# AGENT-PROMPT-v5-P1-1b — O10 amendment 5: Piece A reattempt by remediation, consolidated checklists, proof-pattern annex, test-plan gate, PROJECT-STATE repair

**Date:** 2026-08-06
**Follows:** `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-3.md` (the four-piece decomposition),
`docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-4.md` (the reformulated preflight),
`docs/p1-1b-o10-independent-review.md` (Piece A Reject #1 on candidate `6f86023d…`),
`docs/p1-1b-status.md`, `docs/PROJECT-STATE.md`
**Authority:** Miguel, deciding the Piece A Reject #1 report. This amendment accepts the Piece A
review's findings **in full** as binding remediations, authorizes the **second and final**
pre-escalation Piece A attempt, and adds three process instruments aimed at cycle time. It
reopens no decision. O8-D1/D2, O9-P, O9-D1…D5, O10-D1/D2, amendment 3's four-piece plan, and
amendment 4's preflight all remain in force unchanged. The five baselines stay
119 / 119 / 52 / 221 / **2,787**; the two `Routine` rows still import verbatim; the pin remains
`b91768513fc638381fbde91f0b576b08220a98f6`. Monolithic rejects `b324a3e…`, `57f0f023…`, and
`7ea6c0f…` remain neutralized evidence only, never resurrected, not even in part.

## What Reject #1 established

The review's disposition table records **13 of 16 requirement rows as Pass** on the exact
records-base-to-candidate diff, 0 Critical, and four narrow findings — one behavioral
(the validator identity-class gate is absent), three of proof (EF store-type parity, the
wrong-company evidence test, and status claims exceeding assertions). The High finding's root
cause is a **specification-integration failure**, not a design failure: the identity-class
validator gate is a standing amendment-2 requirement that amendment 3's Piece A list did not
restate, despite amendment 3's promise that every open finding is assigned to exactly one
piece. This amendment assigns it, explicitly, to Piece A.

## Remediation basis — piece candidates may be remediated, monoliths may not

The never-resurrect rule continues to bind `b324a3e…`, `57f0f023…`, and `7ea6c0f…` **by name**
and in full. For **piece** candidates under amendment 3, when a Reject records **0 Critical**
and an enumerated requirement-by-requirement disposition table, the reattempt is a
**remediation of the rejected candidate**, not a from-scratch rewrite: it takes the rejected
candidate's content as its base and applies exactly the named remediations, nothing else.
Rationale, on the record: the review confirmed the passing surfaces against the exact diff;
rewriting them from zero re-rolls implementation variance on proven ground — the failure mode
the decomposition exists to eliminate — and doubles the review burden. The guard is in the
re-review scope below. This basis applies to Piece A attempt #2 now and to future piece
reattempts meeting the same conditions; it never applies to the three named monolithic rejects.

## Binding remediations for Piece A attempt #2

| # | Requirement | Required proof |
|---:|---|---|
| **A-R1 (High)** | `RegistryValidationService` enforces the closed D8 `ItemClass` vocabulary: any **non-null** value outside the closed vocabulary produces an identity-class failure, fail-closed, for **DOCEFL rules and DOCFLG snapshots, imported and native alike**. The database CHECKs remain an independent second barrier, not the gate. | Four validator tests — DOCEFL and DOCFLG, imported and native each — proving an unknown non-null value (e.g. `Invented`) fails closed at the validator; plus the existing null-observation behavior unchanged. |
| **A-R2 (Medium)** | The EF model and snapshot map `DOCFLG.ImportTargetTable` with its actual store type `varchar(32)`, generated/stored expression included — the model matches the SQL catalog **exactly**, store type and all. | A test comparing the EF relational store type against the disposable-database catalog for **every column Piece A adds or alters**, not only the expression/stored flags. |
| **A-R3 (Medium)** | The imported terminal-evidence exemption is proven company-isolated, not only inspected. | A disposable test creating same-code `ImportEvidenceRow` evidence for **another company** and proving it cannot exempt a terminal DOCFLG row. |
| **A-R4 (Low)** | The catalog/uniqueness proof asserts everything its status claims — or the claim is narrowed to what is asserted. | A direct accepted-versus-first-Up comparison of **both** accepted `ImportEvidenceRow` unique-constraint definitions, and inclusion of indexes and column store types for touched objects in the compared catalog surface. Status wording may not exceed the assertions. |

**The Piece A checklist for attempt #2 is the review's disposition table plus A-R1…A-R4:**
every row recorded Pass must still pass on the new diff; the Partial/Fail rows convert to Pass
via the remediations above. No other change to the candidate's content is authorized; an
apparent need for one is a stop-and-report.

## Consolidated checklist discipline — binding for A#2 and for Pieces B, C, D

Each piece's go-ahead must carry **one numbered, exhaustive checklist** merging every
applicable requirement from every standing amendment. The implementer's evidence map and the
reviewer's disposition both key to that checklist and to nothing else. If an implementer or
reviewer finds a standing requirement absent from the checklist, that is a **stop-and-report**
— never silently satisfied, never silently skipped. For attempt #2 the checklist is defined
above; for Pieces B, C, and D the checklists are authored with their go-aheads (they may be
pre-drafted for Miguel's approval while a prior piece is under review).

## Proof-pattern annex — binding on every piece from this amendment forward

1. **Claims equal assertions.** Every proof asserts exactly the state its status record claims;
   an overstated claim is a defect even when the code is correct.
2. **Cross-company negatives.** Every company-scoped object, predicate, or exemption gets a
   negative test proving the wrong-company case fails.
3. **Store-type parity.** Every column a piece adds or alters — generated columns especially —
   gets an EF-versus-catalog store-type comparison test.
4. **"Unchanged" is asserted, not assumed.** Every claim that an accepted object is untouched
   gets a direct catalog assertion comparing accepted definitions with post-Up state.
5. **Vocabularies close twice.** Every closed vocabulary is enforced at the database **and** at
   the validator, with unknown-value fail-closed tests covering imported and native rows.

## Test-plan gate — binding on every piece from this amendment forward

After the governed records commit and **before any implementation code**, the implementer
records the checklist→test mapping (a numbered list: each checklist item to the exact test(s)
that will prove it) in `docs/p1-1b-status.md` and submits it to Miguel for a quick approval.
Implementation starts only after that approval. For attempt #2 this is a short delta list —
still required. The gate exists because all four Reject #1 findings were visible at
test-plan level before a line of code was written.

## PROJECT-STATE repair — ordered, and a recorded process finding

`docs/PROJECT-STATE.md` was not updated for amendment 3, amendment 4, the amendment-4 preflight
pass, or the Piece A candidate/Reject #1/neutralization cycle, although amendment 4 step 1
expressly required its changelog entry. By the file's own precedence rule, the repository's
authoritative state currently denies that Piece A ever ran. This omission is recorded as a
process finding. Binding from now on: **every records commit that changes `p1-1b-status.md` or
`p1-1b-o10-independent-review.md` must update `PROJECT-STATE.md` in the same commit**; a
records commit that leaves them contradictory is itself a defect.

## Parallel O5-prep

The separate assignment `docs/AGENT-PROMPT-v5-P1-2-o5-prep.md` runs under its own authority on
its own disjoint branch and file surface. Miguel green-lights running it **in parallel** with
Piece A attempt #2 now. Its file-surface disjointness rule stands: needing to touch a P1-1b
file is a stop-and-report.

## Re-review scope for attempt #2

A focused independent review: full adversarial depth on A-R1…A-R4 and their proofs, plus
regression confirmation — against the new exact diff — that every disposition row recorded
Pass in Reject #1 still holds. An explicit Accept/Reject verdict is recorded as always. Per
amendment 3, a second Piece A Reject stops everything and escalates to Miguel.

## What this amendment does not authorize

Starting Piece B, C, or D before the prior piece's recorded Accept. Any content change to the
candidate beyond A-R1…A-R4. Resurrecting any part of the three named monolithic rejects. Any
prototype write or post-pin read. Reopening any closed decision or changing any baseline. Any
shared/live database write before the complete disposable rehearsal passes and a verified
fresh backup exists. Production go-live (O5 remains the only other open item). History rewrite
in either repository.

## Ordered instruction

1. **Governed records commit (push before code).** Record this amendment's acceptance and the
   Reject #1 findings in `docs/p1-1b-status.md`; **repair `docs/PROJECT-STATE.md` in the same
   commit** — header, P1-1b phase row, "Still not authorized" section, and changelog entries
   for amendment 3, amendment 4 (including the reformulated-preflight pass and the recorded
   `3dd4150…` divergence), the Piece A candidate and Reject #1 and its neutralization, and this
   amendment; track this prompt file.
2. **Test-plan gate.** Record the attempt-#2 checklist→test mapping and obtain Miguel's
   approval before implementation.
3. **Implement attempt #2 as a remediation of candidate `6f86023d…`** under the amendment-4
   preflight: apply A-R1…A-R4 exactly; full ordinary, focused, and disposable suites green;
   build 0 warnings; 0 residual containers; commit and push. The status evidence map keys to
   the attempt-#2 checklist item by item.
4. **Focused independent re-review** per the scope above, verdict recorded. On Accept, stop and
   report — Piece B needs its own go-ahead. On Reject, neutralize as amendment 3 defines, stop,
   and escalate to Miguel.

O5-prep proceeds in parallel under its own prompt throughout.

## Report at the end

Commit hashes per stage; the attempt-#2 evidence map item by item; the re-review verdict in
full; build/test/container evidence; confirmation that `PROJECT-STATE.md`, `p1-1b-status.md`,
and the review record are mutually consistent; and the O5-prep progress note.
