user-task code, deployed BPMN and both repository lineages; identify the Configuration dependency.\nPrepare the bounded work: Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.\nReturn evidence sufficient to test: The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.\nReject this false completion: The image is new but Camunda still serves the old process: no delivery.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-01-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-01-Plan",
        "case_id": "fixture-dv-01",
        "task_path": "root/source-root/source-camunda_developer",
        "sender": {
          "task_id": "task-fixture-dv-01-3",
          "profile_key": "source.camunda_developer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-01",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-01-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-01-PlanConfirmation",
        "case_id": "fixture-dv-01",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-01-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-01",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-01-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-01-Result",
        "case_id": "fixture-dv-01",
        "task_path": "root/source-root/source-camunda_developer",
        "sender": {
          "task_id": "task-fixture-dv-01-3",
          "profile_key": "source.camunda_developer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-01-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-01-Verdict",
        "case_id": "fixture-dv-01",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-01-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The image is new but Camunda still serves the old process: no delivery.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-01-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement and test the process change, review the commit series, deploy the declared Core image/BPMN set and record the job identity.",
      "case_specific_proof": "The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00217"
            },
            "body": {
              "module": "support",
              "description": "Product process (BPMN + user tasks) for a new or changed product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00218"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00219"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The target serves the expected process version and an authorised test instance reaches the requested stage; old in-flight instances are accounted for."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00220"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00221"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain process placement and deployment/version traps under the backend owner; propose missing process checks."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00222"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00223"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00224"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00225"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Product process (BPMN + user tasks) for a new or changed product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect the live process and branch counterpart before adapting the previous implementation."
      }
    ]
  },
  "DV-02": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-02-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "532fc5f632db87adea6005a00ca8ca0147b75c6510309418755a8a5b8a02efc5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-02-1",
        "parent_task_id": "task-fixture-dv-02-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "fafaa6f409a644a5c952f75fd1d842f9662e2bb481b26b25eb504338866b8346",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-02-2",
        "parent_task_id": "task-fixture-dv-02-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b0f60c549f9b5620e6d74abbe48d3f7aab301c8875d5a1b38868f6529dc9bd0b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-02-3",
        "parent_task_id": "task-fixture-dv-02-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Establish: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\nPrepare the bounded work: Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.\nReturn evidence sufficient to test: The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nReject this false completion: C# is deployed but a configuration toggle, PL/SQL body or BI template is missing: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\nPrepare the bounded work: Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.\nReturn evidence sufficient to test: The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nReject this false completion: C# is deployed but a configuration toggle, PL/SQL body or BI template is missing: fail.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "40d75a75da6945906b93b23a6316a1b9875a27a68e7343cbdd73c086ffc6fb14",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-02-4",
        "parent_task_id": "task-fixture-dv-02-2",
        "profile_key": "source.implementer.db-plsql",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/db-plsql",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Establish: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\nPrepare the bounded work: Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.\nReturn evidence sufficient to test: The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nReject this false completion: C# is deployed but a configuration toggle, PL/SQL body or BI template is missing: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.db-plsql. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\nPrepare the bounded work: Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.\nReturn evidence sufficient to test: The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nReject this false completion: C# is deployed but a configuration toggle, PL/SQL body or BI template is missing: fail.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/db-plsql/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2218e07d79299cc5abf4ba2e86e8deba368dd8227c0a9b8038111983ab3f3143",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-db-plsql"
      },
      {
        "task_id": "task-fixture-dv-02-5",
        "parent_task_id": "task-fixture-dv-02-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "23d7814885b1807734d1341e237953e28c377776cbfb16cace71a811f4f6b58c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-02-6",
        "parent_task_id": "task-fixture-dv-02-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2c63cc2cb9edd4ead446a3ea4d01b3990c5826c3d27bce9326baa176877012c4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-02-7",
        "parent_task_id": "task-fixture-dv-02-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f02d7c4fdba5c483819dab13f60e332c10ca53990c499734f022edf3ae8b5235",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-02-8",
        "parent_task_id": "task-fixture-dv-02-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-02",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain selector/registration boundaries and fail-open counterexamples; record missing release components.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain selector/registration boundaries and fail-open counterexamples; record missing release components.\nCase: fixture-dv-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "fdd4f35798e4e6cdd79c9ed6fb62974445b60bcbc82271676284e11d823628e0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-02-tests",
        "parent_task_id": "task-fixture-dv-02-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-02-executor",
        "parent_task_id": "task-fixture-dv-02-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-02\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-02-Spawn",
        "case_id": "fixture-dv-02",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-02-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Separate print-registration rows, C# selection, shared library, POLQRY and externally owned BI template behaviour.\nPrepare the bounded work: Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.\nReturn evidence sufficient to test: The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.\nReject this false completion: C# is deployed but a configuration toggle, PL/SQL body or BI template is missing: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-02-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-02-Plan",
        "case_id": "fixture-dv-02",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-02-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-02",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-02-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-02-PlanConfirmation",
        "case_id": "fixture-dv-02",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-02-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-02",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-02-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-02-Result",
        "case_id": "fixture-dv-02",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-02-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-02-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-02-Verdict",
        "case_id": "fixture-dv-02",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-02-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "C# is deployed but a configuration toggle, PL/SQL body or BI template is missing: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-02-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Use coordinated Configuration/Development work and external template obligations; release in the compatibility order of the exact components.",
      "case_specific_proof": "The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00226"
            },
            "body": {
              "module": "support",
              "description": "Print-document rules and BI Publisher parameters",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00227"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00228"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The exact document and parameters are correct on target; negative selectors do not produce unwanted documents and the deployed package is not a stub."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00229"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00230"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain selector/registration boundaries and fail-open counterexamples; record missing release components."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00231"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00232"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00233"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00234"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Print-document rules and BI Publisher parameters",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check current invocation and all component versions before using the old print pattern."
      }
    ]
  },
  "DV-03": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-03-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ceb3e3ed77a288a4bf7d8c182f62f7c04b8f31c9acec2c36ee237374edd76118",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-03-1",
        "parent_task_id": "task-fixture-dv-03-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8c8c95db4ce54d664791586b45acd8cc951982bcd3d9383cc3e07c85cbe897f6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-03-2",
        "parent_task_id": "task-fixture-dv-03-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "16daf77a69e437bb23fa72ca2f501210ac8e0d88e55c62ec69e62b5c5b291b6c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-03-3",
        "parent_task_id": "task-fixture-dv-03-2",
        "profile_key": "source.planner",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Establish: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\nPrepare the bounded work: Return an explicit programme referral with accountable ownership; accept only separately scoped implementation cases under the current charter.\nReturn evidence sufficient to test: The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nReject this false completion: 84 commits are treated as one small extension with one generic done test: reject scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.planner. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\nPrepare the bounded work: Return an explicit programme referral with accountable ownership; accept only separately scoped implementation cases under the current charter.\nReturn evidence sufficient to test: The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nReject this false completion: 84 commits are treated as one small extension with one generic done test: reject scope.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "11eb4001976483f004068b6baf76ec008c35050b5c9e33c74ae5a38f411e4e5d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-planner"
      },
      {
        "task_id": "task-fixture-dv-03-4",
        "parent_task_id": "task-fixture-dv-03-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5bb06367b95cfac5bf07e04176b81abd49d18e2b9bafd814de36f4595d588229",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dv-03-5",
        "parent_task_id": "task-fixture-dv-03-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Return an explicit programme referral with accountable ownership; accept only separately scoped implementation cases under the current charter.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Return an explicit programme referral with accountable ownership; accept only separately scoped implementation cases under the current charter.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "949e01b5ce0ba40af65508179f2a9b4062d6e0d5f3957dbf86549afc216c8eca",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-03-6",
        "parent_task_id": "task-fixture-dv-03-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3e6ba4c9cdc6209754dc2b5e8acf8f580c12139ed5a0e952dbae8a418747f9dc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-03-7",
        "parent_task_id": "task-fixture-dv-03-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-03",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain intake/placement evidence for bounded future slices, not a fictional completed-module example.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain intake/placement evidence for bounded future slices, not a fictional completed-module example.\nCase: fixture-dv-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8f847c1da655db49c51aadcb52245ac42db48fbc205a78dd5e58bb5eb96f87bf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-03-tests",
        "parent_task_id": "task-fixture-dv-03-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-03-executor",
        "parent_task_id": "task-fixture-dv-03-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-03\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-03-Spawn",
        "case_id": "fixture-dv-03",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-03-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.planner",
          "profile_version": 1,
          "task_text": "Establish: Record the reinsurance capability request and programme owner; distinguish a bounded defect from the ongoing module stream.\nPrepare the bounded work: Return an explicit programme referral with accountable ownership; accept only separately scoped implementation cases under the current charter.\nReturn evidence sufficient to test: The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.\nReject this false completion: 84 commits are treated as one small extension with one generic done test: reject scope.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-03-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-03-Plan",
        "case_id": "fixture-dv-03",
        "task_path": "root/source-root/source-planner",
        "sender": {
          "task_id": "task-fixture-dv-03-3",
          "profile_key": "source.planner",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-03",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-03-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-03-PlanConfirmation",
        "case_id": "fixture-dv-03",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-03-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-03",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-03-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-03-Result",
        "case_id": "fixture-dv-03",
        "task_path": "root/source-root/source-planner",
        "sender": {
          "task_id": "task-fixture-dv-03-3",
          "profile_key": "source.planner",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-03-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-03-Verdict",
        "case_id": "fixture-dv-03",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dv-03-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "84 commits are treated as one small extension with one generic done test: reject scope.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-03-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Return an explicit programme referral with accountable ownership; accept only separately scoped implementation cases under the current charter.",
      "case_specific_proof": "The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00235"
            },
            "body": {
              "module": "support",
              "description": "The reinsurance stream — a customer-funded capability",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00236"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00237"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The referral/scope decision is acknowledged; no claim that facultative, treaty, reports and e-mail capability have been delivered."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00238"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00239"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain intake/placement evidence for bounded future slices, not a fictional completed-module example."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00240"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00241"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00242"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00243"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: The reinsurance stream — a customer-funded capability",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Route a new bounded reinsurance fix normally; recognise another programme-scale request before implementation."
      }
    ]
  },
  "DV-04": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-04-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6bd039fe8987b25d716e3d8b7b00a31b3e47dd9889ca8acca503ab6eb1dfe221",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-04-1",
        "parent_task_id": "task-fixture-dv-04-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d2cf380e7b0068b9a999443930569c3fbe77828b4a0e2537116467475e4fb28f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-04-2",
        "parent_task_id": "task-fixture-dv-04-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3a0fbb99e31b2331d760edaad5d4d3161d56616775874a64350f5e54e27dbb10",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-04-3",
        "parent_task_id": "task-fixture-dv-04-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\nPrepare the bounded work: Implement at the approved seam; package changed libraries and rebuild all declared consumers with companion rows where needed.\nReturn evidence sufficient to test: Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nReject this false completion: NuGet is published but an active consumer still runs the old rule: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\nPrepare the bounded work: Implement at the approved seam; package changed libraries and rebuild all declared consumers with companion rows where needed.\nReturn evidence sufficient to test: Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nReject this false completion: NuGet is published but an active consumer still runs the old rule: fail.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3f2c6a2afcc1aa0b410f87793588ab07e66643b41ddec6a0aaba2cf159526902",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-04-4",
        "parent_task_id": "task-fixture-dv-04-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f208c8d546ac25fa369654923159c437cc134839ed42ce3bf5697c9845b525e2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-04-5",
        "parent_task_id": "task-fixture-dv-04-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement at the approved seam; package changed libraries and rebuild all declared consumers with companion rows where needed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement at the approved seam; package changed libraries and rebuild all declared consumers with companion rows where needed.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "41da6d6a4ec7de3a791e53b63bf54d60ef1454bb99228af6f78fd7d40820b43c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-04-6",
        "parent_task_id": "task-fixture-dv-04-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e931952567c40bf0be6585f56d7972152413e8655aced80266f5aa494970cc36",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-04-7",
        "parent_task_id": "task-fixture-dv-04-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-04",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain family-specific calculation examples and lineage placement, including approved shared-code debt.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain family-specific calculation examples and lineage placement, including approved shared-code debt.\nCase: fixture-dv-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ae198427b5ece65ff0c426463ccb4ca1359ee715b6f75680afeda05f4defc104",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-04-tests",
        "parent_task_id": "task-fixture-dv-04-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-04-executor",
        "parent_task_id": "task-fixture-dv-04-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-04\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-04-Spawn",
        "case_id": "fixture-dv-04",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-04-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Reproduce the product-family premium/cover rule and inspect plugin versus shared-service placement on each actual lineage.\nPrepare the bounded work: Implement at the approved seam; package changed libraries and rebuild all declared consumers with companion rows where needed.\nReturn evidence sufficient to test: Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.\nReject this false completion: NuGet is published but an active consumer still runs the old rule: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-04-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-04-Plan",
        "case_id": "fixture-dv-04",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-04-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-04",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-04-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-04-PlanConfirmation",
        "case_id": "fixture-dv-04",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-04-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-04",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-04-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-04-Result",
        "case_id": "fixture-dv-04",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-04-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-04-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-04-Verdict",
        "case_id": "fixture-dv-04",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-04-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "NuGet is published but an active consumer still runs the old rule: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-04-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement at the approved seam; package changed libraries and rebuild all declared consumers with companion rows where needed.",
      "case_specific_proof": "Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00244"
            },
            "body": {
              "module": "support",
              "description": "A premium or cover computation rule for a product family (2200 / 2222, 2215, 47xx, 36xx)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00245"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00246"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Worked quotes cover affected products, boundaries and unchanged siblings; ABACUS and INSIS reconcile with the intended rule."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00247"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00248"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain family-specific calculation examples and lineage placement, including approved shared-code debt."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00249"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00250"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00251"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00252"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: A premium or cover computation rule for a product family (2200 / 2222, 2215, 47xx, 36xx)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Re-run the reproducer on current source and pricing versions before reusing code or examples."
      }
    ]
  },
  "DV-05": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-05-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ce5e4925ea9ce904320e7baa279e135152d1491651b269048c28b514512c98d4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-05-1",
        "parent_task_id": "task-fixture-dv-05-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin the partner request contract, registration plugin, identity-client configuration and required database schema.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "675e421166816d52e63a0055e0a17129926879eadeaf593607c69430e2676880",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-05-2",
        "parent_task_id": "task-fixture-dv-05-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1de79e29c58ba4290454409b673f7d13e669c03d58bc83875d303c2288544539",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-05-3",
        "parent_task_id": "task-fixture-dv-05-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\nPrepare the bounded work: Implement the bounded API change with its schema/identity dependencies; deploy only to the explicitly requested partner target.\nReturn evidence sufficient to test: The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nReject this false completion: REST success precedes a failed transfer or missing print: no end-to-end result.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\nPrepare the bounded work: Implement the bounded API change with its schema/identity dependencies; deploy only to the explicitly requested partner target.\nReturn evidence sufficient to test: The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nReject this false completion: REST success precedes a failed transfer or missing print: no end-to-end result.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "38e4cf9170e9034e8dd036cf0bb9289edf1f986d6fafb697ad7793500377356f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-05-4",
        "parent_task_id": "task-fixture-dv-05-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "70272ce9d3bf3695044e64cc22891acfee0388a3d632258fe3adee3ae5fc5194",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-05-5",
        "parent_task_id": "task-fixture-dv-05-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the bounded API change with its schema/identity dependencies; deploy only to the explicitly requested partner target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the bounded API change with its schema/identity dependencies; deploy only to the explicitly requested partner target.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b38f81de0165371b204dafbc58781c9da9529fe039c4d04368f95e012fb824cb",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-05-6",
        "parent_task_id": "task-fixture-dv-05-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3f413c58517df23bb3b693c4a0ff022e0f02fbbb253dab4d315876d9c8dd6bf8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-05-7",
        "parent_task_id": "task-fixture-dv-05-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-05",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain contract examples, validation failures and required release components; redact credentials and customer data.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain contract examples, validation failures and required release components; redact credentials and customer data.\nCase: fixture-dv-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2f27f09b7cdc276041ae595ee3200d942665df3aa0ff781208efbd9b5205ff94",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-05-tests",
        "parent_task_id": "task-fixture-dv-05-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-05-executor",
        "parent_task_id": "task-fixture-dv-05-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-05\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-05-Spawn",
        "case_id": "fixture-dv-05",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-05-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Pin the partner request contract, registration plugin, identity-client configuration and required database schema.\nPrepare the bounded work: Implement the bounded API change with its schema/identity dependencies; deploy only to the explicitly requested partner target.\nReturn evidence sufficient to test: The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.\nReject this false completion: REST success precedes a failed transfer or missing print: no end-to-end result.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-05-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-05-Plan",
        "case_id": "fixture-dv-05",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-05-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-05",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-05-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-05-PlanConfirmation",
        "case_id": "fixture-dv-05",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-05-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-05",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-05-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-05-Result",
        "case_id": "fixture-dv-05",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-05-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-05-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-05-Verdict",
        "case_id": "fixture-dv-05",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-05-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "REST success precedes a failed transfer or missing print: no end-to-end result.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-05-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement the bounded API change with its schema/identity dependencies; deploy only to the explicitly requested partner target.",
      "case_specific_proof": "The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00253"
            },
            "body": {
              "module": "support",
              "description": "Partner registration API hardening (Bul SI, RegisterPolicy)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00254"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00255"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The approved staging contract examples register, transfer and print; invalid and repeated requests follow the declared behaviour."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00256"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00257"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain contract examples, validation failures and required release components; redact credentials and customer data."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00258"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00259"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00260"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00261"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Partner registration API hardening (Bul SI, RegisterPolicy)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck the current partner contract and schema; do not reuse a past partner's credentials or launch authority."
      }
    ]
  },
  "DV-06": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-06-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9a070c873c6705aba812fe2ec24a5ab74628d7be3d96651fb84837a085b986db",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-06-1",
        "parent_task_id": "task-fixture-dv-06-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ed50cdbb186779b407b5d3dec9d1902855660e74f16005acfd3ce521c54cfcb8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-06-2",
        "parent_task_id": "task-fixture-dv-06-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a12662cd5871f9a155b9999c83e2ecb72575e34acf0d6219f1422cb890d3cf73",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-06-3",
        "parent_task_id": "task-fixture-dv-06-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\nPrepare the bounded work: Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.\nReturn evidence sufficient to test: Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nReject this false completion: UI accepts a value that the active backend rejects: fail the pair.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\nPrepare the bounded work: Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.\nReturn evidence sufficient to test: Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nReject this false completion: UI accepts a value that the active backend rejects: fail the pair.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "47619e380ea52fe3fc4ba686f90243e8a756c9d114a505c3c6b94989291f5678",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-06-4",
        "parent_task_id": "task-fixture-dv-06-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\nPrepare the bounded work: Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.\nReturn evidence sufficient to test: Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nReject this false completion: UI accepts a value that the active backend rejects: fail the pair.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\nPrepare the bounded work: Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.\nReturn evidence sufficient to test: Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nReject this false completion: UI accepts a value that the active backend rejects: fail the pair.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b165165889342f9d740d5bbcdd36909d3300972b4cf3d075df1698f83ef8db2b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-06-5",
        "parent_task_id": "task-fixture-dv-06-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "01d46ac0dabff34b724ac711a5a5e2efe83526813fb1c1e7ef4886c3c6449bfe",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-06-6",
        "parent_task_id": "task-fixture-dv-06-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3c4ec5cad84bf8ea1aa48b26c7b13e23a2d8248c6970d5de24536f63283e682b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-06-7",
        "parent_task_id": "task-fixture-dv-06-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "98e2003dc3d6b2b749f97087c39d56da0fda62afa5fdb6f2e11a7b4034343d7b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-06-8",
        "parent_task_id": "task-fixture-dv-06-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-06",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the field/source-of-truth contract and negative identifier/optional-field examples.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the field/source-of-truth contract and negative identifier/optional-field examples.\nCase: fixture-dv-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1da870a1100a117c4dccb02a3780f7c84466c82e51e8d688259094a5d67e4953",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-06-tests",
        "parent_task_id": "task-fixture-dv-06-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-06-executor",
        "parent_task_id": "task-fixture-dv-06-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-06\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-06-Spawn",
        "case_id": "fixture-dv-06",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-06-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Reproduce customer/party validation in UI and backend, including LDAP and INSIS propagation; map the actual code paths.\nPrepare the bounded work: Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.\nReturn evidence sufficient to test: Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.\nReject this false completion: UI accepts a value that the active backend rejects: fail the pair.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-06-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-06-Plan",
        "case_id": "fixture-dv-06",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-06-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-06",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-06-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-06-PlanConfirmation",
        "case_id": "fixture-dv-06",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-06-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-06",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-06-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-06-Result",
        "case_id": "fixture-dv-06",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-06-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-06-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-06-Verdict",
        "case_id": "fixture-dv-06",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-06-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "UI accepts a value that the active backend rejects: fail the pair.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-06-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement the approved pair of changes plus identity dependencies and deploy them in the declared compatibility order.",
      "case_specific_proof": "Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00262"
            },
            "body": {
              "module": "support",
              "description": "Customer and party data rules (custPid, contacts, names, addresses, LDAP accounts)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00263"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00264"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Create/edit the test customer on target and verify transferred participant data; check the prior valid cases still work."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00265"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00266"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the field/source-of-truth contract and negative identifier/optional-field examples."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00267"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00268"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00269"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00270"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Customer and party data rules (custPid, contacts, names, addresses, LDAP accounts)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check both current client validation and server behaviour before applying the previous pattern."
      }
    ]
  },
  "DV-07": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-07-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target participant search and commission defaults work together with the approved agent/office rules.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target participant search and commission defaults work together with the approved agent/office rules.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "37cde032ea21e569a899b22d36cc2d21db2a21540369af4a689e17be1a240bef",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-07-1",
        "parent_task_id": "task-fixture-dv-07-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c402cf954c47b940da929cdbbf66b0952daf07cf330db5fa3d27fcd0cb1b7c3a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-07-2",
        "parent_task_id": "task-fixture-dv-07-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target participant search and commission defaults work together with the approved agent/office rules.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target participant search and commission defaults work together with the approved agent/office rules.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6e76b56dd2bc8b9551eb99fcbc756ea5ae66ec6aa316cef3250ec924fef8d535",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-07-3",
        "parent_task_id": "task-fixture-dv-07-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\nPrepare the bounded work: Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.\nReturn evidence sufficient to test: Target participant search and commission defaults work together with the approved agent/office rules.\nReject this false completion: The UI reaches PROD but its required backend half remains on staging: reject delivery.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\nPrepare the bounded work: Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.\nReturn evidence sufficient to test: Target participant search and commission defaults work together with the approved agent/office rules.\nReject this false completion: The UI reaches PROD but its required backend half remains on staging: reject delivery.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e6800f39d5dbdc7e4ef7c571d19065cc89c7614a85e638475572c2780b5cfe75",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-07-4",
        "parent_task_id": "task-fixture-dv-07-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\nPrepare the bounded work: Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.\nReturn evidence sufficient to test: Target participant search and commission defaults work together with the approved agent/office rules.\nReject this false completion: The UI reaches PROD but its required backend half remains on staging: reject delivery.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\nPrepare the bounded work: Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.\nReturn evidence sufficient to test: Target participant search and commission defaults work together with the approved agent/office rules.\nReject this false completion: The UI reaches PROD but its required backend half remains on staging: reject delivery.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "082a8d26752edbbfd4c23cd55a49c8d53b3bcdb47881ec30f408bc0b61d04181",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-07-5",
        "parent_task_id": "task-fixture-dv-07-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Target participant search and commission defaults work together with the approved agent/office rules.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Target participant search and commission defaults work together with the approved agent/office rules.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "38cdc1848d883a94c92a4a8c55058b5fe558719c2c6f4a716947d7d4cba88631",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-07-6",
        "parent_task_id": "task-fixture-dv-07-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "80563952f675502bd577ae994be6eb3fa4e7379f57ff2fe4b89ed5eed977b895",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-07-7",
        "parent_task_id": "task-fixture-dv-07-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Target participant search and commission defaults work together with the approved agent/office rules.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Target participant search and commission defaults work together with the approved agent/office rules.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6f7f79c8ec9ced4d33be2430b05d813712498ca74e5b405fdfd55ce1071bef2a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-07-8",
        "parent_task_id": "task-fixture-dv-07-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-07",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the cross-component contract and missing-backend-release counterexample.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the cross-component contract and missing-backend-release counterexample.\nCase: fixture-dv-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2c0c3773a90ba553d232b4ab9d36a3f3089567f130966cff92a7fc3f26e3304a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-07-tests",
        "parent_task_id": "task-fixture-dv-07-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-07-executor",
        "parent_task_id": "task-fixture-dv-07-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-07\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-07-Spawn",
        "case_id": "fixture-dv-07",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-07-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Reproduce participant search/office/commission behaviour and establish which backend and UI halves are actually deployed.\nPrepare the bounded work: Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.\nReturn evidence sufficient to test: Target participant search and commission defaults work together with the approved agent/office rules.\nReject this false completion: The UI reaches PROD but its required backend half remains on staging: reject delivery.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-07-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-07-Plan",
        "case_id": "fixture-dv-07",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-07-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-07",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-07-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-07-PlanConfirmation",
        "case_id": "fixture-dv-07",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-07-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-07",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-07-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-07-Result",
        "case_id": "fixture-dv-07",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-07-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-07-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-07-Verdict",
        "case_id": "fixture-dv-07",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-07-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The UI reaches PROD but its required backend half remains on staging: reject delivery.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-07-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement and review the bounded feature or defect across its consumers; keep each target's missing half as a release obligation.",
      "case_specific_proof": "Target participant search and commission defaults work together with the approved agent/office rules.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00271"
            },
            "body": {
              "module": "support",
              "description": "Agent, office and commission code paths (посредник)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00272"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00273"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Target participant search and commission defaults work together with the approved agent/office rules."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00274"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00275"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the cross-component contract and missing-backend-release counterexample."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00276"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00277"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00278"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00279"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Agent, office and commission code paths (посредник)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect serving versions first; the next ticket may be an undeployed half rather than a new defect."
      }
    ]
  },
  "DV-08": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-08-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e86b8a99728d582b99e2a495ef70869d802e55f4be4e1426824b514dcf351e1f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-08-1",
        "parent_task_id": "task-fixture-dv-08-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "51eec6647dc2623186a00f792c1e73ef14c3752580c0ce4b44b0ad695e8b37d1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-08-2",
        "parent_task_id": "task-fixture-dv-08-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ebc66be601fcc0796187bed3510d6f27e2d35a9cb645b9eafcb734bfd9dc1169",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-08-3",
        "parent_task_id": "task-fixture-dv-08-2",
        "profile_key": "source.planner",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Establish: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\nPrepare the bounded work: Refer the programme within the current charter; scoped currency fixes use ordinary source/configuration cases with explicit dependencies.\nReturn evidence sufficient to test: A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nReject this false completion: One successful EUR quote is treated as proof of every legacy policy, report and transfer: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.planner. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\nPrepare the bounded work: Refer the programme within the current charter; scoped currency fixes use ordinary source/configuration cases with explicit dependencies.\nReturn evidence sufficient to test: A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nReject this false completion: One successful EUR quote is treated as proof of every legacy policy, report and transfer: reject.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cc6b4421bc9a256f496f183f728b63093e79053de7eb60d9eeed48cb1abcd67b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-planner"
      },
      {
        "task_id": "task-fixture-dv-08-4",
        "parent_task_id": "task-fixture-dv-08-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ae54e63ecab5932dcaebeb0fbe3c5c1328526f7ebab3fdab3b869e779b5c7b37",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-dv-08-5",
        "parent_task_id": "task-fixture-dv-08-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Refer the programme within the current charter; scoped currency fixes use ordinary source/configuration cases with explicit dependencies.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Refer the programme within the current charter; scoped currency fixes use ordinary source/configuration cases with explicit dependencies.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "39f5044e812de278a09b89f725f032969480d2d8bf0c3c80e7309b60fad09d64",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-08-6",
        "parent_task_id": "task-fixture-dv-08-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cac7ef9680c55b5d681a869389b8957fcf8e7ed5db85057d5eb0eadbde989602",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-08-7",
        "parent_task_id": "task-fixture-dv-08-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-08",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain scoped regression examples and observed compatibility facts without claiming programme completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain scoped regression examples and observed compatibility facts without claiming programme completion.\nCase: fixture-dv-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f890d6db951bbea01ba672b51cfa20cf0cb85d1a309e5af8a69b77e98ab46862",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-08-tests",
        "parent_task_id": "task-fixture-dv-08-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-08-executor",
        "parent_task_id": "task-fixture-dv-08-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-08\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-08-Spawn",
        "case_id": "fixture-dv-08",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-08-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.planner",
          "profile_version": 1,
          "task_text": "Establish: Record the cross-product currency programme, affected seams and accountable coordination owner; identify any requested bounded slice.\nPrepare the bounded work: Refer the programme within the current charter; scoped currency fixes use ordinary source/configuration cases with explicit dependencies.\nReturn evidence sufficient to test: A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.\nReject this false completion: One successful EUR quote is treated as proof of every legacy policy, report and transfer: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-08-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-08-Plan",
        "case_id": "fixture-dv-08",
        "task_path": "root/source-root/source-planner",
        "sender": {
          "task_id": "task-fixture-dv-08-3",
          "profile_key": "source.planner",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-08",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-08-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-08-PlanConfirmation",
        "case_id": "fixture-dv-08",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-08-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-08",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-08-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-08-Result",
        "case_id": "fixture-dv-08",
        "task_path": "root/source-root/source-planner",
        "sender": {
          "task_id": "task-fixture-dv-08-3",
          "profile_key": "source.planner",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-08-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-08-Verdict",
        "case_id": "fixture-dv-08",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-dv-08-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "One successful EUR quote is treated as proof of every legacy policy, report and transfer: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-08-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Refer the programme within the current charter; scoped currency fixes use ordinary source/configuration cases with explicit dependencies.",
      "case_specific_proof": "A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00280"
            },
            "body": {
              "module": "support",
              "description": "A regulatory cross-cutting change: the BGN → EUR changeover",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00281"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00282"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: A referral is labelled as such; a bounded slice proves current EUR behaviour and required legacy-currency cases with currency codes."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00283"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00284"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain scoped regression examples and observed compatibility facts without claiming programme completion."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00285"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00286"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00287"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00288"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: A regulatory cross-cutting change: the BGN → EUR changeover",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Separate new programme scope from a repeat defect and recheck the effective currency/version context."
      }
    ]
  },
  "DV-09": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-09-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "71444a0aedbc76a508c61dd6265b1b53d1b2af4a4a8db5f49872efc32006bed9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-09-1",
        "parent_task_id": "task-fixture-dv-09-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "669bcd20418cdad0811da21708634a6ba650c237ee3c9f32356e999111812589",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-09-2",
        "parent_task_id": "task-fixture-dv-09-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c247c145249d4ff8a7d0ea06366f0e9af8c17a8ec1569e787724605cc4bf9201",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-09-3",
        "parent_task_id": "task-fixture-dv-09-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\nPrepare the bounded work: Change the narrow parser/validator path and review generated dependency changes; deploy the reviewed UI artifact.\nReturn evidence sufficient to test: Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nReject this false completion: DOM text looks correct but the posted numeric value differs: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\nPrepare the bounded work: Change the narrow parser/validator path and review generated dependency changes; deploy the reviewed UI artifact.\nReturn evidence sufficient to test: Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nReject this false completion: DOM text looks correct but the posted numeric value differs: fail.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f2f55dc40d70f18f0efeee17ceb48f55835c4746f52b65b5fb71e498a11affb9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-09-4",
        "parent_task_id": "task-fixture-dv-09-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e6f1481c38fc2bbdceee23a8a594efecc6f842d677d550045556df50326bd89a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-09-5",
        "parent_task_id": "task-fixture-dv-09-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Change the narrow parser/validator path and review generated dependency changes; deploy the reviewed UI artifact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Change the narrow parser/validator path and review generated dependency changes; deploy the reviewed UI artifact.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3403a62024ff90458d8f8053b9cf91ced18d402a0e8482e514055718246ec28c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-09-6",
        "parent_task_id": "task-fixture-dv-09-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1e208270c0642418fea7dac1f5000e27497567fde5bfca126a91b8645b5483cd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-09-7",
        "parent_task_id": "task-fixture-dv-09-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-09",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain interaction-level regression cases and the exact locale/value boundary.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain interaction-level regression cases and the exact locale/value boundary.\nCase: fixture-dv-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "acbeb236d91579180526b4cb475519755aa27379398ac931894b82d8a865da6f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-09-tests",
        "parent_task_id": "task-fixture-dv-09-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-09-executor",
        "parent_task_id": "task-fixture-dv-09-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-09\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-09-Spawn",
        "case_id": "fixture-dv-09",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-09-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-ui",
          "profile_version": 1,
          "task_text": "Establish: Reproduce the exact Bulgarian input gesture, field validator and locale parsing on the active UI lineage.\nPrepare the bounded work: Change the narrow parser/validator path and review generated dependency changes; deploy the reviewed UI artifact.\nReturn evidence sufficient to test: Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.\nReject this false completion: DOM text looks correct but the posted numeric value differs: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-ui",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-09-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-09-Plan",
        "case_id": "fixture-dv-09",
        "task_path": "root/source-root/source-implementer-serdica-ui",
        "sender": {
          "task_id": "task-fixture-dv-09-3",
          "profile_key": "source.implementer.serdica-ui",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-09",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-09-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-09-PlanConfirmation",
        "case_id": "fixture-dv-09",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-09-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-09",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-09-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-09-Result",
        "case_id": "fixture-dv-09",
        "task_path": "root/source-root/source-implementer-serdica-ui",
        "sender": {
          "task_id": "task-fixture-dv-09-3",
          "profile_key": "source.implementer.serdica-ui",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-09-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-09-Verdict",
        "case_id": "fixture-dv-09",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-09-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "DOM text looks correct but the posted numeric value differs: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-09-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Change the narrow parser/validator path and review generated dependency changes; deploy the reviewed UI artifact.",
      "case_specific_proof": "Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00289"
            },
            "body": {
              "module": "support",
              "description": "UI number, locale and field-validation behaviour for Bulgarian operators",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00290"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00291"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Real input sequences cover comma/dot, blur/re-entry and invalid values; client and server interpretations agree."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00292"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00293"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain interaction-level regression cases and the exact locale/value boundary."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00294"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00295"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00296"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00297"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: UI number, locale and field-validation behaviour for Bulgarian operators",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Replay the original gesture before altering shared parsing; search the accepted regression corpus."
      }
    ]
  },
  "DV-10": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-10-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d8187c2ab44f4478a3009211cffa2bf7d14b6c165c9844b214f324d74e9ad83b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-10-1",
        "parent_task_id": "task-fixture-dv-10-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a1554efc4cd63d57acc2d11af7d58326aa9a423f5d6ae0a940312921a571d137",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-10-2",
        "parent_task_id": "task-fixture-dv-10-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a306725f8011c33b477440d5eaa616155bb6c4e88192e03018aa2e46d87dc28c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-10-3",
        "parent_task_id": "task-fixture-dv-10-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Establish: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\nPrepare the bounded work: Implement or promote only the needed approved UI change, including labels and data-contract dependencies.\nReturn evidence sufficient to test: The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nReject this false completion: A code diff exists but the target still serves the older dialog: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\nPrepare the bounded work: Implement or promote only the needed approved UI change, including labels and data-contract dependencies.\nReturn evidence sufficient to test: The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nReject this false completion: A code diff exists but the target still serves the older dialog: no completion.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4fcfab459f349fc781c867688a00ac23418c32da27f2a10ca8dc1301e8ba0e52",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-10-4",
        "parent_task_id": "task-fixture-dv-10-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "59af097b466cec7136e5deb132110fc6a0b7b555243841fcdc2c7f736629f2c3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-10-5",
        "parent_task_id": "task-fixture-dv-10-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement or promote only the needed approved UI change, including labels and data-contract dependencies.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement or promote only the needed approved UI change, including labels and data-contract dependencies.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1241a37f7421c96b8bd3bb8185cded1a056222ef20b5ad66e12427858fd4c149",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-10-6",
        "parent_task_id": "task-fixture-dv-10-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "046901ddb4171a2c4c40a63bf746e55d52b4859fd9b1eaf06bb0898309cfe868",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-10-7",
        "parent_task_id": "task-fixture-dv-10-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-10",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the interaction regression and deployment-gap diagnosis in the UI domain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the interaction regression and deployment-gap diagnosis in the UI domain.\nCase: fixture-dv-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c235c3f2fa3ed98cd85d06258b3fa8ca2637de2811026646af5bd4627d7ad79a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-10-tests",
        "parent_task_id": "task-fixture-dv-10-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-10-executor",
        "parent_task_id": "task-fixture-dv-10-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-10\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-10-Spawn",
        "case_id": "fixture-dv-10",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-10-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-ui",
          "profile_version": 1,
          "task_text": "Establish: Check whether the object dialog feature is absent, defective or simply not deployed; record target browser behaviour and serving revision.\nPrepare the bounded work: Implement or promote only the needed approved UI change, including labels and data-contract dependencies.\nReturn evidence sufficient to test: The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.\nReject this false completion: A code diff exists but the target still serves the older dialog: no completion.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-ui",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-10-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-10-Plan",
        "case_id": "fixture-dv-10",
        "task_path": "root/source-root/source-implementer-serdica-ui",
        "sender": {
          "task_id": "task-fixture-dv-10-3",
          "profile_key": "source.implementer.serdica-ui",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-10",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-10-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-10-PlanConfirmation",
        "case_id": "fixture-dv-10",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-10-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-10",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-10-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-10-Result",
        "case_id": "fixture-dv-10",
        "task_path": "root/source-root/source-implementer-serdica-ui",
        "sender": {
          "task_id": "task-fixture-dv-10-3",
          "profile_key": "source.implementer.serdica-ui",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-10-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-10-Verdict",
        "case_id": "fixture-dv-10",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-10-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A code diff exists but the target still serves the older dialog: no completion.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-10-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement or promote only the needed approved UI change, including labels and data-contract dependencies.",
      "case_specific_proof": "The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00298"
            },
            "body": {
              "module": "support",
              "description": "Product object screens: dialogs, labels, tooltips, descriptions (the 2200 / 2222 wave)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00299"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00300"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The actual dialog opens, edits, validates and persists as requested; repeated navigation and relevant fields work."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00301"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00302"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the interaction regression and deployment-gap diagnosis in the UI domain."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00303"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00304"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00305"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00306"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Product object screens: dialogs, labels, tooltips, descriptions (the 2200 / 2222 wave)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect deployed feature/version before reopening development; reuse the real interaction test."
      }
    ]
  },
  "DV-11": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-11-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target can create the declared child under the correct framework; contract-type values are populated and consumed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2887cdad7a3e46b1a6c90e824511298d9016b5c0202a6121afaa3b0da8fdc618",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-11-1",
        "parent_task_id": "task-fixture-dv-11-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ec7df19909485f22d7c4fe6a7b0fb067215a9b28f2994ce86a11f55a65beeade",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-11-2",
        "parent_task_id": "task-fixture-dv-11-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target can create the declared child under the correct framework; contract-type values are populated and consumed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ba5f2eed25c2e66aed35472c461867f03a5821b46de79ad8b329ea5d6dafa3a1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-11-3",
        "parent_task_id": "task-fixture-dv-11-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\nPrepare the bounded work: Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.\nReturn evidence sufficient to test: The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nReject this false completion: A new column exists on both environments but every required value is NULL: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\nPrepare the bounded work: Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.\nReturn evidence sufficient to test: The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nReject this false completion: A new column exists on both environments but every required value is NULL: fail.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "20082eb25f14a1557d253bdb463426ddac99e7a76597a451341ecd938aec5fb7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-11-4",
        "parent_task_id": "task-fixture-dv-11-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\nPrepare the bounded work: Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.\nReturn evidence sufficient to test: The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nReject this false completion: A new column exists on both environments but every required value is NULL: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\nPrepare the bounded work: Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.\nReturn evidence sufficient to test: The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nReject this false completion: A new column exists on both environments but every required value is NULL: fail.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "adc91fb0a70103d5a883a00f7996b9bc188fbb68c7639a8ed38e5eb8ca437323",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-11-5",
        "parent_task_id": "task-fixture-dv-11-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The target can create the declared child under the correct framework; contract-type values are populated and consumed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0c61cdb98c58f776be9d72bf9ab5d1b7d27d303efd499acf8ae6e7b249f66fe0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-11-6",
        "parent_task_id": "task-fixture-dv-11-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "765a24df534d3ae311aef24f7e74b4558a68b1e74f937a0f82f84bc2756257f9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-11-7",
        "parent_task_id": "task-fixture-dv-11-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The target can create the declared child under the correct framework; contract-type values are populated and consumed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bc1b146584a053dd30e0686114b120027cef50d56edacaf2530c9853515763b1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-11-8",
        "parent_task_id": "task-fixture-dv-11-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-11",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the schema-present-but-unused counterexample and mixed-release contract.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the schema-present-but-unused counterexample and mixed-release contract.\nCase: fixture-dv-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "728b1ec16fda276321db2efaba0b5831bfb56dd6d06f590bad04e5e1c38fecdc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-11-tests",
        "parent_task_id": "task-fixture-dv-11-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-11-executor",
        "parent_task_id": "task-fixture-dv-11-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-11\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-11-Spawn",
        "case_id": "fixture-dv-11",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-11-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Pin FRAME/contract-type schema, plugin, workflow and shared Annexes behaviour plus the expected configuration values.\nPrepare the bounded work: Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.\nReturn evidence sufficient to test: The target can create the declared child under the correct framework; contract-type values are populated and consumed.\nReject this false completion: A new column exists on both environments but every required value is NULL: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-11-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-11-Plan",
        "case_id": "fixture-dv-11",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-11-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-11",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-11-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-11-PlanConfirmation",
        "case_id": "fixture-dv-11",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-11-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-11",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-11-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-11-Result",
        "case_id": "fixture-dv-11",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-11-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-11-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-11-Verdict",
        "case_id": "fixture-dv-11",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-11-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A new column exists on both environments but every required value is NULL: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-11-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Coordinate code, schema and Configuration rows in a dependency graph; record both repository heads and all consumer images.",
      "case_specific_proof": "The target can create the declared child under the correct framework; contract-type values are populated and consumed.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00307"
            },
            "body": {
              "module": "support",
              "description": "Cargo and framework (11xx) contracts: FRAME types, group policies, master-policy objects",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00308"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00309"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The target can create the declared child under the correct framework; contract-type values are populated and consumed."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00310"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00311"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the schema-present-but-unused counterexample and mixed-release contract."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00312"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00313"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00314"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00315"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Cargo and framework (11xx) contracts: FRAME types, group policies, master-policy objects",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck column support, row population and consumer behaviour before reusing the FRAME pattern."
      }
    ]
  },
  "DV-12": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-12-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b8c3ccc94dca65a072d50981b75d54ff3bca438bcd12210e7212927dbc2f8616",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-12-1",
        "parent_task_id": "task-fixture-dv-12-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "97b4e6478177bdad19d2c9d50f4f176efd8c04a303e6d84459cca637a09dee52",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-12-2",
        "parent_task_id": "task-fixture-dv-12-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cee6b79c8074fcf908d211b094c903a3c02ab05bb4fcaf07bff96c40d8469229",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-12-3",
        "parent_task_id": "task-fixture-dv-12-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\nPrepare the bounded work: Implement the scoped plugin/service/riskmodel change or keep Next Release waiting with its explicit trigger.\nReturn evidence sufficient to test: The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nReject this false completion: A timeout is assumed to mean nothing landed and the action is retried blindly: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\nPrepare the bounded work: Implement the scoped plugin/service/riskmodel change or keep Next Release waiting with its explicit trigger.\nReturn evidence sufficient to test: The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nReject this false completion: A timeout is assumed to mean nothing landed and the action is retried blindly: reject.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "baf4c21de10dad973202c77fd9cb203410ce55164607f334ba05ab28f7ae997a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-12-4",
        "parent_task_id": "task-fixture-dv-12-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "fd13edd922d8bb91fe5cfb0bfcad5419a077e5142029ddd4cc659d528df245be",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-12-5",
        "parent_task_id": "task-fixture-dv-12-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the scoped plugin/service/riskmodel change or keep Next Release waiting with its explicit trigger.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the scoped plugin/service/riskmodel change or keep Next Release waiting with its explicit trigger.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "41bb8ce91a0f20ca0de663ea98f9a0f15e4e48e4382a687db7b6d64dbb6e76c1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-12-6",
        "parent_task_id": "task-fixture-dv-12-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f576b093da609825c33fcfe0f92c569c6d1f3ca03363b0725bef1cf5c8a577dc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-12-7",
        "parent_task_id": "task-fixture-dv-12-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-12",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain subtype discrimination, timeout classification and the narrow regression.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain subtype discrimination, timeout classification and the narrow regression.\nCase: fixture-dv-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "453a11c6bf85b4e31a76935ac1a5ea0b9431a485e171fe33674008a463310469",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-12-tests",
        "parent_task_id": "task-fixture-dv-12-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-12-executor",
        "parent_task_id": "task-fixture-dv-12-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-12\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-12-Spawn",
        "case_id": "fixture-dv-12",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-12-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Reproduce the motor-flow rule with product/subtype, partner service response and process version; distinguish a waiting backlog request.\nPrepare the bounded work: Implement the scoped plugin/service/riskmodel change or keep Next Release waiting with its explicit trigger.\nReturn evidence sufficient to test: The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.\nReject this false completion: A timeout is assumed to mean nothing landed and the action is retried blindly: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-12-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-12-Plan",
        "case_id": "fixture-dv-12",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-12-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-12",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-12-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-12-PlanConfirmation",
        "case_id": "fixture-dv-12",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-12-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-12",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-12-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-12-Result",
        "case_id": "fixture-dv-12",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-12-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-12-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-12-Verdict",
        "case_id": "fixture-dv-12",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-12-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A timeout is assumed to mean nothing landed and the action is retried blindly: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-12-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement the scoped plugin/service/riskmodel change or keep Next Release waiting with its explicit trigger.",
      "case_specific_proof": "The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00316"
            },
            "body": {
              "module": "support",
              "description": "Motor (47xx) flow rules",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00317"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00318"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The affected flow works for the requested subtype and relevant sibling products; external effects are separately permitted."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00319"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00320"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain subtype discrimination, timeout classification and the narrow regression."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00321"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00322"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00323"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00324"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Motor (47xx) flow rules",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check current service/flow version and outstanding release before proposing a second fix."
      }
    ]
  },
  "DV-13": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-13-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "78e6ce882b2cec59f3e782e74f50221babd86720046f6831ae7b5337e94f3104",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-13-1",
        "parent_task_id": "task-fixture-dv-13-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2e41d172bb7efbb91b1e67d4408c03346f664c31ed6a56d9bc9effbca6b90a8c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-13-2",
        "parent_task_id": "task-fixture-dv-13-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7245e438dd121b6ebcaca60b93c20f5367c0f554747566986f54e0f2d12b675d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-13-3",
        "parent_task_id": "task-fixture-dv-13-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\nPrepare the bounded work: Use the backend repository's Python toolchain; implement and test the filter, then deploy the declared anl-risk-model artifact.\nReturn evidence sufficient to test: Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nReject this false completion: A change deliberately reverted on PROD is restored by a routine port without review: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\nPrepare the bounded work: Use the backend repository's Python toolchain; implement and test the filter, then deploy the declared anl-risk-model artifact.\nReturn evidence sufficient to test: Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nReject this false completion: A change deliberately reverted on PROD is restored by a routine port without review: reject.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "45a26b2550599e81c1b99065fc87f7aa53f9e6168882c298391668725026928b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-13-4",
        "parent_task_id": "task-fixture-dv-13-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1da88ef42f02ecaa5f37bca80b41b1446417d5ca506fc80c63f8cde1722406ed",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-13-5",
        "parent_task_id": "task-fixture-dv-13-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Use the backend repository's Python toolchain; implement and test the filter, then deploy the declared anl-risk-model artifact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Use the backend repository's Python toolchain; implement and test the filter, then deploy the declared anl-risk-model artifact.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "48e877ac5744fedf5911bcee6d597303d48cee7f6bf8f00984f2b6aef52f9eca",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-13-6",
        "parent_task_id": "task-fixture-dv-13-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cbc9556639c252f1850335da9abc476c18e01d18ad8c1990b94f5c21a5564794",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-13-7",
        "parent_task_id": "task-fixture-dv-13-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-13",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain input/output fixtures and the target-specific reversal; ownership stays with the repository profile.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain input/output fixtures and the target-specific reversal; ownership stays with the repository profile.\nCase: fixture-dv-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6184e8c22015c73c5805fcef0d6caffbe34e5cfccf582eb0ca0b4ef662ab4665",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-13-tests",
        "parent_task_id": "task-fixture-dv-13-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-13-executor",
        "parent_task_id": "task-fixture-dv-13-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-13\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-13-Spawn",
        "case_id": "fixture-dv-13",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-13-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Read the Python riskmodel pre/post-filter, chosen template and current target revision, including PROD-only reversals.\nPrepare the bounded work: Use the backend repository's Python toolchain; implement and test the filter, then deploy the declared anl-risk-model artifact.\nReturn evidence sufficient to test: Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.\nReject this false completion: A change deliberately reverted on PROD is restored by a routine port without review: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-13-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-13-Plan",
        "case_id": "fixture-dv-13",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-13-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-13",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-13-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-13-PlanConfirmation",
        "case_id": "fixture-dv-13",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-13-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-13",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-13-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-13-Result",
        "case_id": "fixture-dv-13",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-13-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-13-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-13-Verdict",
        "case_id": "fixture-dv-13",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-13-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A change deliberately reverted on PROD is restored by a routine port without review: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-13-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Use the backend repository's Python toolchain; implement and test the filter, then deploy the declared anl-risk-model artifact.",
      "case_specific_proof": "Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00325"
            },
            "body": {
              "module": "support",
              "description": "ABACUS pricing pre- and post-filters (Python `riskmodel`)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00326"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00327"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Current get_rates inputs produce expected per-cover premiums and template selection; unaffected cases remain valid."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00328"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00329"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain input/output fixtures and the target-specific reversal; ownership stays with the repository profile."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00330"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00331"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00332"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00333"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: ABACUS pricing pre- and post-filters (Python `riskmodel`)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect the target's actual filter and prior reversal before using a staging implementation."
      }
    ]
  },
  "DV-14": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-14-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5feb6b8476b325a91723d52e340769066fcab0fff4c385cdba386e9824da96eb",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-14-1",
        "parent_task_id": "task-fixture-dv-14-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f8885199ae9a325c8d7c99af6cc082c7c8fb46c491e2e5752b780e5f9dd95f2b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-14-2",
        "parent_task_id": "task-fixture-dv-14-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4b515d200fcc771761f1d4de21fb44c93942542f4391839f436fff304b898204",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-14-3",
        "parent_task_id": "task-fixture-dv-14-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\nPrepare the bounded work: Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.\nReturn evidence sufficient to test: The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nReject this false completion: The C# side is deployed but the database still has the old contract: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\nPrepare the bounded work: Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.\nReturn evidence sufficient to test: The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nReject this false completion: The C# side is deployed but the database still has the old contract: fail.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6e4c8cfe70c81656e77045a2b848e64f3d46a5b7752fb6196542b0f8097c0d0d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-14-4",
        "parent_task_id": "task-fixture-dv-14-2",
        "profile_key": "source.implementer.db-plsql",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/db-plsql",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Establish: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\nPrepare the bounded work: Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.\nReturn evidence sufficient to test: The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nReject this false completion: The C# side is deployed but the database still has the old contract: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.db-plsql. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\nPrepare the bounded work: Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.\nReturn evidence sufficient to test: The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nReject this false completion: The C# side is deployed but the database still has the old contract: fail.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/db-plsql/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f0ba889e9bfa828d15367ed09db85c54ecb46c57456aaf0a62446bcf0310db27",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-db-plsql"
      },
      {
        "task_id": "task-fixture-dv-14-5",
        "parent_task_id": "task-fixture-dv-14-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "863cc21293814ce00bf54a4078b422f039ff50e5e6299eba696b27ee662556f3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-14-6",
        "parent_task_id": "task-fixture-dv-14-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "aa4b2440c2567bb895ecf7c8c7f22af43a72615d7d7a10000f12bdfdb35b0370",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-14-7",
        "parent_task_id": "task-fixture-dv-14-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8a3b5fdff9ad1256730ee9c2728ba0d1c02f3567551653d7a112241c3e2c04c0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-14-8",
        "parent_task_id": "task-fixture-dv-14-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-14",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the confirmed triggering action and caller/database contract; link outstanding data workarounds.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the confirmed triggering action and caller/database contract; link outstanding data workarounds.\nCase: fixture-dv-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "220375a9ddb2c6981f2676d40c88beb7bb8a2e6191d0a15fb94fbf736593963d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-14-tests",
        "parent_task_id": "task-fixture-dv-14-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-14-executor",
        "parent_task_id": "task-fixture-dv-14-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-14\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-14-Spawn",
        "case_id": "fixture-dv-14",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-14-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Reproduce the C# caller/PLSQL contract and transfer/revert behaviour; snapshot the live stored code and effect history.\nPrepare the bounded work: Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.\nReturn evidence sufficient to test: The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.\nReject this false completion: The C# side is deployed but the database still has the old contract: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-14-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-14-Plan",
        "case_id": "fixture-dv-14",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-14-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-14",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-14-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-14-PlanConfirmation",
        "case_id": "fixture-dv-14",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-14-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-14",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-14-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-14-Result",
        "case_id": "fixture-dv-14",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-14-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-14-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-14-Verdict",
        "case_id": "fixture-dv-14",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-14-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The C# side is deployed but the database still has the old contract: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-14-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Deliver the caller and stored-code change in the compatible order; gate DDL and reconcile external effects after timeouts.",
      "case_specific_proof": "The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00334"
            },
            "body": {
              "module": "support",
              "description": "INSIS transfer and revert-to-application handling (C# caller + PL/SQL)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00335"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00336"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended transfer/revert works on target without duplicate effects; the family invariants still hold after the sequence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00337"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00338"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the confirmed triggering action and caller/database contract; link outstanding data workarounds."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00339"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00340"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00341"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00342"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: INSIS transfer and revert-to-application handling (C# caller + PL/SQL)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Load current caller and package signatures before applying the regression; check whether the causal fix is already live."
      }
    ]
  },
  "DV-15": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-15-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3cd08e23a0b0c416b65f3cc141d5277c01b388fbd83cb85e0b4cc14f933b6776",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-15-1",
        "parent_task_id": "task-fixture-dv-15-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a2ee1e7ae3b5f6ed2be600ec7e2b14a16c088095cc337dcf0965f68a50008191",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-15-2",
        "parent_task_id": "task-fixture-dv-15-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6caca134e7fb7e305dfd83a035e227d5973d6791cbcdf895c35274f2432a9b17",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-15-3",
        "parent_task_id": "task-fixture-dv-15-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Establish: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\nPrepare the bounded work: Implement/release the library and explicitly deliver its required rows through Configuration or the scoped owner.\nReturn evidence sufficient to test: Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nReject this false completion: A successful build with no enabling row is reported as a working control: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\nPrepare the bounded work: Implement/release the library and explicitly deliver its required rows through Configuration or the scoped owner.\nReturn evidence sufficient to test: Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nReject this false completion: A successful build with no enabling row is reported as a working control: reject.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7b940c3b7a3323f13c32a235232077c06285571da8e78a8d4c0146d4286556a2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-15-4",
        "parent_task_id": "task-fixture-dv-15-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "85f418d796e2faac6578fa28d40b7ffd0c2b82278de1252c5062dc962832baf8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-15-5",
        "parent_task_id": "task-fixture-dv-15-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement/release the library and explicitly deliver its required rows through Configuration or the scoped owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement/release the library and explicitly deliver its required rows through Configuration or the scoped owner.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "64294f38052f37b6825699626881e68f633c044022a0c19adbf734e7ae07194c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-15-6",
        "parent_task_id": "task-fixture-dv-15-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "53037712d7b5d348f7253a156fd4129c4ae2df3ec7613ec394febeeec64c2896",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-15-7",
        "parent_task_id": "task-fixture-dv-15-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-15",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain code-plus-row dependency checks and the inert-toggle failure.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain code-plus-row dependency checks and the inert-toggle failure.\nCase: fixture-dv-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c56463d98b8f7dd6ff7edad18c493cac411993a0276e5713e8516d357d3426a4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-15-tests",
        "parent_task_id": "task-fixture-dv-15-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-15-executor",
        "parent_task_id": "task-fixture-dv-15-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-15\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-15-Spawn",
        "case_id": "fixture-dv-15",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-15-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Identify the generic code capability, its enabling configuration and message keys, across published package and serving consumers.\nPrepare the bounded work: Implement/release the library and explicitly deliver its required rows through Configuration or the scoped owner.\nReturn evidence sufficient to test: Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.\nReject this false completion: A successful build with no enabling row is reported as a working control: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-15-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-15-Plan",
        "case_id": "fixture-dv-15",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-15-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-15",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-15-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-15-PlanConfirmation",
        "case_id": "fixture-dv-15",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-15-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-15",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-15-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-15-Result",
        "case_id": "fixture-dv-15",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-15-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-15-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-15-Verdict",
        "case_id": "fixture-dv-15",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-15-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A successful build with no enabling row is reported as a working control: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-15-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement/release the library and explicitly deliver its required rows through Configuration or the scoped owner.",
      "case_specific_proof": "Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00343"
            },
            "body": {
              "module": "support",
              "description": "Configurable operator checks and messages with DB rows",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00344"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00345"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Trigger the control on target; required invalid input is blocked, valid input passes and the Bulgarian message resolves."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00346"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00347"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain code-plus-row dependency checks and the inert-toggle failure."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00348"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00349"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00350"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00351"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Configurable operator checks and messages with DB rows",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check whether the code exists but lacks activation or messages before writing new code."
      }
    ]
  },
  "DV-16": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-16-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1ce37e14d1cce9e1b05a9038c316ee9835a434d02425436e8bbb30cb41984fe1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-16-1",
        "parent_task_id": "task-fixture-dv-16-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "989cfacfa7563b1fd5b118d8347ce08fee043c6e65ec91085fe34c6960f6d3d0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-16-2",
        "parent_task_id": "task-fixture-dv-16-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6db18aa168353abdc7e8b6f1a73f0698c64eae36358e3a121fadda081f09a3d4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-16-3",
        "parent_task_id": "task-fixture-dv-16-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\nPrepare the bounded work: Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.\nReturn evidence sufficient to test: The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nReject this false completion: An index is present but the affected query still scans or returns wrong results: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\nPrepare the bounded work: Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.\nReturn evidence sufficient to test: The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nReject this false completion: An index is present but the affected query still scans or returns wrong results: fail.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1c7d19e5e3ea33f29e94ab7f217fe9a8132a18f168a248767eb1b3183035bc78",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-16-4",
        "parent_task_id": "task-fixture-dv-16-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\nPrepare the bounded work: Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.\nReturn evidence sufficient to test: The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nReject this false completion: An index is present but the affected query still scans or returns wrong results: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\nPrepare the bounded work: Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.\nReturn evidence sufficient to test: The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nReject this false completion: An index is present but the affected query still scans or returns wrong results: fail.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8785fca342cbe38d999e80f2383689318f399d4ee8a1c6dc063ea0e275d4a67f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-16-5",
        "parent_task_id": "task-fixture-dv-16-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "277c051dbbe54064b3d4453da49818e9a763bb8e414399cec4cab9bbe3cbe72f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-16-6",
        "parent_task_id": "task-fixture-dv-16-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c26dd74cfceddd9f789564e26601e091261254ba242dfd1add820fc98651b659",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-16-7",
        "parent_task_id": "task-fixture-dv-16-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "be5ef65e5db129978b29f9bf8c4aaeb90daae2eee74c59fd4f535581b5df8a2a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-16-8",
        "parent_task_id": "task-fixture-dv-16-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-16",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the bounded workload and failure injection as regression evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the bounded workload and failure injection as regression evidence.\nCase: fixture-dv-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "94898d2d4ca000f8f7b6911dbc757d6b690f05f0cdd345ed5e8220c6571d8a46",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-16-tests",
        "parent_task_id": "task-fixture-dv-16-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-16-executor",
        "parent_task_id": "task-fixture-dv-16-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-16\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-16-Spawn",
        "case_id": "fixture-dv-16",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-16-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Use incident evidence to reproduce the bounded clamp/index/error defect and identify all consuming services.\nPrepare the bounded work: Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.\nReturn evidence sufficient to test: The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.\nReject this false completion: An index is present but the affected query still scans or returns wrong results: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-16-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-16-Plan",
        "case_id": "fixture-dv-16",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-16-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-16",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-16-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-16-PlanConfirmation",
        "case_id": "fixture-dv-16",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-16-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-16",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-16-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-16-Result",
        "case_id": "fixture-dv-16",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-16-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-16-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-16-Verdict",
        "case_id": "fixture-dv-16",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-16-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "An index is present but the affected query still scans or returns wrong results: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-16-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Implement the smallest approved robustness fix, test boundaries and rebuild/deploy declared consumers.",
      "case_specific_proof": "The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00352"
            },
            "body": {
              "module": "support",
              "description": "Incident-driven robustness fix (clamp, index, error leak)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00353"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00354"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The original failure and boundary workload pass on the target without masking valid results; relevant consumers show the new revision."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00355"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00356"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the bounded workload and failure injection as regression evidence."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00357"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00358"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00359"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00360"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Incident-driven robustness fix (clamp, index, error leak)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Reproduce against the current deployed library and workload; a new outage is not automatically the same mechanism."
      }
    ]
  },
  "DV-17": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-17-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9f20dcd809ec75aa74c913c9aae653b98f97e9da1121d7b89543e21b8defa8c1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-17-1",
        "parent_task_id": "task-fixture-dv-17-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a25f6fe4ab09de75c885f52981710e9955f34583f049c22f7a8572e1908d6926",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-17-2",
        "parent_task_id": "task-fixture-dv-17-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bc168323cb83c79c112c3fcdbf80cd5ee5cb97a82c7bc8c533441776d8ab8454",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-17-3",
        "parent_task_id": "task-fixture-dv-17-2",
        "profile_key": "source.planner",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.planner. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f5a1c482bc3d790cb2f34990c03c2b3e5d2330768c03306200585e8fa63f2484",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-planner"
      },
      {
        "task_id": "task-fixture-dv-17-4",
        "parent_task_id": "task-fixture-dv-17-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "708682d1778b80e2e6d5ddb753b44890492e98d2111f41aff20378cda19837b5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-17-5",
        "parent_task_id": "task-fixture-dv-17-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "418d5084c609add612c512e06b557158eaa3ec7dee619058a3d40fa653306c75",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-17-6",
        "parent_task_id": "task-fixture-dv-17-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8b8cb63422b1b0dbcb498046c2dd4e57787caee2b8745770f21ca85a3c38845a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-17-7",
        "parent_task_id": "task-fixture-dv-17-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1723a098397bad1c29e2b92f8ddd4964a46bb7e6ed8789df85654467da317ee9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-17-8",
        "parent_task_id": "task-fixture-dv-17-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f06f021bb5d60df609ec386cfb2a8271b9cc030c0b8541864d4db4bd20747051",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-17-9",
        "parent_task_id": "task-fixture-dv-17-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-17",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain directional path maps, target-only exceptions and observed head relationships.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain directional path maps, target-only exceptions and observed head relationships.\nCase: fixture-dv-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "468f543fe8ce02565659d1075d2ae75a59cea7a278b07c58c5a137749dc2bdc9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-17-tests",
        "parent_task_id": "task-fixture-dv-17-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-17-executor",
        "parent_task_id": "task-fixture-dv-17-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-17\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-17-Spawn",
        "case_id": "fixture-dv-17",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-17-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.planner",
          "profile_version": 1,
          "task_text": "Establish: Pin source and target heads, actual layouts, target-only fixes and semantic correspondence; detect non-fast-forward history changes.\nPrepare the bounded work: Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.\nReturn evidence sufficient to test: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.\nReject this false completion: Protected target history was rewritten after approval: invalidate preflight and re-review.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-17-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-17-Plan",
        "case_id": "fixture-dv-17",
        "task_path": "root/source-root/source-planner",
        "sender": {
          "task_id": "task-fixture-dv-17-3",
          "profile_key": "source.planner",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-17",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-17-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-17-PlanConfirmation",
        "case_id": "fixture-dv-17",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-17-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-17",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-17-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-17-Result",
        "case_id": "fixture-dv-17",
        "task_path": "root/source-root/source-planner",
        "sender": {
          "task_id": "task-fixture-dv-17-3",
          "profile_key": "source.planner",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-17-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-17-Verdict",
        "case_id": "fixture-dv-17",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-17-6",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Protected target history was rewritten after approval: invalidate preflight and re-review.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-17-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Reapply the reviewed semantic change in the requested direction without discarding target-only work; review the resulting target diff.",
      "case_specific_proof": "Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00361"
            },
            "body": {
              "module": "support",
              "description": "Branch reconciliation and merge-from-master ports (flat-layout upkeep)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00362"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00363"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Target tests and explicit equivalence evidence cover the intended change; source subject matching is insufficient."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00364"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00365"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain directional path maps, target-only exceptions and observed head relationships."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00366"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00367"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00368"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00369"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Branch reconciliation and merge-from-master ports (flat-layout upkeep)",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Measure current heads and differences again; a historic path map is only a hypothesis."
      }
    ]
  },
  "DV-18": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-18-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "902e0f5b3c56af9242cad333fdef4433d2e7fbb23dd717ce48fa8a978a8d036b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-18-1",
        "parent_task_id": "task-fixture-dv-18-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ce3eecc7a1fea5a3a15fd4957eb0037c7f0c41df87f4c677e76de0bd81aa2fbf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-18-2",
        "parent_task_id": "task-fixture-dv-18-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "49c78be9faf22b2c28f676189cf6bc5ce9b4d9ba4619d86afd810fd075b212e8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-18-3",
        "parent_task_id": "task-fixture-dv-18-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Establish: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\nPrepare the bounded work: Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.\nReturn evidence sufficient to test: A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nReject this false completion: Generated lock/schema changes are excluded from review and hide an incompatible dependency: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\nPrepare the bounded work: Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.\nReturn evidence sufficient to test: A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nReject this false completion: Generated lock/schema changes are excluded from review and hide an incompatible dependency: reject.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "43edfa89e0d548bda0ad21221403242d9fa5bc888f426b9f3dc7044dd672dca9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-18-4",
        "parent_task_id": "task-fixture-dv-18-2",
        "profile_key": "source.implementer.serdica-ui",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-ui",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Establish: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\nPrepare the bounded work: Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.\nReturn evidence sufficient to test: A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nReject this false completion: Generated lock/schema changes are excluded from review and hide an incompatible dependency: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-ui. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\nPrepare the bounded work: Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.\nReturn evidence sufficient to test: A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nReject this false completion: Generated lock/schema changes are excluded from review and hide an incompatible dependency: reject.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-ui/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "77712ab3f2b1d5424f4ac9040c5c0ffc1af2ea91d79a23e21f0d23dcbe997ac2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-ui"
      },
      {
        "task_id": "task-fixture-dv-18-5",
        "parent_task_id": "task-fixture-dv-18-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "21c75fa7b1d3353502ce9ab2a283f082f0975bf1e46d8853bdd086ab8a54b43a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-18-6",
        "parent_task_id": "task-fixture-dv-18-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "99d6d087de3d64e2d36fd46b10620241af6669790a8d4eaf979833c9e6858552",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-18-7",
        "parent_task_id": "task-fixture-dv-18-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "51ff33e26663b032d0d4c632b73657a39828497a3fe279aa4c09d32cb5de656f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-18-8",
        "parent_task_id": "task-fixture-dv-18-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-18",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain toolchain compatibility and the reproducible failure/fix, with versions.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain toolchain compatibility and the reproducible failure/fix, with versions.\nCase: fixture-dv-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "089f53573ba55e207a146913472869bb842b6bc126e129ecf8017eb520e72595",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-18-tests",
        "parent_task_id": "task-fixture-dv-18-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-18-executor",
        "parent_task_id": "task-fixture-dv-18-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-18\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-18-Spawn",
        "case_id": "fixture-dv-18",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-18-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Identify the failing build/runtime boundary, actual dependency graph, pipeline identity and generated outputs affected.\nPrepare the bounded work: Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.\nReturn evidence sufficient to test: A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.\nReject this false completion: Generated lock/schema changes are excluded from review and hide an incompatible dependency: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-18-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-18-Plan",
        "case_id": "fixture-dv-18",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-18-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-18",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-18-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-18-PlanConfirmation",
        "case_id": "fixture-dv-18",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-18-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-18",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-18-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-18-Result",
        "case_id": "fixture-dv-18",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-18-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-18-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-18-Verdict",
        "case_id": "fixture-dv-18",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-18-5",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Generated lock/schema changes are excluded from review and hide an incompatible dependency: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-18-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Make the scoped tooling/dependency/pipeline change; review lockfiles, generated schemas and instruction files as relevant changes.",
      "case_specific_proof": "A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00370"
            },
            "body": {
              "module": "support",
              "description": "Pipeline, registry, dependency and tooling maintenance on the customer branch",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00371"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00372"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: A clean reproducible build and the declared runtime/job checks pass; image publication alone is not deployment proof."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00373"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00374"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain toolchain compatibility and the reproducible failure/fix, with versions."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00375"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00376"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00377"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00378"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Pipeline, registry, dependency and tooling maintenance on the customer branch",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Reproduce on the current toolchain and inspect dependency changes before adopting the old command."
      }
    ]
  },
  "DV-19": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-dv-19-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The active service reads the intended route/setting and required integration works on its target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The active service reads the intended route/setting and required integration works on its target.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "860bdf072d634f7c524b861701a0fa7ad0cc639a9521fc98eb54beee3756c089",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-dv-19-1",
        "parent_task_id": "task-fixture-dv-19-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "59e5ee50bf763d49b1bde9dd5e010864e75a3f665f756333fcfb83f4415fcd2d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-dv-19-2",
        "parent_task_id": "task-fixture-dv-19-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The active service reads the intended route/setting and required integration works on its target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The active service reads the intended route/setting and required integration works on its target.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "38be95d0f7a48c1223b9b423cff8bec42d5f40ca006bf7e962f892019f4f7e22",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-dv-19-3",
        "parent_task_id": "task-fixture-dv-19-2",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\nPrepare the bounded work: Apply only approved target values through the declared config/image release; keep secrets in the existing secret store.\nReturn evidence sufficient to test: The active service reads the intended route/setting and required integration works on its target.\nReject this false completion: A local file reset overwrites unrelated target routes or secret references: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\nPrepare the bounded work: Apply only approved target values through the declared config/image release; keep secrets in the existing secret store.\nReturn evidence sufficient to test: The active service reads the intended route/setting and required integration works on its target.\nReject this false completion: A local file reset overwrites unrelated target routes or secret references: reject.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "fe3193b43c1cbb016a8b8ec54a087bac5d0a3665b79634c9ffd77ae5d3839e13",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-dv-19-4",
        "parent_task_id": "task-fixture-dv-19-2",
        "profile_key": "source.reviewer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The active service reads the intended route/setting and required integration works on its target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.reviewer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The active service reads the intended route/setting and required integration works on its target.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3b388b058c2e43f87bec3c3964669c46e553618abbdab49f771870fcc8c1a92d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-reviewer"
      },
      {
        "task_id": "task-fixture-dv-19-5",
        "parent_task_id": "task-fixture-dv-19-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply only approved target values through the declared config/image release; keep secrets in the existing secret store.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply only approved target values through the declared config/image release; keep secrets in the existing secret store.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5a5b8485c60f4152236ebb18d8e5b4d23392675bc0008b735179e09cf6d5f7dc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-dv-19-6",
        "parent_task_id": "task-fixture-dv-19-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The active service reads the intended route/setting and required integration works on its target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The active service reads the intended route/setting and required integration works on its target.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "38a1c192738dca866a94a61e5d703a91403aff8293c2682380e3290dd8ad4c3d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-dv-19-7",
        "parent_task_id": "task-fixture-dv-19-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-DV-19",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the environment-specific setting contract and accidental-reset regression.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the environment-specific setting contract and accidental-reset regression.\nCase: fixture-dv-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 30 Source/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e6075b609f85e62f61e9442d3b55476a9d682264c0e13f1b4f596339aa1bf6bf",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-dv-19-tests",
        "parent_task_id": "task-fixture-dv-19-2",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-dv-19-executor",
        "parent_task_id": "task-fixture-dv-19-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-dv-19\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-dv-19-Spawn",
        "case_id": "fixture-dv-19",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-19-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "task_text": "Establish: Compare environment-specific appsettings and runtime consumption; separate intended configuration from accidental local reset.\nPrepare the bounded work: Apply only approved target values through the declared config/image release; keep secrets in the existing secret store.\nReturn evidence sufficient to test: The active service reads the intended route/setting and required integration works on its target.\nReject this false completion: A local file reset overwrites unrelated target routes or secret references: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "source/serdica-backend",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-dv-19-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-dv-19-Plan",
        "case_id": "fixture-dv-19",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-19-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-19",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-dv-19-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-dv-19-PlanConfirmation",
        "case_id": "fixture-dv-19",
        "task_path": "root/source-root",
        "sender": {
          "task_id": "task-fixture-dv-19-2",
          "profile_key": "source.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-dv-19",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-dv-19-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-dv-19-Result",
        "case_id": "fixture-dv-19",
        "task_path": "root/source-root/source-implementer-serdica-backend",
        "sender": {
          "task_id": "task-fixture-dv-19-3",
          "profile_key": "source.implementer.serdica-backend",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-dv-19-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-dv-19-Verdict",
        "case_id": "fixture-dv-19",
        "task_path": "root/source-root/source-reviewer",
        "sender": {
          "task_id": "task-fixture-dv-19-4",
          "profile_key": "source.reviewer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A local file reset overwrites unrelated target routes or secret references: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-dv-19-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply only approved target values through the declared config/image release; keep secrets in the existing secret store.",
      "case_specific_proof": "The active service reads the intended route/setting and required integration works on its target.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00379"
            },
            "body": {
              "module": "support",
              "description": "`appsettings.json` as code",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00380"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00381"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The active service reads the intended route/setting and required integration works on its target."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00382"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00383"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the environment-specific setting contract and accidental-reset regression."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00384"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00385"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00386"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00387"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: `appsettings.json` as code",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Read the effective setting and target lineage; never copy one environment's complete file."
      }
    ]
  },
  "CF-01": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-01-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended customer action succeeds and both baseline/any twin rule are restored under H7.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended customer action succeeds and both baseline/any twin rule are restored under H7.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "73a8f3a6767d205a3c2f83960f2fa3e424e0165697d3384a62e334a7fbe81dab",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-01-1",
        "parent_task_id": "task-fixture-cf-01-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3eb854aa5ef815286b64cd9a9c943a93e5ef5cb62a03c3db25f343c1b4c06876",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-01-2",
        "parent_task_id": "task-fixture-cf-01-0",
        "profile_key": "support.resolution",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/methodologies",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Establish: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\nPrepare the bounded work: Route the temporary exception to Data and Information; persist the relax/action/restore plan before the first gated change.\nReturn evidence sufficient to test: The intended customer action succeeds and both baseline/any twin rule are restored under H7.\nReject this false completion: A supposedly policy-specific threshold actually affects every policy using the shared row: require the full impact gate.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.resolution. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\nPrepare the bounded work: Route the temporary exception to Data and Information; persist the relax/action/restore plan before the first gated change.\nReturn evidence sufficient to test: The intended customer action succeeds and both baseline/any twin rule are restored under H7.\nReject this false completion: A supposedly policy-specific threshold actually affects every policy using the shared row: require the full impact gate.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/methodologies/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ab0b0c79b2dc3be9f31136622aefc3813accc8caa2f41b5a2ac198163446a5ed",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-resolution"
      },
      {
        "task_id": "task-fixture-cf-01-3",
        "parent_task_id": "task-fixture-cf-01-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended customer action succeeds and both baseline/any twin rule are restored under H7.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended customer action succeeds and both baseline/any twin rule are restored under H7.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "46816bbd7b0b285a38b9d162559ce7d8b1e72c5f5919d633827ba69a2dd13517",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-cf-01-4",
        "parent_task_id": "task-fixture-cf-01-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Route the temporary exception to Data and Information; persist the relax/action/restore plan before the first gated change.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Route the temporary exception to Data and Information; persist the relax/action/restore plan before the first gated change.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "183d0061a09cd47cecd2037d88504a387f508d02abec74a3bea8971b98cbbb2b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-01-5",
        "parent_task_id": "task-fixture-cf-01-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended customer action succeeds and both baseline/any twin rule are restored under H7.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended customer action succeeds and both baseline/any twin rule are restored under H7.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4e5e864be80cb4f8689bc1d20948b9316ca617f132a38c2810611cd912510391",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-01-6",
        "parent_task_id": "task-fixture-cf-01-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-01",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record recurring rule/trigger evidence and link the permanent fix instead of accumulating indefinite exceptions.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record recurring rule/trigger evidence and link the permanent fix instead of accumulating indefinite exceptions.\nCase: fixture-cf-01; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8457de33b30fdc8c5ffe27e078b7858da49e6b988074a0dd163f6ebaaa5e0b33",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-01-executor",
        "parent_task_id": "task-fixture-cf-01-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-01\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-01-Spawn",
        "case_id": "fixture-cf-01",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-cf-01-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "task_text": "Establish: Resolve the blocked policy and actual IPAL/ABACUS rule, its shared audience, current value and existing exceptions.\nPrepare the bounded work: Route the temporary exception to Data and Information; persist the relax/action/restore plan before the first gated change.\nReturn evidence sufficient to test: The intended customer action succeeds and both baseline/any twin rule are restored under H7.\nReject this false completion: A supposedly policy-specific threshold actually affects every policy using the shared row: require the full impact gate.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/methodologies",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-01-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-01-Plan",
        "case_id": "fixture-cf-01",
        "task_path": "root/support-resolution",
        "sender": {
          "task_id": "task-fixture-cf-01-2",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-01",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-01-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-01-PlanConfirmation",
        "case_id": "fixture-cf-01",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-cf-01-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-01",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-01-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-01-Result",
        "case_id": "fixture-cf-01",
        "task_path": "root/support-resolution",
        "sender": {
          "task_id": "task-fixture-cf-01-2",
          "profile_key": "support.resolution",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-01-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-01-Verdict",
        "case_id": "fixture-cf-01",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-cf-01-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A supposedly policy-specific threshold actually affects every policy using the shared row: require the full impact gate.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-01-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Route the temporary exception to Data and Information; persist the relax/action/restore plan before the first gated change.",
      "case_specific_proof": "The intended customer action succeeds and both baseline/any twin rule are restored under H7.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00388"
            },
            "body": {
              "module": "support",
              "description": "Threshold or LOV relax for one policy, then revert",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00389"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00390"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended customer action succeeds and both baseline/any twin rule are restored under H7."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00391"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00392"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record recurring rule/trigger evidence and link the permanent fix instead of accumulating indefinite exceptions."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00393"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00394"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00395"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00396"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: Threshold or LOV relax for one policy, then revert",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Look up previous exceptions and causal fixes, then re-read the live rule and its audience."
      }
    ]
  },
  "CF-02": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-02-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4ebf97370928a8bdb745264ca06d8ed28795c2108877a46aaf701e7a39214236",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-02-1",
        "parent_task_id": "task-fixture-cf-02-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0853d4f0179de40cb2e507403108e1e80728de5a9ca3c9656d6067fb79dc0db5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-02-2",
        "parent_task_id": "task-fixture-cf-02-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9730093d3ad1ddb8c1f85e4f5341828eef606d5800c73da9680efe9f3aa0e2df",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-02-3",
        "parent_task_id": "task-fixture-cf-02-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Establish: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\nPrepare the bounded work: Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.\nReturn evidence sufficient to test: Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nReject this false completion: The row exists but is OFF, or the INSIS twin is omitted: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\nPrepare the bounded work: Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.\nReturn evidence sufficient to test: Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nReject this false completion: The row exists but is OFF, or the INSIS twin is omitted: fail.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3586359bdeea99351bbf18d3e2d5fbc176c1f5577777205b5e7cfdfa174865fc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-02-4",
        "parent_task_id": "task-fixture-cf-02-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Establish: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\nPrepare the bounded work: Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.\nReturn evidence sufficient to test: Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nReject this false completion: The row exists but is OFF, or the INSIS twin is omitted: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\nPrepare the bounded work: Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.\nReturn evidence sufficient to test: Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nReject this false completion: The row exists but is OFF, or the INSIS twin is omitted: fail.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "db6294f4614072adf799be39e3fbb575393d4402038b53c85834a7708b31ffe5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-02-5",
        "parent_task_id": "task-fixture-cf-02-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2d6ba5204a6c87c02afc87eca194d7e2b5fc336cd6c51ae30371c5da89ce98ac",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-02-6",
        "parent_task_id": "task-fixture-cf-02-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4dc28c30f28bb9846e2b252df402e4a48fef507bb2e63514ced0b02d0810eaa3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-02-7",
        "parent_task_id": "task-fixture-cf-02-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d4d206f29cbc41fcdcebaf229f3532c9cfafce348ec4d4ccb600c76ac31f7e9a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-02-8",
        "parent_task_id": "task-fixture-cf-02-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-02",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the condition-to-capability mapping, twin dependencies and examples.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the condition-to-capability mapping, twin dependencies and examples.\nCase: fixture-cf-02; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "efc6ede3b499d0f617332efa5b45dd3922dd2eadd370c9c43af057842e2f31c7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-02-executor",
        "parent_task_id": "task-fixture-cf-02-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-02\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-02-Spawn",
        "case_id": "fixture-cf-02",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-02-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Export the affected rule and test the requested condition against existing code capability, IPAL, ABACUS and INSIS behaviour.\nPrepare the bounded work: Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.\nReturn evidence sufficient to test: Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.\nReject this false completion: The row exists but is OFF, or the INSIS twin is omitted: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-02-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-02-Plan",
        "case_id": "fixture-cf-02",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-02-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-02",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-02-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-02-PlanConfirmation",
        "case_id": "fixture-cf-02",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-02-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-02",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-02-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-02-Result",
        "case_id": "fixture-cf-02",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-02-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-02-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-02-Verdict",
        "case_id": "fixture-cf-02",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-02-5",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The row exists but is OFF, or the INSIS twin is omitted: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-02-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Change the relevant existing control; computed logic recruits Development and INSIS-owned work becomes an external dependency.",
      "case_specific_proof": "Positive and negative examples prove when the rule fires; the requested target and all declared twins pass.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00397"
            },
            "body": {
              "module": "configuration",
              "description": "Permanent check: add, change or explain a control",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00398"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00399"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Positive and negative examples prove when the rule fires; the requested target and all declared twins pass."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00400"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00401"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the condition-to-capability mapping, twin dependencies and examples."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00402"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00403"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00404"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00405"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Permanent check: add, change or explain a control",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Search prior rule changes, export current state and distinguish missing activation from missing code."
      }
    ]
  },
  "CF-03": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-03-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "72ed8129f1415e994e27b788d5636865c0564ddce99a2fa8ea73d2bc9e5c71fc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-03-1",
        "parent_task_id": "task-fixture-cf-03-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "28c2c10908bec1924fe54565f566702a2ea155172e77d48ec1370477e97e721b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-03-2",
        "parent_task_id": "task-fixture-cf-03-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0820bb352f32096a4da89f573810e6c52b7f96c4564aa384b483f85e83096e1e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-03-3",
        "parent_task_id": "task-fixture-cf-03-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Establish: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\nPrepare the bounded work: Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.\nReturn evidence sufficient to test: The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nReject this false completion: An overly broad group grants the exception to unlisted users: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\nPrepare the bounded work: Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.\nReturn evidence sufficient to test: The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nReject this false completion: An overly broad group grants the exception to unlisted users: reject.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1e857b0f125b6438b64b358f238cb6235a420fd892602ea16ec7a54daea85a8a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-03-4",
        "parent_task_id": "task-fixture-cf-03-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Establish: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\nPrepare the bounded work: Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.\nReturn evidence sufficient to test: The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nReject this false completion: An overly broad group grants the exception to unlisted users: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\nPrepare the bounded work: Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.\nReturn evidence sufficient to test: The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nReject this false completion: An overly broad group grants the exception to unlisted users: reject.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "79a4b68ba17114e47b5b67f16014f6b34ecb238c7cd8f6fcfa5d9a11c07a529d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-03-5",
        "parent_task_id": "task-fixture-cf-03-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5de12f9334ece38ff7b3911436b7ba012927da4daf4db4ce384c7497b6496b2a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-03-6",
        "parent_task_id": "task-fixture-cf-03-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c689efb30e7d6bb4a8fd7576feee5e9ce96710126b6e77dd15dd78e60c2eb23b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-03-7",
        "parent_task_id": "task-fixture-cf-03-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bcf7087b0b869d3de41629192b383f133e80f81852d91044481279a6dfa2e82f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-03-8",
        "parent_task_id": "task-fixture-cf-03-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-03",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the permission mapping and positive/negative role tests without personal identifiers.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the permission mapping and positive/negative role tests without personal identifiers.\nCase: fixture-cf-03; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3536c3f3089f77eac7ebe07fa735898db3de0099b158b995361c5769e9b04fb6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-03-executor",
        "parent_task_id": "task-fixture-cf-03-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-03\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-03-Spawn",
        "case_id": "fixture-cf-03",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-03-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Resolve approved identity/group handles and compare effective bypass/visibility rights across both validation systems and product routes.\nPrepare the bounded work: Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.\nReturn evidence sufficient to test: The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.\nReject this false completion: An overly broad group grants the exception to unlisted users: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-03-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-03-Plan",
        "case_id": "fixture-cf-03",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-03-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-03",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-03-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-03-PlanConfirmation",
        "case_id": "fixture-cf-03",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-03-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-03",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-03-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-03-Result",
        "case_id": "fixture-cf-03",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-03-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-03-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-03-Verdict",
        "case_id": "fixture-cf-03",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-03-5",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "An overly broad group grants the exception to unlisted users: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-03-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the explicit role/bypass delta under shared-impact and target gates; external identity administration stays with its owner.",
      "case_specific_proof": "The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00406"
            },
            "body": {
              "module": "configuration",
              "description": "Who may bypass, who may see: overrule groups, per-user and per-agent lists, product roles",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00407"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00408"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended identity can do the permitted action; an unlisted identity cannot, and unrelated roles remain unchanged."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00409"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00410"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the permission mapping and positive/negative role tests without personal identifiers."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00411"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00412"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00413"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00414"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Who may bypass, who may see: overrule groups, per-user and per-agent lists, product roles",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck current group membership, scope and requested authority; no previous approval is inherited."
      }
    ]
  },
  "CF-04": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-04-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6fcaed2fc66eaf5acb55d617ac441b481f0eb56c85a94ae133e95d374ce53f39",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-04-1",
        "parent_task_id": "task-fixture-cf-04-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "426577071b5fc5f939f716f592dfcd6c1c81576e19eedd42787d60cf430a28ef",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-04-2",
        "parent_task_id": "task-fixture-cf-04-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "70b7687dc004ce58311257c523071e00fd5ec71631edbf742153bc6b6cd866ac",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-04-3",
        "parent_task_id": "task-fixture-cf-04-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\nPrepare the bounded work: Create the selected version delta, compile under its declared effects and release only the requested target set.\nReturn evidence sufficient to test: Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nReject this false completion: The new version is present but the engine still selects the old tariff: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\nPrepare the bounded work: Create the selected version delta, compile under its declared effects and release only the requested target set.\nReturn evidence sufficient to test: Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nReject this false completion: The new version is present but the engine still selects the old tariff: fail.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6d72cb94b715c0fc4d4db683146390d6e2a3188074b5e65326068befc0aaa647",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-04-4",
        "parent_task_id": "task-fixture-cf-04-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\nPrepare the bounded work: Create the selected version delta, compile under its declared effects and release only the requested target set.\nReturn evidence sufficient to test: Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nReject this false completion: The new version is present but the engine still selects the old tariff: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\nPrepare the bounded work: Create the selected version delta, compile under its declared effects and release only the requested target set.\nReturn evidence sufficient to test: Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nReject this false completion: The new version is present but the engine still selects the old tariff: fail.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "aa9cc07d1c0315b2797178cb2c8f53ffeded8659edd0f18361042d3da0536372",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-04-5",
        "parent_task_id": "task-fixture-cf-04-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "42554d15b1635e985ee34ab06c1ec2577437dcbb907edee9a30df6388981fa49",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-04-6",
        "parent_task_id": "task-fixture-cf-04-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Create the selected version delta, compile under its declared effects and release only the requested target set.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Create the selected version delta, compile under its declared effects and release only the requested target set.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e5ef63c728cfc44da325647556c3a91ed1969de42fc6bdc20d5b2b0d1ef3a3f7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-04-7",
        "parent_task_id": "task-fixture-cf-04-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d25759eb8d42f9534faf86637a134e8e397dea1244c0bd275f5d4d86e8b7625b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-04-8",
        "parent_task_id": "task-fixture-cf-04-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-04",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain reviewed rating examples and the actual target version matrix.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain reviewed rating examples and the actual target version matrix.\nCase: fixture-cf-04; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "49fc1038e7c7ba3ef04d78ec464a2bbc75168a22761d0875828fabfd7e37b8e5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-04-executor",
        "parent_task_id": "task-fixture-cf-04-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-04\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-04-Spawn",
        "case_id": "fixture-cf-04",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-04-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "task_text": "Establish: Read the current tariff versions, effective dates, requested rates/limits and any consuming INSIS catalogue obligations.\nPrepare the bounded work: Create the selected version delta, compile under its declared effects and release only the requested target set.\nReturn evidence sufficient to test: Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.\nReject this false completion: The new version is present but the engine still selects the old tariff: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/abacus",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-04-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-04-Plan",
        "case_id": "fixture-cf-04",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-04-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-04",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-04-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-04-PlanConfirmation",
        "case_id": "fixture-cf-04",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-04-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-04",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-04-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-04-Result",
        "case_id": "fixture-cf-04",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-04-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-04-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-04-Verdict",
        "case_id": "fixture-cf-04",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-04-5",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The new version is present but the engine still selects the old tariff: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-04-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Create the selected version delta, compile under its declared effects and release only the requested target set.",
      "case_specific_proof": "Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00415"
            },
            "body": {
              "module": "configuration",
              "description": "Tariff refresh on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00416"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00417"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Worked examples at rate/effective-date boundaries pass for every changed template; downstream limits match where in scope."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00418"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00419"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain reviewed rating examples and the actual target version matrix."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00420"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00421"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00422"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00423"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Tariff refresh on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check current effective versions and requested scope before importing another tariff."
      }
    ]
  },
  "CF-05": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-05-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c77c19eaf040734114fa681ef7b78659106adef2f6f294c7b3fd9b53aeacfa60",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-05-1",
        "parent_task_id": "task-fixture-cf-05-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0cba2c1b5ce7f8c4e5ae8361c7ff4f25e914d8c628688a4ff85e27e22cbdcef8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-05-2",
        "parent_task_id": "task-fixture-cf-05-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "aaeb265c7bcf6b31e70e6771cc5c3a9ccc5d3bac8797ed5304a53e3221253c34",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-05-3",
        "parent_task_id": "task-fixture-cf-05-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Establish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "359614211069179291a8f0d658b3af3e70ca5e57a11678bba8fbbf8ee33cdb67",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-05-4",
        "parent_task_id": "task-fixture-cf-05-2",
        "profile_key": "configuration.offer.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/offer",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Establish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.offer.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/offer/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "64045dc6de4cc6dd490b02c2fcbdd17a93bfb03c76107fbb815b95cef9cec26a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-offer-stage"
      },
      {
        "task_id": "task-fixture-cf-05-5",
        "parent_task_id": "task-fixture-cf-05-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Establish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a06d50f781ca04e010371d22aeb8326f66d029a3012801a17e499754a6ba672c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-05-6",
        "parent_task_id": "task-fixture-cf-05-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "70ffb9a5f55420ad1c19164f762cf1dd1abb0070b97baa214092fb8d8ec6f65d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-05-7",
        "parent_task_id": "task-fixture-cf-05-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6341058cfe40cae104f843bd5c5b9889ab128b4437c428b81408bf577d6c853e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-05-8",
        "parent_task_id": "task-fixture-cf-05-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bbb3566d5ce3502c5ad6ae5b837c632f1d00277d4d64868255e19a17a73ef389",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-05-9",
        "parent_task_id": "task-fixture-cf-05-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-05",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the selector-to-template matrix and per-template test cases; record missing or unreleased items explicitly.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the selector-to-template matrix and per-template test cases; record missing or unreleased items explicitly.\nCase: fixture-cf-05; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e4a0938c926f1354a43cda9b5bc1bdd9310aa6673b9563460b3ad74d637b1d75",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-05-executor",
        "parent_task_id": "task-fixture-cf-05-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-05\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-05-Spawn",
        "case_id": "fixture-cf-05",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-05-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "task_text": "Establish: List the exact broker/channel template keys, selectors, role visibility, effective dates and current rating/offer relationships.\nPrepare the bounded work: Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.\nReturn evidence sufficient to test: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.\nReject this false completion: All templates compile but every caller falls back to the default: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/abacus",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-05-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-05-Plan",
        "case_id": "fixture-cf-05",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-05-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-05",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-05-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-05-PlanConfirmation",
        "case_id": "fixture-cf-05",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-05-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-05",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-05-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-05-Result",
        "case_id": "fixture-cf-05",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-05-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-05-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-05-Verdict",
        "case_id": "fixture-cf-05",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-05-6",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "All templates compile but every caller falls back to the default: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-05-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Fan out S2 work by template using single-template leaf specifications; join offer/role dependencies and compile/release each required item.",
      "case_specific_proof": "Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00424"
            },
            "body": {
              "module": "configuration",
              "description": "Broker, channel or partner rating template on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00425"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00426"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Every selected template is exercised by its intended caller; default and unrelated callers keep their expected prices and visibility."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00427"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00428"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the selector-to-template matrix and per-template test cases; record missing or unreleased items explicitly."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00429"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00430"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00431"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00432"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Broker, channel or partner rating template on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Resolve the caller and active template first; reuse only compatible examples and create a new version delta."
      }
    ]
  },
  "CF-06": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-06-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7dc597ceff4328b6f66ef09ada09ccccf53f89086e9361a2c5b8279594546c0c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-06-1",
        "parent_task_id": "task-fixture-cf-06-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "69f59874575a4b2e0fff045975d4ea70eea4d0d74e9d4946a8b33bae9bcd3928",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-06-2",
        "parent_task_id": "task-fixture-cf-06-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "19151ac2b3d62422b659f5b1c971f146ab7524f2dcc0cd476e139ba6b7ed3da3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-06-3",
        "parent_task_id": "task-fixture-cf-06-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Establish: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\nPrepare the bounded work: Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.\nReturn evidence sufficient to test: The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nReject this false completion: Only HT_DISCOUNT_TYPE is installed while the operative rule is missing: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\nPrepare the bounded work: Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.\nReturn evidence sufficient to test: The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nReject this false completion: Only HT_DISCOUNT_TYPE is installed while the operative rule is missing: no completion.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "76a76ae1110cc9ed1380e1ceb78c89711cfebfb8c7dd812ed69f5aca1761e7d0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-06-4",
        "parent_task_id": "task-fixture-cf-06-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Establish: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\nPrepare the bounded work: Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.\nReturn evidence sufficient to test: The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nReject this false completion: Only HT_DISCOUNT_TYPE is installed while the operative rule is missing: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\nPrepare the bounded work: Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.\nReturn evidence sufficient to test: The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nReject this false completion: Only HT_DISCOUNT_TYPE is installed while the operative rule is missing: no completion.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "33119a66a0f18705db3926cc02bdbb512f47f966e389897ff602f4f7a6c25cce",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-06-5",
        "parent_task_id": "task-fixture-cf-06-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d0515bfcfd36020bf90a56c93d3fe6e0ef81197f612ab80f0fdc37475579f595",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-06-6",
        "parent_task_id": "task-fixture-cf-06-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ed0399995cca1b78e0d5edd623254a37d5b60167326debaa69582a45fa3c6e38",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-06-7",
        "parent_task_id": "task-fixture-cf-06-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "01947676044210dc45129c9b7f99c0f645b22e850d993c52c0a8e4818f5f0379",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-06-8",
        "parent_task_id": "task-fixture-cf-06-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-06",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the three-system rule mapping and worked boundary examples.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the three-system rule mapping and worked boundary examples.\nCase: fixture-cf-06; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "19bc7daccd67d815c1a3741035aebb41f189b865d1ec87d3d2c48ccf7a636cf8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-06-executor",
        "parent_task_id": "task-fixture-cf-06-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-06\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-06-Spawn",
        "case_id": "fixture-cf-06",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-06-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "task_text": "Establish: Reconcile the requested discount/loading/deductible across IPAL definitions, ABACUS rules and INSIS types/effective dates.\nPrepare the bounded work: Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.\nReturn evidence sufficient to test: The same authorised scenario produces the intended amount, limit and deductible on every requested surface.\nReject this false completion: Only HT_DISCOUNT_TYPE is installed while the operative rule is missing: no completion.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/abacus",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-06-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-06-Plan",
        "case_id": "fixture-cf-06",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-06-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-06",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-06-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-06-PlanConfirmation",
        "case_id": "fixture-cf-06",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-06-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-06",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-06-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-06-Result",
        "case_id": "fixture-cf-06",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-06-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-06-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-06-Verdict",
        "case_id": "fixture-cf-06",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-06-5",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Only HT_DISCOUNT_TYPE is installed while the operative rule is missing: no completion.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-06-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the stage delta and tracked INSIS-owner work; coordinate any code dependency before activating the rule.",
      "case_specific_proof": "The same authorised scenario produces the intended amount, limit and deductible on every requested surface.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00433"
            },
            "body": {
              "module": "configuration",
              "description": "Discount, loading or deductible rule",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00434"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00435"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The same authorised scenario produces the intended amount, limit and deductible on every requested surface."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00436"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00437"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the three-system rule mapping and worked boundary examples."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00438"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00439"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00440"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00441"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Discount, loading or deductible rule",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check existing partial delivery and active versions before adding duplicate definitions."
      }
    ]
  },
  "CF-07": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-07-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The value appears under the intended dependent selection and is correctly priced/transferred.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The value appears under the intended dependent selection and is correctly priced/transferred.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d0628525f03de49c24935c0941598d666e8f3b6488fa88060ec48ca051da6387",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-07-1",
        "parent_task_id": "task-fixture-cf-07-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a1d7b70ed6570663e58b062f5479b268905a365da3f8642da518330cd6c8b192",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-07-2",
        "parent_task_id": "task-fixture-cf-07-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The value appears under the intended dependent selection and is correctly priced/transferred.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The value appears under the intended dependent selection and is correctly priced/transferred.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e0c3474a84cf11bd07f90d61891a70d4c549927b7cbd5c6c8ae0c0336d83099d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-07-3",
        "parent_task_id": "task-fixture-cf-07-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Establish: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\nPrepare the bounded work: Apply only the approved business-key additions and labels, with shared scope gates; obtain any external twin from its owner.\nReturn evidence sufficient to test: The value appears under the intended dependent selection and is correctly priced/transferred.\nReject this false completion: A new factor value is selectable but maps to the wrong INSIS code: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\nPrepare the bounded work: Apply only the approved business-key additions and labels, with shared scope gates; obtain any external twin from its owner.\nReturn evidence sufficient to test: The value appears under the intended dependent selection and is correctly priced/transferred.\nReject this false completion: A new factor value is selectable but maps to the wrong INSIS code: fail.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0d4e5d6d4b008804051718891757edb6f14a59692d28cfa5159b92d5af4ef846",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-07-4",
        "parent_task_id": "task-fixture-cf-07-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The value appears under the intended dependent selection and is correctly priced/transferred.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The value appears under the intended dependent selection and is correctly priced/transferred.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "53d38b01d52d2978f379e95894f23b9ecbc33258a7398536b14cd4eaa9780f66",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-07-5",
        "parent_task_id": "task-fixture-cf-07-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply only the approved business-key additions and labels, with shared scope gates; obtain any external twin from its owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply only the approved business-key additions and labels, with shared scope gates; obtain any external twin from its owner.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ea11f73f1c9c880d4b5836fe5e9e66e6d3e3498c217185eb9db0a4142dccad3b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-07-6",
        "parent_task_id": "task-fixture-cf-07-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The value appears under the intended dependent selection and is correctly priced/transferred.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The value appears under the intended dependent selection and is correctly priced/transferred.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f04321776e5806beecd4aa9ef98d959c0e958e7d41955f35c9010fcc62ffab38",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-07-7",
        "parent_task_id": "task-fixture-cf-07-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-07",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain dependency and cross-code checks in the relevant existing skill.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain dependency and cross-code checks in the relevant existing skill.\nCase: fixture-cf-07; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cab4deecd5a765c37990edee54e6ebacbfca93b072095faaa23e1ff637d27aca",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-07-executor",
        "parent_task_id": "task-fixture-cf-07-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-07\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-07-Spawn",
        "case_id": "fixture-cf-07",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-07-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Export factor values/dependencies, global versus product scope, labels and INSIS/ABACUS codes.\nPrepare the bounded work: Apply only the approved business-key additions and labels, with shared scope gates; obtain any external twin from its owner.\nReturn evidence sufficient to test: The value appears under the intended dependent selection and is correctly priced/transferred.\nReject this false completion: A new factor value is selectable but maps to the wrong INSIS code: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-07-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-07-Plan",
        "case_id": "fixture-cf-07",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-07-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-07",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-07-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-07-PlanConfirmation",
        "case_id": "fixture-cf-07",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-07-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-07",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-07-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-07-Result",
        "case_id": "fixture-cf-07",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-07-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-07-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-07-Verdict",
        "case_id": "fixture-cf-07",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-07-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A new factor value is selectable but maps to the wrong INSIS code: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-07-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply only the approved business-key additions and labels, with shared scope gates; obtain any external twin from its owner.",
      "case_specific_proof": "The value appears under the intended dependent selection and is correctly priced/transferred.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00442"
            },
            "body": {
              "module": "configuration",
              "description": "Pricing-factor LOV or dependent value add",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00443"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00444"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The value appears under the intended dependent selection and is correctly priced/transferred."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00445"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00446"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain dependency and cross-code checks in the relevant existing skill."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00447"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00448"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00449"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00450"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Pricing-factor LOV or dependent value add",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Read current value and parent dependencies first; distinguish missing value from missing visibility."
      }
    ]
  },
  "CF-08": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-08-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f2faa4e9d11efa63a53ece0a05de62b6efa88db3531a90fe5f785c7fc7324477",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-08-1",
        "parent_task_id": "task-fixture-cf-08-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inspect the document registration, code selector, exact template parameters and external BI template version.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inspect the document registration, code selector, exact template parameters and external BI template version.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c3a2c1e4fc88013bd543ef1bb46fd1e5ff3be81539368b8d53c13249c5732242",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-08-2",
        "parent_task_id": "task-fixture-cf-08-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "eb1f056d84310b28423b3412ea803cb42039b84dd83c47ac00bc29bf4940a6a4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-08-3",
        "parent_task_id": "task-fixture-cf-08-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Establish: Inspect the document registration, code selector, exact template parameters and external BI template version.\nPrepare the bounded work: Change the declared registration/document set; coordinate Development or BI-owner changes where the template contract differs.\nReturn evidence sufficient to test: The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nReject this false completion: A NULL/zero gate is interpreted as enabled and extra documents are emitted: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inspect the document registration, code selector, exact template parameters and external BI template version.\nPrepare the bounded work: Change the declared registration/document set; coordinate Development or BI-owner changes where the template contract differs.\nReturn evidence sufficient to test: The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nReject this false completion: A NULL/zero gate is interpreted as enabled and extra documents are emitted: reject.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "78300d6ecbf6b742ba0bf2a7f1a9a40bc960c57bf1a7919b3465429f3c41cf46",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-08-4",
        "parent_task_id": "task-fixture-cf-08-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0437690e5050c2a1e8e1656675f210d174d7ea4f9af612e28bc135889d6dfa86",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-08-5",
        "parent_task_id": "task-fixture-cf-08-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Change the declared registration/document set; coordinate Development or BI-owner changes where the template contract differs.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Change the declared registration/document set; coordinate Development or BI-owner changes where the template contract differs.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c11a2355bdf182efde0bbfcb087482c111292306bb76a2e2f91562f55bb87e6d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-08-6",
        "parent_task_id": "task-fixture-cf-08-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "544e39d8deb7b8b8728ff4f31fb1f4931ed80203fc85624994500f34cbfcfda7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-08-7",
        "parent_task_id": "task-fixture-cf-08-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-08",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the registration/selector assertion and repeated inert-cell evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the registration/selector assertion and repeated inert-cell evidence.\nCase: fixture-cf-08; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inspect the document registration, code selector, exact template parameters and external BI template version.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9a00c6e4053ad2382bc6eb3ad24dbc2b920e3bd6b4bd23331249042447aada0e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-08-executor",
        "parent_task_id": "task-fixture-cf-08-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-08\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-08-Spawn",
        "case_id": "fixture-cf-08",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-08-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "task_text": "Establish: Inspect the document registration, code selector, exact template parameters and external BI template version.\nPrepare the bounded work: Change the declared registration/document set; coordinate Development or BI-owner changes where the template contract differs.\nReturn evidence sufficient to test: The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.\nReject this false completion: A NULL/zero gate is interpreted as enabled and extra documents are emitted: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/serdica",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-08-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-08-Plan",
        "case_id": "fixture-cf-08",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-08-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-08",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-08-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-08-PlanConfirmation",
        "case_id": "fixture-cf-08",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-08-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-08",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-08-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-08-Result",
        "case_id": "fixture-cf-08",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-08-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-08-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-08-Verdict",
        "case_id": "fixture-cf-08",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-08-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A NULL/zero gate is interpreted as enabled and extra documents are emitted: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-08-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Change the declared registration/document set; coordinate Development or BI-owner changes where the template contract differs.",
      "case_specific_proof": "The intended document set and copy counts appear; invalid/negative selectors produce no extra documents.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00451"
            },
            "body": {
              "module": "configuration",
              "description": "Print template registration and document-set change",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00452"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00453"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The intended document set and copy counts appear; invalid/negative selectors produce no extra documents."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00454"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00455"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the registration/selector assertion and repeated inert-cell evidence."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00456"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00457"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00458"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00459"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Print template registration and document-set change",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Probe invocation and current template parameters before editing the same cell again."
      }
    ]
  },
  "CF-09": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-09-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "fca2ef0c54529fd40d715e1953eaccae150f9f56f56c99b782860bf50fe4923d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-09-1",
        "parent_task_id": "task-fixture-cf-09-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "607f68cbd78ac888d05f88c1bc1804c3b30073b0fd664cfa18e507a91d71ce23",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-09-2",
        "parent_task_id": "task-fixture-cf-09-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7b12cf789f0fe3689ea0b632ea25a2bbeb053e8fdbb92d51cfc2a2a4754f266b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-09-3",
        "parent_task_id": "task-fixture-cf-09-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Establish: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\nPrepare the bounded work: Coordinate row changes with the separately authorised DDL or external-owner sequence step; never reset an existing counter casually.\nReturn evidence sufficient to test: The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nReject this false completion: The sequence exists but its synonym/grant is missing, or a reset would collide: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\nPrepare the bounded work: Coordinate row changes with the separately authorised DDL or external-owner sequence step; never reset an existing counter casually.\nReturn evidence sufficient to test: The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nReject this false completion: The sequence exists but its synonym/grant is missing, or a reset would collide: fail.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e50fbc0c7a687cc95e35361ee6fdf4f2de8eb209e5140922150908c4b736de77",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-09-4",
        "parent_task_id": "task-fixture-cf-09-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d708d770ea111289b02726f7506273aa8b784ca353c066350fc362deee5916ac",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-cf-09-5",
        "parent_task_id": "task-fixture-cf-09-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate row changes with the separately authorised DDL or external-owner sequence step; never reset an existing counter casually.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate row changes with the separately authorised DDL or external-owner sequence step; never reset an existing counter casually.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "713fe0f758d94c18bb9c4ec0f9818e016fb5d078db4a1e31da0232750299496d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-09-6",
        "parent_task_id": "task-fixture-cf-09-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e6f437447b3869db6d0dd42ce85790c1ce9065826653ead7c24dd6c47752a7b9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-09-7",
        "parent_task_id": "task-fixture-cf-09-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-09",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the complete row/sequence/grant/synonym checklist and yearly scope.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the complete row/sequence/grant/synonym checklist and yearly scope.\nCase: fixture-cf-09; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8bf2b99fc085175fd9e10220a15c19f34810892c755612d7453d6e74ff584fae",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-09-executor",
        "parent_task_id": "task-fixture-cf-09-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-09\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-09-Spawn",
        "case_id": "fixture-cf-09",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-09-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "task_text": "Establish: Read office/product/year numbering rows, current sequence state, grant and synonym existence; identify the authorised sequence owner.\nPrepare the bounded work: Coordinate row changes with the separately authorised DDL or external-owner sequence step; never reset an existing counter casually.\nReturn evidence sufficient to test: The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.\nReject this false completion: The sequence exists but its synonym/grant is missing, or a reset would collide: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/serdica",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-09-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-09-Plan",
        "case_id": "fixture-cf-09",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-09-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-09",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-09-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-09-PlanConfirmation",
        "case_id": "fixture-cf-09",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-09-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-09",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-09-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-09-Result",
        "case_id": "fixture-cf-09",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-09-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-09-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-09-Verdict",
        "case_id": "fixture-cf-09",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-cf-09-4",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The sequence exists but its synonym/grant is missing, or a reset would collide: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-09-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Coordinate row changes with the separately authorised DDL or external-owner sequence step; never reset an existing counter casually.",
      "case_specific_proof": "The correct principal can allocate a unique number for the requested office/product/year under an approved effect test.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00460"
            },
            "body": {
              "module": "configuration",
              "description": "Numbering: the yearly sequence roll, per-office rows, the INSIS sequence with grant and synonym",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00461"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00462"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The correct principal can allocate a unique number for the requested office/product/year under an approved effect test."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00463"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00464"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the complete row/sequence/grant/synonym checklist and yearly scope."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00465"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00466"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00467"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00468"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Numbering: the yearly sequence roll, per-office rows, the INSIS sequence with grant and synonym",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect existing sequence and maximum issued values before applying a known creation pattern."
      }
    ]
  },
  "CF-10": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-10-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "080a5f29dd769d963937dd46c9165cfed9eb9e3d5ca259335836c2640e316b08",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-10-1",
        "parent_task_id": "task-fixture-cf-10-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1f1e779c1b0f8c7708b719ebf78e93610f9057d26aca0e29d569898bf145e6f4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-10-2",
        "parent_task_id": "task-fixture-cf-10-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "11f3c16215033741d3c38bd0f2bb106540327235b0996f9b17dc1c033034276b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-10-3",
        "parent_task_id": "task-fixture-cf-10-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\nPrepare the bounded work: Apply the approved existing-product delta with explicit per-cover scope and external dependencies.\nReturn evidence sufficient to test: Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nReject this false completion: Copying TEST's smaller deductible set removes valid PROD definitions: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\nPrepare the bounded work: Apply the approved existing-product delta with explicit per-cover scope and external dependencies.\nReturn evidence sufficient to test: Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nReject this false completion: Copying TEST's smaller deductible set removes valid PROD definitions: reject.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f58a370743dc5c0ac5f60ae710fb9b6f69a550ea53b515ec29d4c7b8b5de96cb",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-10-4",
        "parent_task_id": "task-fixture-cf-10-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c28bcf3f1f5f439c32275cb911c6994fff02a476784ad9e3dac692c4fcf077dc",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-10-5",
        "parent_task_id": "task-fixture-cf-10-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved existing-product delta with explicit per-cover scope and external dependencies.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved existing-product delta with explicit per-cover scope and external dependencies.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cfc6f06792f32273c60f1101e33c38b73e0ffaa5f2dbecb29319e5dd71dd2aa6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-10-6",
        "parent_task_id": "task-fixture-cf-10-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "da8a5f21da358e99dcd852a785ac3a21c614c11f78d22666ba7a9cec6a678e88",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-10-7",
        "parent_task_id": "task-fixture-cf-10-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-10",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the limit mapping and unchanged-cover regression set.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the limit mapping and unchanged-cover regression set.\nCase: fixture-cf-10; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "699971a28013a4ba47faf38ed5f618d8ca430317419a9a1d7cac801fcc624f10",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-10-executor",
        "parent_task_id": "task-fixture-cf-10-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-10\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-10-Spawn",
        "case_id": "fixture-cf-10",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-10-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Compare current cover/deductible/sublimit definitions on every affected product and the requested INSIS counterpart.\nPrepare the bounded work: Apply the approved existing-product delta with explicit per-cover scope and external dependencies.\nReturn evidence sufficient to test: Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.\nReject this false completion: Copying TEST's smaller deductible set removes valid PROD definitions: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-10-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-10-Plan",
        "case_id": "fixture-cf-10",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-10-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-10",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-10-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-10-PlanConfirmation",
        "case_id": "fixture-cf-10",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-10-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-10",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-10-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-10-Result",
        "case_id": "fixture-cf-10",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-10-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-10-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-10-Verdict",
        "case_id": "fixture-cf-10",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-10-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Copying TEST's smaller deductible set removes valid PROD definitions: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-10-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the approved existing-product delta with explicit per-cover scope and external dependencies.",
      "case_specific_proof": "Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00469"
            },
            "body": {
              "module": "configuration",
              "description": "Cover limit, deductible definition or sublimit on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00470"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00471"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Boundary quotes and requested target views enforce the intended limits while unaffected cover definitions remain."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00472"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00473"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the limit mapping and unchanged-cover regression set."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00474"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00475"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00476"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00477"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Cover limit, deductible definition or sublimit on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Export both targets, including PROD-only definitions, before changing one cover."
      }
    ]
  },
  "CF-11": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-11-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f19cbc9492a5f1497a70860c82485a1143ea04b194a7b80db05381cc48285631",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-11-1",
        "parent_task_id": "task-fixture-cf-11-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the message key, language, current texts, consumers and target cache behaviour.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Resolve the message key, language, current texts, consumers and target cache behaviour.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "67347aadc1c9ba64fed09fca65b697d8726c4ce3828ead5ff9bad711036256a6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-11-2",
        "parent_task_id": "task-fixture-cf-11-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f418a29600aac3cbfb522328994d07b3d3ba95cbc995bbb53a756057b428b947",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-11-3",
        "parent_task_id": "task-fixture-cf-11-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Establish: Resolve the message key, language, current texts, consumers and target cache behaviour.\nPrepare the bounded work: Apply the exact shared-label delta and authorised cache refresh, preserving unrelated language and product keys.\nReturn evidence sufficient to test: The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nReject this false completion: The row changes but the customer still sees cached text: no visible-result proof.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Resolve the message key, language, current texts, consumers and target cache behaviour.\nPrepare the bounded work: Apply the exact shared-label delta and authorised cache refresh, preserving unrelated language and product keys.\nReturn evidence sufficient to test: The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nReject this false completion: The row changes but the customer still sees cached text: no visible-result proof.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "aee7e0b1df9b40ae2defab3a45829ad742782b70b2414c5052e01759121dc106",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-11-4",
        "parent_task_id": "task-fixture-cf-11-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7b69a3fbea77b78822fe0242a6cb8cdafe98c9801d4854cf9d588ea323701c73",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-11-5",
        "parent_task_id": "task-fixture-cf-11-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the exact shared-label delta and authorised cache refresh, preserving unrelated language and product keys.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the exact shared-label delta and authorised cache refresh, preserving unrelated language and product keys.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c8f45d9190e1e043ab10719ecdb13dfa4db837b6fcffb3c23cdf682679daea4f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-11-6",
        "parent_task_id": "task-fixture-cf-11-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "35edf3e36f084515ebbc2f722d80171552285936e0bb720573620e2b87b79c6e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-11-7",
        "parent_task_id": "task-fixture-cf-11-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-11",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain consumer/key mapping and a stale-cache example.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain consumer/key mapping and a stale-cache example.\nCase: fixture-cf-11; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Resolve the message key, language, current texts, consumers and target cache behaviour.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d656f2ab0b5dcf48a2a9b3b9e4f25f45b0bbc64bf6566e504fc38a82b5f24c3b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-11-executor",
        "parent_task_id": "task-fixture-cf-11-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-11\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-11-Spawn",
        "case_id": "fixture-cf-11",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-11-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "task_text": "Establish: Resolve the message key, language, current texts, consumers and target cache behaviour.\nPrepare the bounded work: Apply the exact shared-label delta and authorised cache refresh, preserving unrelated language and product keys.\nReturn evidence sufficient to test: The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.\nReject this false completion: The row changes but the customer still sees cached text: no visible-result proof.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/serdica",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-11-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-11-Plan",
        "case_id": "fixture-cf-11",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-11-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-11",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-11-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-11-PlanConfirmation",
        "case_id": "fixture-cf-11",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-11-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-11",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-11-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-11-Result",
        "case_id": "fixture-cf-11",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-11-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-11-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-11-Verdict",
        "case_id": "fixture-cf-11",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-11-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The row changes but the customer still sees cached text: no visible-result proof.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-11-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the exact shared-label delta and authorised cache refresh, preserving unrelated language and product keys.",
      "case_specific_proof": "The affected screen/document shows the intended text after refresh; unrelated consumers remain valid.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00478"
            },
            "body": {
              "module": "configuration",
              "description": "Label, translation or message fix",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00479"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00480"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The affected screen/document shows the intended text after refresh; unrelated consumers remain valid."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00481"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00482"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain consumer/key mapping and a stale-cache example."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00483"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00484"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00485"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00486"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Label, translation or message fix",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check the current target key and cache before proposing another translation write."
      }
    ]
  },
  "CF-12": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-12-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6085eb671acd3792034383d04200ed3b4ef49d69c1f9e813fe5937bb88d49c7f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-12-1",
        "parent_task_id": "task-fixture-cf-12-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8a5ee4fb2be12c9d5f6fcf99cf249aa1bb39fd09f32ef62e17f901b75b38407c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-12-2",
        "parent_task_id": "task-fixture-cf-12-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "db3f69171d3efb14d86778ec130d9016d3bbe89cefec254430a6f786e65a3a5c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-12-3",
        "parent_task_id": "task-fixture-cf-12-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Establish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c7985a9fec207c82eee91b8571540e94781ed8ad96fc4cdf874c32b6888e6c3f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-12-4",
        "parent_task_id": "task-fixture-cf-12-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Establish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3d370d7bc2fda51f74a8a29f24f5f3bbf26c47926126d9885745b83271fa118b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-12-5",
        "parent_task_id": "task-fixture-cf-12-2",
        "profile_key": "configuration.offer.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/offer",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Establish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.offer.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/offer/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8ae8c1718c44b8782050191a6101787947002abaf5635d3e96f4e7f4352ba4bd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-offer-stage"
      },
      {
        "task_id": "task-fixture-cf-12-6",
        "parent_task_id": "task-fixture-cf-12-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Establish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "591f61a971d841ba67c3a10d60f7f3ac8620ae627feed93109f5cf4a37993b0b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-12-7",
        "parent_task_id": "task-fixture-cf-12-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "650e090da72d5c6adb50f1f4e2586c030cf018485bfedbe106c12c04ddefa9a5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-12-8",
        "parent_task_id": "task-fixture-cf-12-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Run only affected stages and tracked external/Development work; join their signed results before target release.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Run only affected stages and tracked external/Development work; join their signed results before target release.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "46ff39abfc17f8442cec50dc360fbb69c26bb5830522ad4bedc5f5d4e969f704",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-12-9",
        "parent_task_id": "task-fixture-cf-12-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8e22e2bedd1bf58da32acd7adebbb79851d474f811237181f5054c60e0df878d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-12-10",
        "parent_task_id": "task-fixture-cf-12-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-12",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the cross-stage clause checklist and changed-version dependency graph.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the cross-stage clause checklist and changed-version dependency graph.\nCase: fixture-cf-12; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3f97d87149612a865fddc12606a3c0d8191fc441b7911996a9ed5f21bf059187",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-12-executor",
        "parent_task_id": "task-fixture-cf-12-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-12\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-12-Spawn",
        "case_id": "fixture-cf-12",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-12-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "task_text": "Establish: Map the new clause through catalogue, tariff, offer, limits, print and INSIS seam; establish which dependencies already exist.\nPrepare the bounded work: Run only affected stages and tracked external/Development work; join their signed results before target release.\nReturn evidence sufficient to test: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.\nReject this false completion: The cover prices correctly but has no INSIS mapping or print support: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/abacus",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-12-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-12-Plan",
        "case_id": "fixture-cf-12",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-12-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-12",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-12-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-12-PlanConfirmation",
        "case_id": "fixture-cf-12",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-12-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-12",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-12-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-12-Result",
        "case_id": "fixture-cf-12",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-12-3",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-12-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-12-Verdict",
        "case_id": "fixture-cf-12",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-12-7",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The cover prices correctly but has no INSIS mapping or print support: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-12-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Run only affected stages and tracked external/Development work; join their signed results before target release.",
      "case_specific_proof": "The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00487"
            },
            "body": {
              "module": "configuration",
              "description": "New clause or cover on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00488"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00489"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The clause can be selected, priced, transferred and printed on the declared target with the correct limits and LD."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00490"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00491"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the cross-stage clause checklist and changed-version dependency graph."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00492"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00493"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00494"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00495"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: New clause or cover on an existing product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Export the current clause and related versions first; apply only the requested new delta."
      }
    ]
  },
  "CF-13": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-13-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6cd8ad44e19aff21384af8ddd1c887ce3d0209ffb4c3c81f248abd95ed507884",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-13-1",
        "parent_task_id": "task-fixture-cf-13-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5d87c03da53d3184bfe76f1e4a70459f999497476bb67992928c1fae8094d042",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-13-2",
        "parent_task_id": "task-fixture-cf-13-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "34b65d30db2d2abea0030e00ca75f8939765c3f20f6ef6e2da8e352dd157349e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-13-3",
        "parent_task_id": "task-fixture-cf-13-2",
        "profile_key": "configuration.offer.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/offer",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\nPrepare the bounded work: Apply the approved package/offer delta while preserving unrelated packages and resolving any required tariff input from fresh evidence.\nReturn evidence sufficient to test: Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nReject this false completion: The happy-path package works but a forbidden cover combination remains selectable: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.offer.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\nPrepare the bounded work: Apply the approved package/offer delta while preserving unrelated packages and resolving any required tariff input from fresh evidence.\nReturn evidence sufficient to test: Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nReject this false completion: The happy-path package works but a forbidden cover combination remains selectable: reject.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/offer/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0413ad98409d518a8a8d85e596c4e116b3101a3a20e21b7d1e7eb15426dd31ee",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-offer-stage"
      },
      {
        "task_id": "task-fixture-cf-13-4",
        "parent_task_id": "task-fixture-cf-13-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ff6033ba0b4d2cdad31a878e076fdc6778450b4463b8e254536ada8276442825",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-13-5",
        "parent_task_id": "task-fixture-cf-13-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved package/offer delta while preserving unrelated packages and resolving any required tariff input from fresh evidence.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved package/offer delta while preserving unrelated packages and resolving any required tariff input from fresh evidence.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9fada55666749b96a10e49b2bf580169e2521bedb1d550116e97a40bcdc3a938",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-13-6",
        "parent_task_id": "task-fixture-cf-13-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "932005909949e57f84a4e766a1e19fd708df2671c98d8a9ad8e5a0a12515ad52",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-13-7",
        "parent_task_id": "task-fixture-cf-13-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-13",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain offer-resolution examples and the associated tariff compatibility.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain offer-resolution examples and the associated tariff compatibility.\nCase: fixture-cf-13; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7a79298ddeba860f6dde4b6d7bc561689b00c2179d19266e819a7a357a98fbf2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-13-executor",
        "parent_task_id": "task-fixture-cf-13-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-13\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-13-Spawn",
        "case_id": "fixture-cf-13",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-13-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.offer.stage",
          "profile_version": 1,
          "task_text": "Establish: Read the existing offer, covers, selection constraints and dependency rules; identify the required pricing baseline.\nPrepare the bounded work: Apply the approved package/offer delta while preserving unrelated packages and resolving any required tariff input from fresh evidence.\nReturn evidence sufficient to test: Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.\nReject this false completion: The happy-path package works but a forbidden cover combination remains selectable: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/offer",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-13-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-13-Plan",
        "case_id": "fixture-cf-13",
        "task_path": "root/configuration-root/configuration-offer-stage",
        "sender": {
          "task_id": "task-fixture-cf-13-3",
          "profile_key": "configuration.offer.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-13",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-13-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-13-PlanConfirmation",
        "case_id": "fixture-cf-13",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-13-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-13",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-13-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-13-Result",
        "case_id": "fixture-cf-13",
        "task_path": "root/configuration-root/configuration-offer-stage",
        "sender": {
          "task_id": "task-fixture-cf-13-3",
          "profile_key": "configuration.offer.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-13-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-13-Verdict",
        "case_id": "fixture-cf-13",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-13-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The happy-path package works but a forbidden cover combination remains selectable: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-13-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the approved package/offer delta while preserving unrelated packages and resolving any required tariff input from fresh evidence.",
      "case_specific_proof": "Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00496"
            },
            "body": {
              "module": "configuration",
              "description": "Package or offer change",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00497"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00498"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Selection, mandatory/optional covers, conflicts and limits work for allowed and forbidden combinations."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00499"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00500"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain offer-resolution examples and the associated tariff compatibility."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00501"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00502"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00503"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00504"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Package or offer change",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Re-evaluate the current offer and pricing versions before reusing its previous rule."
      }
    ]
  },
  "CF-14": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-14-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7aeac752759673aa20a4d033539dba637373b32a1318c1f2b6b0900323e5d6c6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-14-1",
        "parent_task_id": "task-fixture-cf-14-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "385a18604e51fce69de1eed94af3bdc78abc3b171ef4082d88e95f9540e105be",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-14-2",
        "parent_task_id": "task-fixture-cf-14-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b40eb491654e98305af59e9c72daaccc36e8d08ec30aa17471c006b7492316a7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-14-3",
        "parent_task_id": "task-fixture-cf-14-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Establish: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\nPrepare the bounded work: Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.\nReturn evidence sufficient to test: The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nReject this false completion: INSIS shows the question but IPAL or rating still ignores it: remain partially delivered.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\nPrepare the bounded work: Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.\nReturn evidence sufficient to test: The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nReject this false completion: INSIS shows the question but IPAL or rating still ignores it: remain partially delivered.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "fbd218cd61c80cdcd3ffbc53dc106e8ad513e7c3d7e40cae3d724f967b20a3f2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-14-4",
        "parent_task_id": "task-fixture-cf-14-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Establish: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\nPrepare the bounded work: Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.\nReturn evidence sufficient to test: The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nReject this false completion: INSIS shows the question but IPAL or rating still ignores it: remain partially delivered.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\nPrepare the bounded work: Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.\nReturn evidence sufficient to test: The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nReject this false completion: INSIS shows the question but IPAL or rating still ignores it: remain partially delivered.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a9dab2459d24d67412ae16713988970de4baa3ec947e03f4058400a7eef87fd4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-14-5",
        "parent_task_id": "task-fixture-cf-14-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "de24fd19e1bf889a2ea6374a82a3c7fbf6e9acb034e20b153540299062bce3d1",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-cf-14-6",
        "parent_task_id": "task-fixture-cf-14-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cd28126fddfda79385c682561d574a881cf6da360c20ec355e7ef9b7e0a2bdf0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-14-7",
        "parent_task_id": "task-fixture-cf-14-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2dcc93abf02415a8807908c4d736392501ea1d57749c4ce3a68e8ab4cb4fe17c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-14-8",
        "parent_task_id": "task-fixture-cf-14-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-14",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain field-to-system mappings and the partial-delivery counterexample.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain field-to-system mappings and the partial-delivery counterexample.\nCase: fixture-cf-14; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bc48b56a0e14f7c7c36c6a1f1bb6c641e58c755b6bf85177d97772b532185cec",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-14-executor",
        "parent_task_id": "task-fixture-cf-14-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-14\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-14-Spawn",
        "case_id": "fixture-cf-14",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-14-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Map the question/answer or field to its INSIS-native definition, IPAL factor and ABACUS consumption, with effective dates.\nPrepare the bounded work: Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.\nReturn evidence sufficient to test: The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.\nReject this false completion: INSIS shows the question but IPAL or rating still ignores it: remain partially delivered.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-14-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-14-Plan",
        "case_id": "fixture-cf-14",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-14-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-14",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-14-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-14-PlanConfirmation",
        "case_id": "fixture-cf-14",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-14-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-14",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-14-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-14-Result",
        "case_id": "fixture-cf-14",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-14-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-14-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-14-Verdict",
        "case_id": "fixture-cf-14",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-cf-14-5",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "INSIS shows the question but IPAL or rating still ignores it: remain partially delivered.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-14-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Track INSIS-owner work and the affected IPAL/rating delta as separate obligations in the same requested delivery.",
      "case_specific_proof": "The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00505"
            },
            "body": {
              "module": "configuration",
              "description": "Questionnaire question, answer or object field",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00506"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00507"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The field/question is usable on every promised surface, mandatory conditions fire and rating receives the intended answer."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00508"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00509"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain field-to-system mappings and the partial-delivery counterexample."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00510"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00511"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00512"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00513"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Questionnaire question, answer or object field",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Inspect which twins already exist and their effective dates rather than restarting the whole request."
      }
    ]
  },
  "CF-15": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-15-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "30f95ea8455d97c304225d01fa6762a1fe3337648da9a98dd581985f38de0cd3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-15-1",
        "parent_task_id": "task-fixture-cf-15-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "787f5eb9a983884ca6941b5d13066090dbabb5053c63f6abd490a1bbec3777a2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-15-2",
        "parent_task_id": "task-fixture-cf-15-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e3755b164f174cdb2f1c4332de17eafac0153ee0f5c73145394f2b48d029773f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-15-3",
        "parent_task_id": "task-fixture-cf-15-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Establish: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\nPrepare the bounded work: Apply the approved mapping delta; a missing code capability recruits Development rather than adding an inert mapping.\nReturn evidence sufficient to test: Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nReject this false completion: The mapping row is present but the consumer never reads that column: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\nPrepare the bounded work: Apply the approved mapping delta; a missing code capability recruits Development rather than adding an inert mapping.\nReturn evidence sufficient to test: Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nReject this false completion: The mapping row is present but the consumer never reads that column: reject.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "20e93ccab24816ef30ba078326dcab57818a9499653ed62d32fae5e1a0b88c73",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-15-4",
        "parent_task_id": "task-fixture-cf-15-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8f81b1d7db5ed2812dc0f2635ea92406499099caa6ffbacb6d7e9fe1d7c05f44",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-15-5",
        "parent_task_id": "task-fixture-cf-15-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved mapping delta; a missing code capability recruits Development rather than adding an inert mapping.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved mapping delta; a missing code capability recruits Development rather than adding an inert mapping.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bb6041086629f3623487b6092089a94743fbe16ce894f9c9a7b6e28aba8780b2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-15-6",
        "parent_task_id": "task-fixture-cf-15-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "23944b413b1c28a2492bc535ddfdc82478601896d27dcee7139a77ec00668f63",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-15-7",
        "parent_task_id": "task-fixture-cf-15-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-15",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the seam mapping assertions and any code precondition.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the seam mapping assertions and any code precondition.\nCase: fixture-cf-15; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "597a481e1613d3e91ffeb4cc6df217f9320bb3a9866134e32cbbe5dd20084f69",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-15-executor",
        "parent_task_id": "task-fixture-cf-15-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-15\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-15-Spawn",
        "case_id": "fixture-cf-15",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-15-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Export the actual covers/objects/LD/field seam and compare both system code sets and consuming transfer code.\nPrepare the bounded work: Apply the approved mapping delta; a missing code capability recruits Development rather than adding an inert mapping.\nReturn evidence sufficient to test: Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.\nReject this false completion: The mapping row is present but the consumer never reads that column: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-15-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-15-Plan",
        "case_id": "fixture-cf-15",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-15-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-15",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-15-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-15-PlanConfirmation",
        "case_id": "fixture-cf-15",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-15-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-15",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-15-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-15-Result",
        "case_id": "fixture-cf-15",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-15-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-15-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-15-Verdict",
        "case_id": "fixture-cf-15",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-15-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The mapping row is present but the consumer never reads that column: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-15-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the approved mapping delta; a missing code capability recruits Development rather than adding an inert mapping.",
      "case_specific_proof": "Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00514"
            },
            "body": {
              "module": "configuration",
              "description": "IPAL ↔ INSIS seam change for a changed or new product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00515"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00516"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Representative transfer values map correctly, including negative/unmapped inputs and unaffected siblings."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00517"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00518"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the seam mapping assertions and any code precondition."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00519"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00520"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00521"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00522"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: IPAL ↔ INSIS seam change for a changed or new product",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check current code and configuration together before treating a missing result as a missing row."
      }
    ]
  },
  "CF-16": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-16-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a365820364201c728162dd7f718d3d28f8365081aeb7327c6b3c35198bbbdfa6",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-16-1",
        "parent_task_id": "task-fixture-cf-16-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "35e9f866eed4aff9f314cc1726bf0f56e8daf0d5b42b9e3c73a8f4b65daaee0e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-16-2",
        "parent_task_id": "task-fixture-cf-16-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4b5a04dd95933cc1a43a9e9d46fec969ebfb845770719b73166f661f1c95e375",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-16-3",
        "parent_task_id": "task-fixture-cf-16-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "f129a0f3742b10f8cbcd76346563cbfaeadf09976a20947ceff76fe129e09d0c",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-cf-16-4",
        "parent_task_id": "task-fixture-cf-16-2",
        "profile_key": "configuration.normalizer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/normalization",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.normalizer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/normalization/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "de2a2a2976994cf2b611d24bc17d368a45ea2d0723c970c0e9c07c690185ea70",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-normalizer"
      },
      {
        "task_id": "task-fixture-cf-16-5",
        "parent_task_id": "task-fixture-cf-16-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6a78f172cc30dc1ee7721932f2e2f58e08d854a418a74a8d2cf24b082fde5720",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-16-6",
        "parent_task_id": "task-fixture-cf-16-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "faea9eb5e72309c2205eacc91e6df99ce32c2bee3e6a85d519f328bc7b699eb7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-16-7",
        "parent_task_id": "task-fixture-cf-16-3",
        "profile_key": "source.camunda_developer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Establish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.camunda_developer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "9620f3175222a5eee000f02fb86c28a414a1f3f9a1ffc4bf5ec311793f4fbc84",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-camunda_developer"
      },
      {
        "task_id": "task-fixture-cf-16-8",
        "parent_task_id": "task-fixture-cf-16-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "11a68b2e3cd6de38f8f0904087fd57becb08836ff147b62cfafc5572f810d811",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-16-9",
        "parent_task_id": "task-fixture-cf-16-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6fa2a218b4d8a4f3804d9df299809fb328693c8d1190e0e6932cb535f1bf8c0d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-16-10",
        "parent_task_id": "task-fixture-cf-16-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5c7bc0228892f2416a106e27569c1347e5b6919d77e02ad92e1a450f84b8d12d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-16-11",
        "parent_task_id": "task-fixture-cf-16-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-16",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain donor suitability checks and the clone-plus-code dependency pattern.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain donor suitability checks and the clone-plus-code dependency pattern.\nCase: fixture-cf-16; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2fee6edc6b3228afdf216f5cd847f09fb2185a4f08a6a578de317421db14d22f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-16-tests",
        "parent_task_id": "task-fixture-cf-16-3",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-cf-16-executor",
        "parent_task_id": "task-fixture-cf-16-4",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-16\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-16-Spawn",
        "case_id": "fixture-cf-16",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-16-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "task_text": "Establish: Inventory the donor and requested differences across the applicable parts; verify actual process reuse instead of assuming a complete clone.\nPrepare the bounded work: Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.\nReturn evidence sufficient to test: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.\nReject this false completion: Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/normalization",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-16-4"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-16-Plan",
        "case_id": "fixture-cf-16",
        "task_path": "root/configuration-root/configuration-normalizer",
        "sender": {
          "task_id": "task-fixture-cf-16-4",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-16",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-16-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-16-PlanConfirmation",
        "case_id": "fixture-cf-16",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-16-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-16",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-16-4"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-16-Result",
        "case_id": "fixture-cf-16",
        "task_path": "root/configuration-root/configuration-normalizer",
        "sender": {
          "task_id": "task-fixture-cf-16-4",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-16-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-16-Verdict",
        "case_id": "fixture-cf-16",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-16-8",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Rows are cloned but the product starts the donor's wrong process or uses donor numbering: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-16-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Clone only approved structures, build affected stage deltas and recruit Development for required process/user-task changes.",
      "case_specific_proof": "The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00523"
            },
            "body": {
              "module": "configuration",
              "description": "Copy-of-product or variant",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00524"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00525"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The variant's own codes, rating, route, process, transfer and documents work on its target; donor behaviour stays intact."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00526"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00527"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain donor suitability checks and the clone-plus-code dependency pattern."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00528"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00529"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00530"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00531"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Copy-of-product or variant",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Read the donor's current state and reject incompatible inherited fields or processes."
      }
    ]
  },
  "CF-17": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-17-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ec199020044d68c5593e54ff7b34382e12b65de3b5a2aefa6d64fbe05e99fb0e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-17-1",
        "parent_task_id": "task-fixture-cf-17-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1b1150dff00caf72ab550a6db12f18d6c9cef194683801c0bafdd23bd0d38ba9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-17-2",
        "parent_task_id": "task-fixture-cf-17-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "14995156267d184ee310a6f5607870f62c4c76159cd1c7863940fa42b6be4b62",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-17-3",
        "parent_task_id": "task-fixture-cf-17-2",
        "profile_key": "configuration.normalizer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/normalization",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.normalizer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/normalization/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "38a41a1c4b49b2312571ded7a89729f6b601bf48926ec6c69597db3831a7e85e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-normalizer"
      },
      {
        "task_id": "task-fixture-cf-17-4",
        "parent_task_id": "task-fixture-cf-17-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6046ee0d13505379b51b19b9be0bb8d59125fab96dfb1b9176e86e7028edddde",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-17-5",
        "parent_task_id": "task-fixture-cf-17-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Establish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "bdfc86e2d54b75459848ae02f4ff5d8fc73e86b3c50c2b3a6dcdc3098ad3f0ad",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-17-6",
        "parent_task_id": "task-fixture-cf-17-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1d2f87d92da7de47202a8a97d6090202c10ef586a457eeaf635782240ded61d3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-cf-17-7",
        "parent_task_id": "task-fixture-cf-17-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2c0032a5a64d8e98abbdc89c9ff2f496957f6031cac87ce60212d9297301bf75",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-17-8",
        "parent_task_id": "task-fixture-cf-17-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a4564ab3c57b1d64479b2971eaeea0f09341e66363e35d31f4f907740dd0c913",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-17-9",
        "parent_task_id": "task-fixture-cf-17-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-17",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the non-IPAL product variant and explicit owner/sign-out boundary.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the non-IPAL product variant and explicit owner/sign-out boundary.\nCase: fixture-cf-17; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2017647168d53204348679b4360f24144a0e69e2094af157ce2c1d201e7b6ce3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-17-executor",
        "parent_task_id": "task-fixture-cf-17-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-17\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-17-Spawn",
        "case_id": "fixture-cf-17",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-17-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "task_text": "Establish: Record an INSIS-native objective: INSIS product/rules, ABACUS rating and only the required IPAL seam; do not invent an IPAL sales catalogue.\nPrepare the bounded work: Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.\nReturn evidence sufficient to test: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.\nReject this false completion: An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/normalization",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-17-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-17-Plan",
        "case_id": "fixture-cf-17",
        "task_path": "root/configuration-root/configuration-normalizer",
        "sender": {
          "task_id": "task-fixture-cf-17-3",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-17",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-17-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-17-PlanConfirmation",
        "case_id": "fixture-cf-17",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-17-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-17",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-17-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-17-Result",
        "case_id": "fixture-cf-17",
        "task_path": "root/configuration-root/configuration-normalizer",
        "sender": {
          "task_id": "task-fixture-cf-17-3",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-17-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-17-Verdict",
        "case_id": "fixture-cf-17",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-cf-17-6",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "An ABACUS-only sign-out closes the request while the INSIS product remains unusable: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-17-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Coordinate the INSIS owner's product setup with selected rating/seam work; keep each target obligation visible until evidence returns.",
      "case_specific_proof": "The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00532"
            },
            "body": {
              "module": "configuration",
              "description": "INSIS-native new product with ABACUS rating and an IPAL seam only",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00533"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00534"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The INSIS-native sales flow receives correct rating and any promised seam behaviour; no false IPAL issuance claim."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00535"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00536"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the non-IPAL product variant and explicit owner/sign-out boundary."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00537"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00538"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00539"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00540"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: INSIS-native new product with ABACUS rating and an IPAL seam only",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recognise the target administration at intake and select only its real stages."
      }
    ]
  },
  "CF-18": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-18-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. All outputs consume the current approved requirement revision; superseded values no longer drive the target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ea2619d2cff35a8385b42d70318ed433e3b72074c2fd9bbde6d2841b2cf07c05",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-18-1",
        "parent_task_id": "task-fixture-cf-18-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "83bb39ebcd1824749490cd5a2a593a44e6c447c3e8d06ccf908392279d1ef124",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-18-2",
        "parent_task_id": "task-fixture-cf-18-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. All outputs consume the current approved requirement revision; superseded values no longer drive the target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e4e63664b68fca4f6214cf95894d51993571bc5f0f14cc627d226a53e63e517a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-18-3",
        "parent_task_id": "task-fixture-cf-18-2",
        "profile_key": "configuration.normalizer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/normalization",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Establish: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\nPrepare the bounded work: Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.\nReturn evidence sufficient to test: All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nReject this false completion: An old H3 or preview approval is reused after the tariff/limit requirement changed: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.normalizer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\nPrepare the bounded work: Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.\nReturn evidence sufficient to test: All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nReject this false completion: An old H3 or preview approval is reused after the tariff/limit requirement changed: reject.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/normalization/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a055a4f46d0a6227771a116d83b21f64d3b5d17e5eaaa7e661d8dc417b5c5ecd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-normalizer"
      },
      {
        "task_id": "task-fixture-cf-18-4",
        "parent_task_id": "task-fixture-cf-18-2",
        "profile_key": "configuration.estate_prober",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Establish: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\nPrepare the bounded work: Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.\nReturn evidence sufficient to test: All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nReject this false completion: An old H3 or preview approval is reused after the tariff/limit requirement changed: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.estate_prober. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\nPrepare the bounded work: Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.\nReturn evidence sufficient to test: All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nReject this false completion: An old H3 or preview approval is reused after the tariff/limit requirement changed: reject.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ae1bb736cf76c9f64643893ad9c909f384ae7a38c45e031f214c4fe2ed4f0c98",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-estate_prober"
      },
      {
        "task_id": "task-fixture-cf-18-5",
        "parent_task_id": "task-fixture-cf-18-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. All outputs consume the current approved requirement revision; superseded values no longer drive the target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "96da770d14bacf631e2a0926da8593d57a30452793c1e02ec8cfc16d3ef9cee3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-18-6",
        "parent_task_id": "task-fixture-cf-18-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d106d3a5abdb68022b03d9af4ad61b4ca0384e4dde1b2aae646491ce3c9e34de",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-18-7",
        "parent_task_id": "task-fixture-cf-18-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. All outputs consume the current approved requirement revision; superseded values no longer drive the target.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "df8fdf531cd4f650d9f53034a36454216aef8aed3d49223d801040f7e9b76ede",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-18-8",
        "parent_task_id": "task-fixture-cf-18-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-18",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the ambiguity resolution and dependency invalidation example.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain the ambiguity resolution and dependency invalidation example.\nCase: fixture-cf-18; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b2d81b55a20d0bdbd7e7d3bd015768484fb55c42df5c0817d4b5e53fdcb3c73d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-18-executor",
        "parent_task_id": "task-fixture-cf-18-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-18\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-18-Spawn",
        "case_id": "fixture-cf-18",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-18-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "task_text": "Establish: Correlate related source requests and versions, preserve contradictions, and identify which approved requirement changed.\nPrepare the bounded work: Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.\nReturn evidence sufficient to test: All outputs consume the current approved requirement revision; superseded values no longer drive the target.\nReject this false completion: An old H3 or preview approval is reused after the tariff/limit requirement changed: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/normalization",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-18-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-18-Plan",
        "case_id": "fixture-cf-18",
        "task_path": "root/configuration-root/configuration-normalizer",
        "sender": {
          "task_id": "task-fixture-cf-18-3",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-18",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-18-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-18-PlanConfirmation",
        "case_id": "fixture-cf-18",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-18-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-18",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-18-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-18-Result",
        "case_id": "fixture-cf-18",
        "task_path": "root/configuration-root/configuration-normalizer",
        "sender": {
          "task_id": "task-fixture-cf-18-3",
          "profile_key": "configuration.normalizer",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-18-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-18-Verdict",
        "case_id": "fixture-cf-18",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-18-5",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "An old H3 or preview approval is reused after the tariff/limit requirement changed: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-18-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Publish the amended S1 delta with H1a, invalidate dependent evidence and rerun affected stages/tests; retain valid prior work.",
      "case_specific_proof": "All outputs consume the current approved requirement revision; superseded values no longer drive the target.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00541"
            },
            "body": {
              "module": "configuration",
              "description": "Product re-upload or catalogue correction from a changed specification",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00542"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00543"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: All outputs consume the current approved requirement revision; superseded values no longer drive the target."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00544"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00545"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain the ambiguity resolution and dependency invalidation example."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00546"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00547"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00548"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00549"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Product re-upload or catalogue correction from a changed specification",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Retrieve the product's latest approved scope and change history before accepting another re-upload."
      }
    ]
  },
  "CF-19": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-19-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "23482dcff2bda6b9b9b309b343987e1326c26093be9d3188a101b4f1879179f9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-19-1",
        "parent_task_id": "task-fixture-cf-19-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "10ec13e7c0c78a73e3219564668c08612cbfce3117471140411ad84b8d6430c8",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-19-2",
        "parent_task_id": "task-fixture-cf-19-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0cf2b8e32f29acad8ee58783a843795f61b8c0ac7d734991372cc4095d10cdf9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-19-3",
        "parent_task_id": "task-fixture-cf-19-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5f19f5c7cdfc695e59c3a49c76f3b0722d65358ebf5807e1961753818a21afb5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-cf-19-4",
        "parent_task_id": "task-fixture-cf-19-2",
        "profile_key": "configuration.abacus.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/abacus",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Establish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.abacus.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/abacus/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d14d7fcf8a2452872e7bb09c4ad42c80a67958524c267cbdfe085343734bcc06",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-abacus-stage"
      },
      {
        "task_id": "task-fixture-cf-19-5",
        "parent_task_id": "task-fixture-cf-19-2",
        "profile_key": "configuration.offer.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/offer",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Establish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.offer.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/offer/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "85e65cc6e8b665a39defba5e846398a50d0fb34f94fadabd6fc8b1d31ad99b05",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-offer-stage"
      },
      {
        "task_id": "task-fixture-cf-19-6",
        "parent_task_id": "task-fixture-cf-19-3",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Establish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "7c9dc05df7648339314e0081828900934054c6506d9620543ca66271dbcfefd7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-cf-19-7",
        "parent_task_id": "task-fixture-cf-19-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ef98f74cba9276e53634030c423ee2a72a102efae4ad65c9f6c333822f2263db",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-19-8",
        "parent_task_id": "task-fixture-cf-19-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5d8e42d5804eca094319a73b911b1261e33944465e920dd17a1f0b8341888f11",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-19-9",
        "parent_task_id": "task-fixture-cf-19-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a1757451756d722f87cc8104dc872d7f7491e79d85059d808459e1e54becfdc4",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-19-10",
        "parent_task_id": "task-fixture-cf-19-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-19",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain time-bound examples and separate commercial expiry from destructive removal.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain time-bound examples and separate commercial expiry from destructive removal.\nCase: fixture-cf-19; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cf6ea014a5718f69748c092cf600bfaba42e3967bc7b0c21d8515de512ddd9b5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-19-tests",
        "parent_task_id": "task-fixture-cf-19-3",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-cf-19-executor",
        "parent_task_id": "task-fixture-cf-19-4",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-19\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-19-Spawn",
        "case_id": "fixture-cf-19",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-19-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "task_text": "Establish: Define campaign dates, eligibility, computed duration, offer behaviour and what happens to already issued policies.\nPrepare the bounded work: Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.\nReturn evidence sufficient to test: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.\nReject this false completion: A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/abacus",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-19-4"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-19-Plan",
        "case_id": "fixture-cf-19",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-19-4",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-19",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-19-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-19-PlanConfirmation",
        "case_id": "fixture-cf-19",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-19-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-19",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-19-4"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-19-Result",
        "case_id": "fixture-cf-19",
        "task_path": "root/configuration-root/configuration-abacus-stage",
        "sender": {
          "task_id": "task-fixture-cf-19-4",
          "profile_key": "configuration.abacus.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-19-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-19-Verdict",
        "case_id": "fixture-cf-19",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-19-7",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A closed browser/session cancels campaign retirement, or removal breaks issued policies: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-19-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Coordinate code, rating, offer and labels; create durable stop-offering and later removal obligations with H7 before delivery.",
      "case_specific_proof": "Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00550"
            },
            "body": {
              "module": "configuration",
              "description": "Promo or time-boxed campaign",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00551"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00552"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Boundary dates and eligibility pass; after expiry new sales stop as intended while issued policies retain their valid terms."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00553"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00554"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain time-bound examples and separate commercial expiry from destructive removal."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00555"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00556"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00557"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00558"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Promo or time-boxed campaign",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check current campaign and successor obligations before extending or recreating it."
      }
    ]
  },
  "CF-20": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-20-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "943924ada95a4fc3e391d0b109eb0bc437c3ffa2d26d17411af3687d27c1470b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-20-1",
        "parent_task_id": "task-fixture-cf-20-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read effective route/product roles in each target and the approved intended audience.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read effective route/product roles in each target and the approved intended audience.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c10177457d1ad750988698028a011e49b26ddb34cef5833f362d54e378dcc092",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-20-2",
        "parent_task_id": "task-fixture-cf-20-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "dbca482c04401d571e6d26d72e25279e3664ee8d0b82159931470aa060c769bb",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-20-3",
        "parent_task_id": "task-fixture-cf-20-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Establish: Read effective route/product roles in each target and the approved intended audience.\nPrepare the bounded work: Apply the exact visibility delta under the full shared-role/target authority and refresh the relevant projection/cache.\nReturn evidence sufficient to test: Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nReject this false completion: The menu hides a route but the backend still permits an excluded role: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read effective route/product roles in each target and the approved intended audience.\nPrepare the bounded work: Apply the exact visibility delta under the full shared-role/target authority and refresh the relevant projection/cache.\nReturn evidence sufficient to test: Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nReject this false completion: The menu hides a route but the backend still permits an excluded role: fail.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "63d0928871755f84b5be549ff42047dfa0c7c0e6eafa6c9a2b734b2009bbeeae",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-20-4",
        "parent_task_id": "task-fixture-cf-20-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2ddc9d835cd44748480f0484b40a7f990736bfe15fe8a009e158e1dd81ba6fc3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-20-5",
        "parent_task_id": "task-fixture-cf-20-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the exact visibility delta under the full shared-role/target authority and refresh the relevant projection/cache.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the exact visibility delta under the full shared-role/target authority and refresh the relevant projection/cache.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "df045a057dc57432742eee64735701e032c1365b844793ea57eab89be1e47d4f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-20-6",
        "parent_task_id": "task-fixture-cf-20-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "288f7e58c6917415f66fe471053c6fea2ce399b761b84898a2421a068ef8f8fa",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-20-7",
        "parent_task_id": "task-fixture-cf-20-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-20",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain positive/negative audience tests and the target-specific role mapping.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain positive/negative audience tests and the target-specific role mapping.\nCase: fixture-cf-20; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read effective route/product roles in each target and the approved intended audience.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5f747f09ba0bc2e262023f7e6b42c1672ec3e68e09211d9e39a1e930851f70f5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-20-executor",
        "parent_task_id": "task-fixture-cf-20-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-20\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-20-Spawn",
        "case_id": "fixture-cf-20",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-20-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "task_text": "Establish: Read effective route/product roles in each target and the approved intended audience.\nPrepare the bounded work: Apply the exact visibility delta under the full shared-role/target authority and refresh the relevant projection/cache.\nReturn evidence sufficient to test: Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.\nReject this false completion: The menu hides a route but the backend still permits an excluded role: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/serdica",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-20-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-20-Plan",
        "case_id": "fixture-cf-20",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-20-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-20",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-20-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-20-PlanConfirmation",
        "case_id": "fixture-cf-20",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-20-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-20",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-20-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-20-Result",
        "case_id": "fixture-cf-20",
        "task_path": "root/configuration-root/configuration-serdica-stage",
        "sender": {
          "task_id": "task-fixture-cf-20-3",
          "profile_key": "configuration.serdica.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-20-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-20-Verdict",
        "case_id": "fixture-cf-20",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-20-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "The menu hides a route but the backend still permits an excluded role: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-20-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the exact visibility delta under the full shared-role/target authority and refresh the relevant projection/cache.",
      "case_specific_proof": "Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00559"
            },
            "body": {
              "module": "configuration",
              "description": "Product visibility: routes and roles",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00560"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00561"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Intended customer/agent roles see the product and an excluded role cannot access it; backend checks agree."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00562"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00563"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain positive/negative audience tests and the target-specific role mapping."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00564"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00565"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00566"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00567"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Product visibility: routes and roles",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Recheck live effective rights; TEST visibility does not prove PROD entitlement."
      }
    ]
  },
  "CF-21": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-21-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ea74a812926f18e7604b50ecd1d592323580b040c7a0820e23c3f870e36ed653",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-21-1",
        "parent_task_id": "task-fixture-cf-21-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3a89127ad41eeddb150ef6fc7c5e0154e4bc2382e8decb1c92690975fe6efffa",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-21-2",
        "parent_task_id": "task-fixture-cf-21-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d9050f2be32d1a5a5e3c54bb82f5143c7ac996cf42040255431e785a9e4fb809",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-21-3",
        "parent_task_id": "task-fixture-cf-21-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\nPrepare the bounded work: Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.\nReturn evidence sufficient to test: New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nReject this false completion: Replacing the catalogue changes the meaning of existing tariff keys: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\nPrepare the bounded work: Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.\nReturn evidence sufficient to test: New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nReject this false completion: Replacing the catalogue changes the meaning of existing tariff keys: reject.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2ca8e2dbdfb47ac0db2d2bd86122b2490c061b5c9e313113a241f439618ea88a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-21-4",
        "parent_task_id": "task-fixture-cf-21-2",
        "profile_key": "configuration.serdica.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/serdica",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\nPrepare the bounded work: Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.\nReturn evidence sufficient to test: New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nReject this false completion: Replacing the catalogue changes the meaning of existing tariff keys: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.serdica.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\nPrepare the bounded work: Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.\nReturn evidence sufficient to test: New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nReject this false completion: Replacing the catalogue changes the meaning of existing tariff keys: reject.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/serdica/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "5bde85a8bf3a3b8b1430b2dd0ea6f1b96e2ae1f6f0d935622a34bedc6bc2b266",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-serdica-stage"
      },
      {
        "task_id": "task-fixture-cf-21-5",
        "parent_task_id": "task-fixture-cf-21-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "cb323712caa4c849deb51effed2a4a81c8fdc6e0169ac9f1aa386bc00e11982e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-21-6",
        "parent_task_id": "task-fixture-cf-21-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "12e49e5826255b3b339153579e23af3be0ddb8013d3ae61f306cc0554603c6f0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-21-7",
        "parent_task_id": "task-fixture-cf-21-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6fd4e931e80e70472949df54899237945d91d8151ea090eba0578d24d073f5bd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-21-8",
        "parent_task_id": "task-fixture-cf-21-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-21",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain compatibility mappings and forbidden wholesale-replacement examples.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain compatibility mappings and forbidden wholesale-replacement examples.\nCase: fixture-cf-21; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "574a0066c941212d302c03fc67c684b91cf5e4526aec51d00a6203ce0c172fea",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-21-executor",
        "parent_task_id": "task-fixture-cf-21-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-21\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-21-Spawn",
        "case_id": "fixture-cf-21",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-21-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Compare old/new nomenclature business keys, pricing dependencies, labels and historical consumers across systems.\nPrepare the bounded work: Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.\nReturn evidence sufficient to test: New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.\nReject this false completion: Replacing the catalogue changes the meaning of existing tariff keys: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-21-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-21-Plan",
        "case_id": "fixture-cf-21",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-21-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-21",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-21-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-21-PlanConfirmation",
        "case_id": "fixture-cf-21",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-21-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-21",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-21-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-21-Result",
        "case_id": "fixture-cf-21",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-21-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-21-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-21-Verdict",
        "case_id": "fixture-cf-21",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-21-5",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "Replacing the catalogue changes the meaning of existing tariff keys: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-21-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply only a reviewed compatible reload/mapping plan; unresolved tariff semantics become a business question, not a blind replacement.",
      "case_specific_proof": "New selections price and transfer correctly, old policies remain interpretable and shared labels resolve.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00568"
            },
            "body": {
              "module": "configuration",
              "description": "Master-nomenclature reload",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00569"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00570"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: New selections price and transfer correctly, old policies remain interpretable and shared labels resolve."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00571"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00572"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain compatibility mappings and forbidden wholesale-replacement examples."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00573"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00574"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00575"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00576"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Master-nomenclature reload",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Re-evaluate current pricing references and previously rejected scope before reusing a reload script."
      }
    ]
  },
  "CF-22": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-22-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ecd0bde57ce5fe09a83ea85d017d353cef774fee97393b6932de108df4c08030",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-22-1",
        "parent_task_id": "task-fixture-cf-22-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "60d347a22dbfece7cb893335c863f8534e4c43570ea74dca213b14604c21c2de",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-22-2",
        "parent_task_id": "task-fixture-cf-22-0",
        "profile_key": "support.investigator.master_data",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/investigators/master_data",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Establish: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\nPrepare the bounded work: Insert only the approved missing blank ranges under the declared scope; preserve used numbers and external registry ownership.\nReturn evidence sufficient to test: Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.\nReject this false completion: A repeated request would reinsert used or already allocated blanks: reject.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.investigator.master_data. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\nPrepare the bounded work: Insert only the approved missing blank ranges under the declared scope; preserve used numbers and external registry ownership.\nReturn evidence sufficient to test: Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.\nReject this false completion: A repeated request would reinsert used or already allocated blanks: reject.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/investigators/master_data/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "c2301de38b5af37682203e78c45b093db2c48b709547e19282a6cb4ad96e5671",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-investigator-master_data"
      },
      {
        "task_id": "task-fixture-cf-22-3",
        "parent_task_id": "task-fixture-cf-22-0",
        "profile_key": "support.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "e04951060bf304caef62f960c83d6a4a1c3751d7f1f701f1e75588827d4d1001",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-verifier"
      },
      {
        "task_id": "task-fixture-cf-22-4",
        "parent_task_id": "task-fixture-cf-22-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Insert only the approved missing blank ranges under the declared scope; preserve used numbers and external registry ownership.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Insert only the approved missing blank ranges under the declared scope; preserve used numbers and external registry ownership.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3f9e075f022b7af339438d4dbcdbeb5d06a7cac41d78c68c50f9d02e3b362c7e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-22-5",
        "parent_task_id": "task-fixture-cf-22-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d291d6ffdcac747cec997054000201c5ade74d831d13b6910a10483126fd50ba",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-22-6",
        "parent_task_id": "task-fixture-cf-22-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-22",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record batch provenance and skill use without treating every blank as an independent training case.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Record batch provenance and skill use without treating every blank as an independent training case.\nCase: fixture-cf-22; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "17ed3f0c66f183d416bf85270eadeae7d429de502966b0f80d9035b328bef1a7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-22-executor",
        "parent_task_id": "task-fixture-cf-22-2",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-22\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-22-Spawn",
        "case_id": "fixture-cf-22",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-cf-22-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "task_text": "Establish: Route BSO batch work to the existing Support skill; inspect exact ranges, ownership, duplicates and used/free lifecycle.\nPrepare the bounded work: Insert only the approved missing blank ranges under the declared scope; preserve used numbers and external registry ownership.\nReturn evidence sufficient to test: Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.\nReject this false completion: A repeated request would reinsert used or already allocated blanks: reject.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "support/investigators/master_data",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-22-2"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-22-Plan",
        "case_id": "fixture-cf-22",
        "task_path": "root/support-investigator-master_data",
        "sender": {
          "task_id": "task-fixture-cf-22-2",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-22",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-22-0"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-22-PlanConfirmation",
        "case_id": "fixture-cf-22",
        "task_path": "root",
        "sender": {
          "task_id": "task-fixture-cf-22-0",
          "profile_key": "support.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-22",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-22-2"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-22-Result",
        "case_id": "fixture-cf-22",
        "task_path": "root/support-investigator-master_data",
        "sender": {
          "task_id": "task-fixture-cf-22-2",
          "profile_key": "support.investigator.master_data",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-22-0"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-22-Verdict",
        "case_id": "fixture-cf-22",
        "task_path": "root/support-verifier",
        "sender": {
          "task_id": "task-fixture-cf-22-3",
          "profile_key": "support.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A repeated request would reinsert used or already allocated blanks: reject.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-22-0"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Insert only the approved missing blank ranges under the declared scope; preserve used numbers and external registry ownership.",
      "case_specific_proof": "Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00577"
            },
            "body": {
              "module": "support",
              "description": "BSO blank batch",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00578"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00579"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Range counts and uniqueness reconcile; an authorised consuming action accepts the intended free blank."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00580"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00581"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Record batch provenance and skill use without treating every blank as an independent training case."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00582"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00583"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00584"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00585"
            },
            "body": {
              "module": "support",
              "description": "A new independent request of the same kind: BSO blank batch",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check overlap and lifecycle again; last month's range is not this month's authority."
      }
    ]
  },
  "CF-23": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-23-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "46a6c04c0c155bde87291fb529c7627d8e06e9b3dcae9df66ab5a09c5065fe52",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-23-1",
        "parent_task_id": "task-fixture-cf-23-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1d6a6de353f293734c8bc0da0c3538bf849880aa991565f97603e300c96d45d5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-23-2",
        "parent_task_id": "task-fixture-cf-23-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ab3130e4f81dbc7e704864aee857320c986f60d12e13962aa94101678815481e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-23-3",
        "parent_task_id": "task-fixture-cf-23-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Establish: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\nPrepare the bounded work: Apply the approved rule delta and declared external counterpart; keep policy-specific repairs separate.\nReturn evidence sufficient to test: Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nReject this false completion: A new global expression changes historical or unrelated policies unexpectedly: fail.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\nPrepare the bounded work: Apply the approved rule delta and declared external counterpart; keep policy-specific repairs separate.\nReturn evidence sufficient to test: Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nReject this false completion: A new global expression changes historical or unrelated policies unexpectedly: fail.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ad96d9ad9a3003076d8efde4e1a65bf69bd28cdd9f49def451c3a218cb495f30",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-23-4",
        "parent_task_id": "task-fixture-cf-23-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2ba01ba698d75b3c33498760a1b573fa7294a3295480fca29874eb6f426f5833",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-23-5",
        "parent_task_id": "task-fixture-cf-23-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved rule delta and declared external counterpart; keep policy-specific repairs separate.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Apply the approved rule delta and declared external counterpart; keep policy-specific repairs separate.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "4368e3ad45dde6f7204111f2e2335a7d89c480a83d6defa34456d0e36e35307b",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-23-6",
        "parent_task_id": "task-fixture-cf-23-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b2c9824090b086036951fcb96e57e6ea553a5b1cee708d06f10d2e83ab62aa0f",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-23-7",
        "parent_task_id": "task-fixture-cf-23-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-23",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain rule-boundary examples and distinguish configuration changes from one-policy corrections.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain rule-boundary examples and distinguish configuration changes from one-policy corrections.\nCase: fixture-cf-23; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "75c79640174c657d1623f3533a3100201fcb48ad49056e8741d99abc05336bf5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-23-executor",
        "parent_task_id": "task-fixture-cf-23-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-23\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-23-Spawn",
        "case_id": "fixture-cf-23",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-23-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Read the effective commission rule set, product/agent scope, dates and dependent policy calculations.\nPrepare the bounded work: Apply the approved rule delta and declared external counterpart; keep policy-specific repairs separate.\nReturn evidence sufficient to test: Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.\nReject this false completion: A new global expression changes historical or unrelated policies unexpectedly: fail.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-23-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-23-Plan",
        "case_id": "fixture-cf-23",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-23-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-23",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-23-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-23-PlanConfirmation",
        "case_id": "fixture-cf-23",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-23-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-23",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-23-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-23-Result",
        "case_id": "fixture-cf-23",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-23-3",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-23-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-23-Verdict",
        "case_id": "fixture-cf-23",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-23-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A new global expression changes historical or unrelated policies unexpectedly: fail.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-23-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Apply the approved rule delta and declared external counterpart; keep policy-specific repairs separate.",
      "case_specific_proof": "Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00586"
            },
            "body": {
              "module": "configuration",
              "description": "Commission rule set",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00587"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00588"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: Representative effective-date and participant cases produce the expected commission with currency; unaffected scopes stay unchanged."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00589"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00590"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain rule-boundary examples and distinguish configuration changes from one-policy corrections."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00591"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00592"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00593"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00594"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Commission rule set",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Read the current effective rule and its affected scope before reusing the earlier expression."
      }
    ]
  },
  "CF-24": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-24-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "b76c111080a26d2a8d2cea2e7b92233cacb31f74931710a9b307d1478225f7bd",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-24-1",
        "parent_task_id": "task-fixture-cf-24-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "560bbee635644afeba4786a93518ae39dd0449ee1dd26546a645c555c0721997",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-24-2",
        "parent_task_id": "task-fixture-cf-24-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "36a1abf3934563eca24f042f010025c7fa78a055050c4904c83e7a45a00e8fc9",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-24-3",
        "parent_task_id": "task-fixture-cf-24-0",
        "profile_key": "source.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "dccbeb6b6c85eaddc8588515b5a084c61c53c9a22cdfa478bd241d60c791c0e7",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root"
      },
      {
        "task_id": "task-fixture-cf-24-4",
        "parent_task_id": "task-fixture-cf-24-2",
        "profile_key": "configuration.ipal.stage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration/ipal",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Establish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.ipal.stage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/ipal/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "43674db9bd11a6e5c514aa3cbbca33aebb90bd4943fc172f1fde20a08cbb14c0",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-ipal-stage"
      },
      {
        "task_id": "task-fixture-cf-24-5",
        "parent_task_id": "task-fixture-cf-24-3",
        "profile_key": "source.camunda_developer",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Establish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.camunda_developer. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8f33fed46b3d958bdc86a3b78e0be4ef20490f45132c707925d31b902ba2122d",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-camunda_developer"
      },
      {
        "task_id": "task-fixture-cf-24-6",
        "parent_task_id": "task-fixture-cf-24-3",
        "profile_key": "source.implementer.serdica-backend",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "source/serdica-backend",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Establish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: source.implementer.serdica-backend. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned source/serdica-backend/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2473e866ead782de318dc03de7cef150153c7c62f586a25f9efac09d5efe43b2",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [
            "worktree.edit",
            "worktree.diff",
            "worktree.build"
          ],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/source-root/source-implementer-serdica-backend"
      },
      {
        "task_id": "task-fixture-cf-24-7",
        "parent_task_id": "task-fixture-cf-24-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "6a38e4517e5967fa09abf60f574e115497cb305b7b49031ca3fdf2cf7604a09a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-24-8",
        "parent_task_id": "task-fixture-cf-24-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "2d9e31c13239f59ba7030c2955b174e71b5df71ec780ae1810d11094c335c2ff",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-24-9",
        "parent_task_id": "task-fixture-cf-24-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "dcd6a223e65177d29dc08b8722e3a7fbce51351372f5d6fdc37c04e806801299",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-24-10",
        "parent_task_id": "task-fixture-cf-24-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-24",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain schema-plus-value-plus-consumer proof and the inert-registration counterexample.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain schema-plus-value-plus-consumer proof and the inert-registration counterexample.\nCase: fixture-cf-24; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "3555770a1a459dadec19f4c8cb0bea019487bed4bc83681178c3a01bd07a25ad",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-24-tests",
        "parent_task_id": "task-fixture-cf-24-3",
        "profile_key": "source.test_runner",
        "profile_version": 1,
        "stage_id": "S4",
        "state": "open",
        "execution_kind": "deterministic",
        "rendered_input": null,
        "task_text": "Run the declared build/test commands in the confined worktree and return their actual results.",
        "dispatch": "Only after the source plan and task dependencies permit it."
      },
      {
        "task_id": "task-fixture-cf-24-executor",
        "parent_task_id": "task-fixture-cf-24-4",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-24\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-24-Spawn",
        "case_id": "fixture-cf-24",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-24-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "task_text": "Establish: Map contract-type/process registration to real schema support, configuration values, BPMN and code consumers.\nPrepare the bounded work: Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.\nReturn evidence sufficient to test: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.\nReject this false completion: CONTRACT_TYPE is deployed but NULL and never consumed: no completion.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration/ipal",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-24-4"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-24-Plan",
        "case_id": "fixture-cf-24",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-24-4",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-24",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-24-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-24-PlanConfirmation",
        "case_id": "fixture-cf-24",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-24-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-24",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-24-4"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-24-Result",
        "case_id": "fixture-cf-24",
        "task_path": "root/configuration-root/configuration-ipal-stage",
        "sender": {
          "task_id": "task-fixture-cf-24-4",
          "profile_key": "configuration.ipal.stage",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-24-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-24-Verdict",
        "case_id": "fixture-cf-24",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-24-7",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "CONTRACT_TYPE is deployed but NULL and never consumed: no completion.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-24-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Coordinate the Configuration and Development results; deploy compatible schema/code before activating rows where required.",
      "case_specific_proof": "The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00595"
            },
            "body": {
              "module": "configuration",
              "description": "Process or contract-type registration",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00596"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00597"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The declared process/contract type is populated and actually selected by the target workflow, with an authorised test instance."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00598"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00599"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain schema-plus-value-plus-consumer proof and the inert-registration counterexample."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00600"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00601"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00602"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00603"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Process or contract-type registration",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Check all three layers before assuming a new field or registration row is sufficient."
      }
    ]
  },
  "CF-25": {
    "status": "Synthetic protocol examples; fixture versions/ids/evidence are not published or observed results. The two-step Plan/Result illustrates preparation only. Budget 10 is fixture data, not an operating default.",
    "api_base": "/ai-support/api/v1",
    "agent_initializations": [
      {
        "task_id": "task-fixture-cf-25-0",
        "parent_task_id": null,
        "profile_key": "support.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "ec6c57904df02c533a6c2066f414e8c20e423889358c9946d534f5bd6f7cdd0a",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root"
      },
      {
        "task_id": "task-fixture-cf-25-1",
        "parent_task_id": "task-fixture-cf-25-0",
        "profile_key": "support.triage",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Classify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.triage. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nClassify the request and retrieve compatible precedents before investigation. Do not treat a matching symptom as a proved mechanism. Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "04eec21ab832b8459549628b9541b1701943cc9111323feee4185c1f01e26043",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-triage"
      },
      {
        "task_id": "task-fixture-cf-25-2",
        "parent_task_id": "task-fixture-cf-25-0",
        "profile_key": "configuration.root",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Own the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.root. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nOwn the requested outcome. Select declared stages and specialists, confirm child plans, join their assertions and retain external/restoration obligations. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1f8e485fd9268e565f8be98383a8cac35d76568292e5649a7f4893f2bdb3004e",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root"
      },
      {
        "task_id": "task-fixture-cf-25-3",
        "parent_task_id": "task-fixture-cf-25-2",
        "profile_key": "configuration.estate_prober",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Establish: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\nPrepare the bounded work: Produce a reviewed reconciliation delta or a report-only result as requested; do not synchronise environments wholesale.\nReturn evidence sufficient to test: The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nReject this false completion: A TEST-only UI_REQUIRED column is used in a PROD write packet: reject before dispatch.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.estate_prober. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nEstablish: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\nPrepare the bounded work: Produce a reviewed reconciliation delta or a report-only result as requested; do not synchronise environments wholesale.\nReturn evidence sufficient to test: The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nReject this false completion: A TEST-only UI_REQUIRED column is used in a PROD write packet: reject before dispatch.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "a93f851e4ccd53bf71e943a519697a10ec824b133df8929a01ec6a6687b25256",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-estate_prober"
      },
      {
        "task_id": "task-fixture-cf-25-4",
        "parent_task_id": "task-fixture-cf-25-2",
        "profile_key": "configuration.verifier",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "configuration",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Independently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [
          "investigator_transcript"
        ],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: configuration.verifier. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nIndependently test the proposed result against current evidence. Return agree/disagree with separating evidence. Do not read the investigator's transcript. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned configuration/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "d3ef8d1af80e6044fd80cd3382464afc6f31e5e2a57063111b02f2abef33ff40",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/configuration-root/configuration-verifier"
      },
      {
        "task_id": "task-fixture-cf-25-5",
        "parent_task_id": "task-fixture-cf-25-0",
        "profile_key": "platform.write_auditor",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "platform",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Review exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Produce a reviewed reconciliation delta or a report-only result as requested; do not synchronise environments wholesale.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: platform.write_auditor. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nReview exactness, boundedness, reversibility, authority scope and mechanism for the current packet. Return pass/refuse with failed items. Never execute it. Produce a reviewed reconciliation delta or a report-only result as requested; do not synchronise environments wholesale.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned platform/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "1a13ade8d0077054822e96dfcfe40cc8389f0fe1c5a8d4c4a0dbbe1b1ec5b6e5",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/platform-write_auditor"
      },
      {
        "task_id": "task-fixture-cf-25-6",
        "parent_task_id": "task-fixture-cf-25-0",
        "profile_key": "support.communicator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Draft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.communicator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nDraft the actual achieved result and outstanding work in customer language. No database details in the client view. Sending requires its own granted operation. The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "8ff3ef6efe1ed994b778ffbc623f13a1ea510a8b522edb651b2090dcdc3246a3",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-communicator"
      },
      {
        "task_id": "task-fixture-cf-25-7",
        "parent_task_id": "task-fixture-cf-25-0",
        "profile_key": "support.curator",
        "profile_version": 1,
        "prompt_version": 1,
        "model_route": "fixture-readonly-route-v1",
        "execution_kind": "llm",
        "memory_node": "support/experience",
        "state": "open",
        "lease_owner": null,
        "fence_epoch": 0,
        "runtime_version": "fixture-v1",
        "grant_subset": [
          "fixture-read-grant"
        ],
        "budget_minutes": 10,
        "pinned_inputs": {
          "manifest": "fixture-manifest-v1",
          "case_type": "fixture-CF-25",
          "plan_revision": 1
        },
        "task_text": "Record actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain compatibility checks and directional drift classifications, with observation dates.",
        "permitted_preparation_tools": [
          "papers.read",
          "papers.write",
          "memory.read",
          "memory.search",
          "connectors.read"
        ],
        "denied_context": [],
        "rendered_input": "[TRUSTED PLATFORM/PROFILE PROTOCOL]\nWorking discipline (published protocol, adapted from CLAUDE_andrej-karpathy.md):\n1. State assumptions. Separate confirmed evidence, hypothesis and missing information.\n2. Make the smallest change that achieves this task; add no optional feature or unrelated cleanup.\n3. Preserve unrelated state and work. Work only at the authorised target and scope.\n4. Define success as explicit checks. Reconcile the whole plan; missing evidence is not success.\nQuestions and dead ends go to the parent. Only the root presents unresolved questions to a human.\nThese rules guide reasoning. Runtime grants and capability checks enforce authority.\nRole: support.curator. Return model-turn v1 only.\n[REGISTERED TOOLS AND AUTHORITY]\nInitial estate access is read-only: connectors.read. Owned case papers may be read/written; memory.read/search retrieves evidence. Return a Plan or Question when more work is needed. No target write, send, deployment or grant creation tool is exposed.\n[PARENT TASK, CURRENT PLAN]\nRecord actual outcome and independent uses. File proposed experience and hand domain changes to the canonical owner; do not auto-publish or grant authority. Retain compatibility checks and directional drift classifications, with observation dates.\nCase: fixture-cf-25; plan revision: 1.\n[DOMAIN KNOWLEDGE, DERIVED EVIDENCE]\nRead the pinned support/experience/AGENTS.md index. Historical catalogue evidence is a candidate: 20 Configuration/Typical Cases.md. Re-check its current applicability. Initial knowledge context: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\n[CURRENT CASE PAPERS]\nrequest, approved scope, target inventory and selected evidence revisions only. Unavailable papers must be requested, not invented. Fixture paper references below stand for stored bytes.\n[OUTPUT]\nOne schema-valid tool_calls or message object. A stated summary and evidence references, not hidden chain-of-thought. Unproved or externally reported results remain unproved.",
        "input_sha256": "0e486d6a149811d80d18420d213ef9955e8e451fe0e77d533e1b08c61c0e8a63",
        "phase_tool_catalogues": {
          "preparation": [
            "papers.read",
            "papers.write",
            "memory.read",
            "memory.search",
            "connectors.read"
          ],
          "after_parent_plan_confirmation": [
            "papers.write",
            "tasks.consult",
            "tasks.spawn",
            "skills.run",
            "writes.propose"
          ],
          "after_placement_approval": [],
          "post_result": [
            "papers.write",
            "memory.propose"
          ],
          "restriction": "Each list is intersected with the published profile, current grants and capabilities. No model receives direct mutating connector or grant creation tools. gates.request is root-only."
        },
        "task_path": "root/support-curator"
      },
      {
        "task_id": "task-fixture-cf-25-executor",
        "parent_task_id": "task-fixture-cf-25-3",
        "profile_key": "platform.write_executor",
        "profile_version": 1,
        "state": "open",
        "execution_kind": "deterministic",
        "grant_subset": [
          "fixture-reserved-effect-grant"
        ],
        "task_text": "Execute the exact current granted packet and return journalled evidence; no model prompt.",
        "rendered_input": null,
        "dispatch": "Created by the execution coordinator service only after all effect gates pass; inherits the reserved exact-packet grant and current fence."
      }
    ],
    "model_responses": [
      {
        "kind": "tool_calls",
        "summary": "Read current scope before choosing a historical solution.",
        "tool_calls": [
          {
            "name": "connectors.read",
            "arguments_json": "{\"operation_id\": \"fixture.scope.read\", \"input\": {\"case_scope_ref\": \"paper:current-scope\"}}"
          }
        ],
        "message": null
      },
      {
        "kind": "message",
        "summary": "Return the bounded preparation plan to the parent.",
        "tool_calls": [],
        "message": {
          "type": "Plan",
          "payload_json": "{\"plan_id\": \"plan-fixture-cf-25\", \"revision_no\": 1, \"step_count\": 2, \"open_questions\": 0}",
          "paper_ref": "paper:two-step-illustration"
        }
      }
    ],
    "messages": [
      {
        "type": "Spawn",
        "version": 1,
        "message_id": "message-fixture-cf-25-Spawn",
        "case_id": "fixture-cf-25",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-25-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "kind": "sub_agent",
          "profile_key": "configuration.estate_prober",
          "profile_version": 1,
          "task_text": "Establish: Compare only affected source/target groups in both directions, including columns, current rows, effective versions and consuming code.\nPrepare the bounded work: Produce a reviewed reconciliation delta or a report-only result as requested; do not synchronise environments wholesale.\nReturn evidence sufficient to test: The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.\nReject this false completion: A TEST-only UI_REQUIRED column is used in a PROD write packet: reject before dispatch.",
          "budget_minutes": 10,
          "grant_subset": [
            "fixture-read-grant"
          ],
          "memory_node": "configuration",
          "denied_context": []
        },
        "recipient_task_id": "task-fixture-cf-25-3"
      },
      {
        "type": "Plan",
        "version": 1,
        "message_id": "message-fixture-cf-25-Plan",
        "case_id": "fixture-cf-25",
        "task_path": "root/configuration-root/configuration-estate_prober",
        "sender": {
          "task_id": "task-fixture-cf-25-3",
          "profile_key": "configuration.estate_prober",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-25",
          "revision_no": 1,
          "step_count": 2,
          "open_questions": 0
        },
        "artefact": {
          "hash": "75e8d36bac3e9a9837ea54e45235aa68362401860ef304834095195f1979d506",
          "paper_ref": "paper:two-step-illustration"
        },
        "recipient_task_id": "task-fixture-cf-25-2"
      },
      {
        "type": "PlanConfirmation",
        "version": 1,
        "message_id": "message-fixture-cf-25-PlanConfirmation",
        "case_id": "fixture-cf-25",
        "task_path": "root/configuration-root",
        "sender": {
          "task_id": "task-fixture-cf-25-2",
          "profile_key": "configuration.root",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "plan_id": "plan-fixture-cf-25",
          "revision_no": 1,
          "decision": "confirmed",
          "scope_confirmed": [
            "establish",
            "propose"
          ]
        },
        "recipient_task_id": "task-fixture-cf-25-3"
      },
      {
        "type": "Result",
        "version": 1,
        "message_id": "message-fixture-cf-25-Result",
        "case_id": "fixture-cf-25",
        "task_path": "root/configuration-root/configuration-estate_prober",
        "sender": {
          "task_id": "task-fixture-cf-25-3",
          "profile_key": "configuration.estate_prober",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "proof_level": "structural",
          "reconciliation": {
            "steps_planned": 2,
            "steps_done": 2,
            "assertions_passed": 1,
            "assertions_failed": 0
          },
          "missing_open": 0
        },
        "artefact": {
          "hash": "c143136ca276df827167377f907cf0685e68ea595dcee8190351449e58d1a0f4",
          "paper_ref": "paper:prepared-plan-not-target-proof"
        },
        "recipient_task_id": "task-fixture-cf-25-2"
      },
      {
        "type": "Verdict",
        "version": 1,
        "message_id": "message-fixture-cf-25-Verdict",
        "case_id": "fixture-cf-25",
        "task_path": "root/configuration-root/configuration-verifier",
        "sender": {
          "task_id": "task-fixture-cf-25-4",
          "profile_key": "configuration.verifier",
          "profile_version": 1,
          "runtime_version": "fixture-v1"
        },
        "occurred_on": "2026-09-07T09:00:00Z",
        "trust_class": "derived",
        "payload": {
          "verdict": "refuse",
          "checks": [
            {
              "check": "mechanism",
              "result": "refuse",
              "failing_item": "A TEST-only UI_REQUIRED column is used in a PROD write packet: reject before dispatch.",
              "evidence_ref": "paper:falsifying-evidence"
            }
          ]
        },
        "artefact": {
          "hash": "03db55040e8993179eb8a8bdc0c5f3c2f2b91cd5039cd65c16bd0bcfecceb656",
          "paper_ref": "paper:refusal"
        },
        "recipient_task_id": "task-fixture-cf-25-2"
      }
    ],
    "connector_execution": {
      "input_type": "WritePacketCall",
      "fields": [
        "Call: OperationId, Version, Scope, InputJson, IdempotencyKey, CaseId, TaskId, RuntimeCallId, FenceEpoch",
        "ShapeKey/ShapeVersion, ArtefactHash, BoundStep[] with template hashes, concrete parameters and expected counts",
        "Assertion[] with query/call and expected result, teardown hashes, PreflightRequired"
      ],
      "coordinator": "Resolve exact immutable packet and current GrantView; compare hash/scope, all decision ids, expiry, ReservedCallId and FenceEpoch immediately before dispatch.",
      "forms": {
        "A": "One deterministic connector operation: apply uncommitted, verify local assertions and consuming query, then commit; failure rolls back locally.",
        "B": "Leased deterministic multi-call transaction; no model/provider or human wait while open; expiry rolls back.",
        "E": "External/DDL effect: dispatch once, journal observed result, reconcile unknown/partial outcome with WhatLandedAsync before retry."
      },
      "output_type": "WriteResult: StepOutcome[] expected/actual counts and returned ids; VerifyResult assertions/level; actual statement/call; teardown reference; nullable commit time; LandedDisposition.",
      "case_specific_execution": "Produce a reviewed reconciliation delta or a report-only result as requested; do not synchronise environments wholesale.",
      "case_specific_proof": "The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work.",
      "reversal": "Before a committed effect, record its exact inverse/compensation. After commit, an H7 packet uses the original journal plus current target state; its execution has a new operation identity. Uncommitted local failure rolls back immediately. Irreversible residues stay explicit."
    },
    "provider_call": {
      "interface": "IInferenceClient.ExecuteAsync(InferenceRequestV1)",
      "input": "Exact rendered_input bytes above; one input document in the copied adapter.",
      "output_schema": "contracts/model-turn.schema.json",
      "persistence": "PAPERS request bytes and hash before dispatch; RUNTIME_CALLS request/ref/disposition; response bytes then action validation before tools."
    },
    "transitions": [
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201; case/arrival identities; authority gaps return 202",
            "headers": {
              "Idempotency-Key": "fixture-command-00604"
            },
            "body": {
              "module": "configuration",
              "description": "Environment reconciliation before configuring",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/client/requests/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "ARRIVALS: canonical origin, received time, source/body hashes, state and case id",
          "CASES: objective, customer, selected case type, clocks and opened state",
          "PAPERS: normalised request and initial context; CASE_HANDLES: protected identity map",
          "INBOX_MESSAGES + OUTBOX_MESSAGES + AUDIT_LEDGER: command dedup, queued triage and event, committed atomically"
        ],
        "initialization": "Create root and triage tasks. Child tasks are opened only when the route/plan permits them; the examples list the eventual roles, not an eager spawn of every role."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "TASKS: pinned profile/version, task text, parent, stage, restricted grants, memory node, lease/fence",
          "PAPERS: current inventory, evidence, exact model input/output; RUNTIME_CALLS: model intent/result",
          "TURN_CHECKPOINTS: state-paper id/hash, pending calls/messages and next turn; MEMORY_USES: actual retrieval/use verdict"
        ],
        "initialization": "Run the selected specialist preparation prompt below. Reads go through a registered scoped operation; fixture.scope.read is a test adapter placeholder, not an estate operation that exists."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 decision; 409 stale version/hash; 403 wrong role",
            "headers": {
              "Idempotency-Key": "fixture-command-00605"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "79608af5b4a07d593f617b49271ecfadda391f21263376cb38c707a540d248fa",
              "expected_version": "4",
              "reason": "Fixture: approve the displayed scope."
            }
          }
        ],
        "storage": [
          "PLANS + immutable PLAN_REVISIONS: confirmed scope/hash; PLAN_STEPS: stable ids, target, effects and assertion references",
          "PAPERS: semantic packet, execution-obligation matrix, audit/verifier reports",
          "GATES + GATE_DECISIONS: checkpoint/effect decisions; GRANTS: only eligible exact effect scope; no write on plan confirmation"
        ],
        "initialization": "Specialist Plan returns to its immediate parent; PlanConfirmation orders work. The root raises the applicable gate; parent confirmation does not replace it."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/responses",
            "response": "202 checking; only when an assigned external step exists",
            "headers": {
              "Idempotency-Key": "fixture-command-00606"
            },
            "body": {
              "request_ref": "paper:external-instruction",
              "expected_version": "5",
              "response_kind": "report_completed",
              "step_id": "external-step",
              "plan_revision": 1,
              "text": "Fixture: I performed the requested action; please verify.",
              "evidence_refs": [
                "paper:uploaded-evidence"
              ]
            }
          },
          {
            "method": "GET",
            "path": "/cases/{caseId}/cards",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "External branch: response paper + TASKS parked/reopened; INBOX_MESSAGES/OUTBOX_MESSAGES atomically schedule verification",
          "Platform branch: RUNTIME_CALLS intent; IMPACT_LOCKS and grant reservation; connector result; WRITE_LOG only for platform effects",
          "BUILD_STATE records verified completed steps/returned ids; TURN_CHECKPOINTS records next work; no model holds a transaction"
        ],
        "initialization": "The response POST is conditional on external work. Automatic execution needs no extra browser Execute endpoint: the execution coordinator dispatches after the gate. It constructs OperationCall from the approved packet and current grant/fence."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/cases/{caseId}/where",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}/{kind}/{name}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: per-member assertion results with exact query/tool and evidence revision",
          "Execution paper: which required checks passed/failed; PLAN_STEPS and BUILD_STATE update only on verified evidence",
          "RUNTIME_CALLS/WRITE_LOG remain authoritative for what landed; no successful assertion is invented from model text"
        ],
        "initialization": "Initialise an independent verifier with current evidence and required assertions; deny the investigator transcript. Required proof: The report accounts for every selected difference, or the applied delta passes its target assertions while preserving accepted target-only work."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/decisions/gates/{gateId}",
            "response": "200; current authorised projection"
          },
          {
            "method": "POST",
            "path": "/decisions/gates/{gateId}/decide",
            "response": "200 H7 decision; separate effect prerequisites still compose",
            "headers": {
              "Idempotency-Key": "fixture-command-00607"
            },
            "body": {
              "decision": "approve",
              "artefact_hash": "51a804c151c04781b4e17e2849711d7c09bbf4a901a7e46ecff6eddeff461fee",
              "expected_version": "6",
              "reason": "Fixture: approve the displayed H7 compensation."
            }
          }
        ],
        "storage": [
          "PAPERS: reversal packet derived from original effect journal, before image and current comparison",
          "GATES/GATE_DECISIONS/GRANTS: H7 plus applicable target/effect permissions",
          "RUNTIME_CALLS: new reversal operation id, original call retained; WRITE_LOG: inverse/compensating effect and proof; suspended shape recorded when required"
        ],
        "initialization": "Failure returns to the responsible root. Re-read current target state, propose the exact reversal, and run only the authorised compensation. For a DB-local uncommitted validation failure the deterministic connector rolls back immediately; no H7 is needed to avoid committing. After commit, never overwrite later external changes. A read-only answer/referral has no target rollback; correct its record and communicate through the send gate."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests/{caseId}/accept",
            "response": "200 only for the shown customer-owned acceptance; early proof gaps remain visible",
            "headers": {
              "Idempotency-Key": "fixture-command-00608"
            },
            "body": {
              "gate_id": "fixture-delivery-gate",
              "artefact_hash": "454ec99c2d215753249eaca79a278df756b1796ef85e0ebcbe7e8e704e1ee803",
              "decision": "accept",
              "scope": "delivery",
              "expected_version": "7",
              "note": "Fixture: the stated result is accepted."
            }
          }
        ],
        "storage": [
          "CASES: resolved only after obligation join; GATE_DECISIONS: the corresponding acceptance",
          "PAPERS: achieved outcome and remaining/successor obligations; channel-send call/evidence retained",
          "OUTBOX_MESSAGES post-result job and resolution commit together; customer confirmation closes after required technical proof"
        ],
        "initialization": "Communicator receives a verified outcome summary, not unrestricted source transcripts. Preparation of scripts, preview and a completed subcase do not silently change the parent's objective."
      },
      {
        "http": [
          {
            "method": "GET",
            "path": "/knowledge/proposals",
            "response": "200; current authorised projection"
          },
          {
            "method": "GET",
            "path": "/papers/{caseId}",
            "response": "200; current authorised projection"
          }
        ],
        "storage": [
          "PAPERS: sanitised experience and precipitation decision linked to result revision",
          "EXPERIENCE_ENTRIES: proposed index entry with actual outcome and execution-record reference",
          "MEMORY_ARTICLES: proposed owned-domain change; AUDIT_LEDGER: justified nothing, reuse or correction; OUTBOX/INBOX prevents duplicate post-result work"
        ],
        "initialization": "Initialise support.curator and, where needed, the actual domain owner with the retained sanitised result. Retain compatibility checks and directional drift classifications, with observation dates."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/evaluate",
            "response": "202 evaluation queued",
            "headers": {
              "Idempotency-Key": "fixture-command-00609"
            }
          },
          {
            "method": "POST",
            "path": "/knowledge/articles/{articleId}/confirm",
            "response": "200 active only for the authorised owner/review path",
            "headers": {
              "Idempotency-Key": "fixture-command-00610"
            }
          },
          {
            "method": "POST",
            "path": "/studio/{subject}/{key}/{version}/publish",
            "response": "200 published; 403/409/422 when authority, revision or publish prerequisites fail",
            "headers": {
              "Idempotency-Key": "fixture-command-00611"
            }
          }
        ],
        "storage": [
          "EVAL_SETS/evaluation records: pinned dependency versions and positive/negative case results",
          "MEMORY_USES: independent canonical requests and verification verdicts; MEMORY_ARTICLES/registry new version on publication",
          "WRITE_SHAPES/RISK_ACCEPTANCES are separate authority records and are never changed merely by publishing knowledge"
        ],
        "initialization": "Run the affected profile eval set with held-out request/causal families. Corrections are new immutable versions; source/proposed material never becomes authority."
      },
      {
        "http": [
          {
            "method": "POST",
            "path": "/client/requests",
            "response": "201 new case; delivery retry with the original key remains the original request",
            "headers": {
              "Idempotency-Key": "fixture-command-00612"
            },
            "body": {
              "module": "configuration",
              "description": "A new independent request of the same kind: Environment reconciliation before configuring",
              "attachments": []
            }
          },
          {
            "method": "GET",
            "path": "/knowledge/experience/search",
            "response": "200 compatible active candidates; this is the operator API, not a customer data feed"
          }
        ],
        "storage": [
          "New CASES/ARRIVALS/CASE_HANDLES and fresh plan/grants; origin aliases dedup only the same source request",
          "MEMORY_USES records candidate selection, pinned article/skill version and current applicability proof",
          "PAPERS: fresh preflight and discriminating evidence; no old result/grant reused as current proof"
        ],
        "initialization": "New root/triage and specialist tasks use the current published revisions. Re-measure affected groups; stored differences are historical evidence, never today's source of truth."
      }
    ]
  }
}