# AGENT-PROMPT-v5-P1-1b — O10 amendment 4: prototype preflight reformulated for a live source — snapshot-integrity pin, divergence-as-finding, Scope 1 re-pin checkpoint

**Date:** 2026-08-06
**Follows:** `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-2.md` (step 1 preflight),
`docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-3.md` (the four-piece decomposition),
`docs/p1-1b-status.md`, `docs/PROJECT-STATE.md`
**Authority:** Miguel, deciding the preflight stop reported on 2026-08-06 before Piece A started.
This amendment changes **one thing**: the prototype half of the read-only preflight. It reopens
no decision. O8-D1/D2, O9-P, O9-D1…D5, and O10-D1/D2 remain closed and govern unchanged. The
five completeness baselines stay 119 / 119 / 52 / 221 / **2,787**, the two `Routine` rows still
import verbatim, and the immutable pin remains `b91768513fc638381fbde91f0b576b08220a98f6`.
Rejected `b324a3e…`, `57f0f023…`, and `7ea6c0f…` remain neutralized evidence only. The
four-piece plan of amendment 3 stands exactly as written.

## The stop this amendment decides

The Piece A preflight stopped correctly and changed nothing. Findings, on the record:

- Prototype local `HEAD` = pin `b917685…` — correct.
- Prototype `origin/main` and live `refs/heads/main` = `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`
  — divergent from the pin.
- The pin remains reachable and **is an ancestor** of the new main: history was not rewritten.
- Two post-pin commits exist: `1e841a4` *(Complete Stage 10 Round 8 reconciliation and mapping
  updates)* and `3dd4150` *(Apply Stage 10 Round 8 revenue review updates)*, touching
  `Editor/Data` files including `entbnk.json`, `document_type_rules.json`, `entities.json`,
  `flag_instances.json`, and `permanent_code_ledger.json`.

## Why the preflight changes and the pin does not

Amendment 2's preflight required local `HEAD`, local `origin/main`, and live `refs/heads/main`
to all equal the pin. That condition assumed a frozen source. The prototype is a **live,
operating system** — FDR keeps producing Stage 10 rounds — so tip-equality is now permanently
unsatisfiable without a prototype history rewrite, which is forbidden. The requirement's real
purpose was to detect silent source drift, and it did. The detector is kept; its shape is fixed.

Re-pinning to the new tip now is rejected: the post-pin commits touch the source files behind
**every governed baseline** (C8's 43/43/0/0, the 119/119 ENTMST gaps, the 52-row DOCEFL
manifest, the 221 terminal DOCFLG rows, the 2,787 snapshots, C13's measurements) and behind
O8-D1's verified-free `EF0000053` premise. Adopting the tip would force re-measurement of every
number, risk reopening closed decisions, and chase a target that will move again during the
four review-gated pieces. Pieces A–D read pinned content through `git show` at the pin, which
is content-addressed and immune to `main` moving; the freshness of live data has no bearing on
them. It matters only at Scope 1, which has its own checkpoint below.

## The reformulated prototype preflight — binding wherever the pin is checked

The prototype preflight for Piece A, and for every later preflight that references the pin
(Pieces B, C, D and the Scope 1 restart), verifies **snapshot integrity**, read-only as always
(metadata, `git fetch`, `git show`, `git merge-base` only — never checkout, pull, or merge):

1. **Pin reachable.** Commit `b917685…` resolves in the local clone and in the fetched remote.
2. **No history rewrite.** The pin is an ancestor of live `refs/heads/main`
   (`git merge-base --is-ancestor`). Failure is a **hard stop**: it means force-push or rewrite.
3. **Local clone anchored.** Local `HEAD` still equals the pin. A moved local `HEAD` is a
   **hard stop** (someone altered the working clone).
4. **Roster integrity at the pin.** 49/49 roster blobs resolve at the pin with their recorded
   hashes.
5. **Surface integrity at the pin.** The direct `Editor/Data` surface **at the pin** is exactly
   the 48 rostered files.
6. **Divergence is a recorded finding, not a stop.** When `refs/heads/main` is beyond the pin,
   record in `docs/p1-1b-status.md`: the live tip SHA, the hash and subject of every post-pin
   commit, and the statement that no post-pin content was read or adopted. Then proceed.

Checks 1–5 failing remain stop-and-report, never adapt. Check 6 replaces the former
tip-equality requirement; nothing else in amendment 2's step 1 (the Sibyla-side conditions) or
in amendment 3 changes.

## Non-adoption rule — binding

No file content, count, code, mapping, or value from **any commit after the pin** may inform
any Sibyla artifact: not a migration, not a fixture, not a test, not a validator expectation,
not a status record beyond the hash-and-subject divergence log above. Post-pin commits are
opaque. The prototype remains read-only for every agent under this prompt family, exactly as
before. If any piece's work appears to *need* post-pin content, that is a design contradiction:
stop and report.

## Scope 1 re-pin checkpoint — new, binding, and the only place freshness is decided

After Piece D's Accept and **before** the Scope 1 restart, Miguel decides explicitly, on the
record, between exactly two paths — neither is pre-decided by this amendment:

- **(a) Confirm `b917685…`** as the historical-import snapshot. Post-pin prototype evolution is
  then handled under the already-closed additive-period-imports decision (D4–D9) as later
  governed imports; the eventual cutover delta is acknowledged as inevitable either way,
  because the prototype keeps operating until Sibyla replaces it.
- **(b) Re-pin once** to the then-current tip under a new governed record (O11-class),
  requiring before any Scope 1 work: full roster/blob/surface re-verification at the new pin;
  re-measurement of all five baselines, C8 (43/43/0/0), and C13; the DOCTYP manifest re-check;
  and a verified-free check of `EF0000053` — and of every authored code — against the changed
  `permanent_code_ledger.json`. Any conflict between the new pin's data and a closed decision
  (O8-class or otherwise) is a stop-and-report, never an adaptation, and reopens nothing by
  itself.

## What this amendment does not authorize

Any prototype write. Reading or adopting post-pin prototype content. Re-pinning now. Starting
Piece B, C, or D before its predecessor's Accept verdict. Reopening O8, O9-P, O9-D1…D5, or
O10-D1/D2. Changing any baseline number. Resurrecting or cherry-picking any rejected commit.
Any shared/live database write before the complete disposable rehearsal passes and a verified
fresh backup exists. Production go-live (O5 remains the project's only other open item).
History rewrite in either repository.

## Ordered instruction

1. **Governed records commit (push before code).** Record this amendment's acceptance and the
   2026-08-06 preflight stop findings (including the divergence log per check 6) in
   `docs/p1-1b-status.md`; add the changelog entry to `docs/PROJECT-STATE.md`; track this
   prompt file. No baseline changes.
2. **Re-run the Piece A preflight under the reformulated checks above.** On any of checks 1–5
   failing: stop and report. On pass: proceed with **Piece A exactly as amendment 3 defines
   it**, through its independent review verdict, then stop and report as amendment 3 requires.
