> # ⛔ REVOKED — 2026-08-10
>
> **This go-ahead is revoked and must not be executed.** It authorises the P1-1b Scope 1–8 bulk
> import of the FDR document corpus. Decision **V6-D3** (`docs/V6.md` §2, 2026-08-10) cancels that
> import: no document data is imported into Sibyla. Documents enter one at a time through the
> defined channels as day-to-day work.
>
> Only **Layer 2** (Entity Item Classification) and **Layer 4** (Auxiliary Calculation) reference
> data is imported, plus the DOCTYP/DOCEFL rule catalogues as configuration. That work is
> `S1` in `docs/project-todo-v6.md`, not Scope 1, and it uses a plain idempotent seeder — no
> import-provenance machinery, no pinned-blob roster, no row-count acceptance criteria.
>
> Withdrawn together with this document: the five data-quality baselines (119 / 119 / 52 / 221 /
> 2,787), the 55.9% reconciliation baseline, and the grandfathering machinery, all of which exist
> only to serve the imported history.
>
> Retained as historical record. **Do not follow any instruction below this line.**

# AGENT-PROMPT-v5-P1-1b — Scope 1 go-ahead: the ordered Scopes 1–6, rehearsal first, live pass withheld

**Date:** 2026-08-09
**Follows:** `docs/AGENT-PROMPT-v5-P1-1b.md` (the standing prompt — Gate, Scope in order, the live
pass, what you may not do, report at the end), `docs/AGENT-PROMPT-v5-P1-1b-c8-amendment.md`,
`docs/AGENT-PROMPT-v5-P1-1b-o8-amendment.md`, `docs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md`,
`docs/AGENT-PROMPT-v5-P1-1b-o10-amendment.md`, `-o10-amendment-2.md` (step 5 / restart),
`-o10-amendment-3.md` (the four-piece decomposition and its process rules), `-o10-amendment-4.md`
(the reformulated preflight, the non-adoption rule, the Scope 1 re-pin checkpoint),
`-o10-amendment-5.md` (consolidated-checklist discipline, the proof-pattern annex, the test-plan
gate), `docs/AGENT-PROMPT-v5-P1-1b-scope1-pin-confirmation.md`,
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md` (format and sequencing precedent),
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-mapping-approval.md` (Miguel's Piece D test-plan approval and
the Observation 1 option (b) decision that defers item 5 to Scope 1),
`docs/p1-1b-status.md`, `docs/p1-1b-o10-independent-review.md`, `docs/PROJECT-STATE.md`
**Authority:** Miguel.
**What this document is:** Scope 1's own go-ahead and its gate specification. Scope 1's content was
authorized by the standing prompt as amended; **this document authorizes its start**, under the
gates below and under no others — and only after the governed acceptance of section 8 and the
test-plan gate of section 8 step 2. It reopens no decision, changes no baseline, and alters no
accepted object.

## 1 · Authority and base

**The four pieces are accepted.** Piece A `f6f297b…`, Piece B `7059809…` (the B-R1 remediation of
rejected candidate `b8fa033…`), Piece C `ce983b2…`, and Piece D attempt #2
`a4d40aac429584baed3481d62c2f859dd4ad2860` each carry a recorded independent Accept. Piece D's
verdict is **Accept — 0 Critical, 0 High, 0 Medium, 1 Low (D-A2-L1)**, recorded in
`docs/p1-1b-o10-independent-review.md` ("Piece D attempt #2 integration review — Accept") and
published at `744424df167af52b9680d0f46bfca50225422138`.

**The lower Reject wording in `docs/PROJECT-STATE.md` is superseded history, not a current
contradiction — and nothing in that file is edited here.** `PROJECT-STATE.md` carries, further down,
a **frozen historical snapshot** from the round in which a Piece D candidate stood rejected. That
lower text is **expressly superseded by the same file's top current blocks** — the merge-adoption
block, the confirmed-pin block, and the Piece D **Accept** block — which state the present state and
take precedence over the frozen snapshot below them. The lower wording is therefore **preserved
historical evidence** of a superseded round, not a live statement about the current verdict, and it
is left exactly as written: this document edits no part of `PROJECT-STATE.md` and asserts no repair
of it. If, on reading the file, a **genuinely current** contradiction remains — one the top current
blocks do not supersede — that is not resolved here or by the implementer: **checklist item 68
stops** and reports it for Miguel.

**What Piece D's Accept authorizes, attributed exactly.** Amendment 3 made Piece D's Accept "what
authorizes the Scope 1 restart"; **amendment 4 narrowed that** by interposing the
confirm-pin-or-re-pin checkpoint after Piece D's Accept and before any Scope 1 restart; and the
**Piece D go-ahead's ordered execution 4** states the narrowed form operatively — "**Only Accept
authorizes Scope 1 to seek/restart** at its own preflight and confirm-pin-or-re-pin checkpoint."
The correct attribution is therefore **amendment 3 as narrowed by amendment 4's checkpoint and as
ordered by the Piece D go-ahead's ordered execution 4**: Piece D's Accept authorizes Scope 1 to
**seek** its restart at its own preflight and at that checkpoint — and only that.

**The confirm-pin-or-re-pin checkpoint is satisfied, by path (a).** Amendment 4 placed that
checkpoint after Piece D's Accept and before any Scope 1 restart, and expressly did not pre-decide
it. Miguel decided it, verbatim:

> Confirmo o pin b91768513fc638381fbde91f0b576b08220a98f6 como snapshot de importação
> histórica. Caminho (a) do amendment 4. A evolução pós-pin do protótipo é tratada como
> importações governadas posteriores sob as decisões já fechadas D4–D9.

The full record is `docs/AGENT-PROMPT-v5-P1-1b-scope1-pin-confirmation.md`, with that session's own
fresh read-only amendment-4 preflight (pin resolves; pin ancestral to live prototype `origin/main`
`3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`; local clone anchored and clean; roster **49/49 cell by
cell, 0 mismatches, 0 resolve failures**, with the O8 `entbnk` substitution blob
`70d418f6023bff68f0d642b4aff26c1ead1298be`; direct pinned `Editor/Data` surface **48/48 direct
blobs, exactly one `Backups` tree, 0 missing, 0 extra**; divergence logged as metadata only).
Those figures are **that session's measurements, quoted here** — **this** authoring session ran no
prototype preflight and touched no prototype repository, and Scope 1 must still run its own fresh
preflight (section 7 items 3–9).

**The standing prompt's Gate is SUPERSEDED — precisely, and only in the part named here.** The
standing prompt's "Gate — before anything else" requires Luís's confirmation that the prototype is
stable and the queued documents are ingested, and then a **new pin** with a fresh blob roster. That
Gate is superseded by Miguel's governed pin confirmation above, on these exact terms:

- **The pin is unchanged: `b91768513fc638381fbde91f0b576b08220a98f6`.** It remains the single
  content-addressed source for every governed Scope 1 read.
- **No new pin is taken.** Path (b) — an O11-class re-pin — was **not** taken, is not authorized,
  and is not available without a new governed Miguel decision; it is never an inference from this
  document. Consequently none of path (b)'s preconditions is triggered: no roster/blob/surface
  re-verification at a new pin, no re-measurement of the five baselines, no C8 (43/43/0/0) or C13
  re-measurement, no DOCTYP manifest re-check, and no re-check of `EF0000053` or any other authored
  code against a changed `permanent_code_ledger.json`.
- **The rest of the Gate stands in full.** The prototype stays **read-only** at that pin for the
  whole assignment — metadata, `git fetch`, `git show`, `git merge-base` only; never checkout, pull,
  merge, or write. Amendment 4's **non-adoption rule is integral**: no file content, count, code,
  mapping, or value from **any** commit after the pin may inform any Sibyla artifact — not a
  migration, not a fixture, not a test, not a validator expectation, not a status record beyond the
  hash-and-subject divergence log of check 6. If any Scope 1 work appears to *need* post-pin
  content, that is a design contradiction: **stop and report.**
- **Nothing else is superseded.** Every fail-closed identity control, every stop-and-report rule,
  the minimal-surface discipline, the proof-pattern annex, and the consolidated-checklist discipline
  remain in force exactly as written.

**Post-pin prototype evolution** is handled as later governed imports under the already-closed
**D4–D9** additive-period-imports decisions. The eventual cutover delta is acknowledged as
inevitable under either path, because the prototype keeps operating until Sibyla replaces it.

## 2 · Scope — what this go-ahead covers, and what it does not

**In scope: Scopes 1–6 of the standing prompt, in that order,** as amended by O8, O9, O10 and the
O10 amendments 2, 3, 4 and 5:

1. **Reference layer import** — ENTMST, ENTALS, ITMMST, ITMALS, ENTITM, ITMCLS, MNGACC, SNCACC,
   COCACC, EXCRAT, DOCTYP rules, DOCEFL rules, DOCFLG instances, `user_observations.json`,
   `reference_only_documents.json`. Permanent codes preserved verbatim; per-field provenance on
   anything not extracted.
2. **2026 history import (D4)** — DOCLOG, FDCHDR, FDCDTL and the governed Layer 5 set, with
   grandfathering derived and persisted at import from each instance's own `DetectedAt` against the
   rule's `EnforcementStartsAt` (never recomputed); D5 `ReferenceOnly` rows carrying no EntryCode;
   the seven comma-joined payroll aggregates through the ordered junction with exact cardinalities
   (**2, 2, 2, 3, 3, 11, 15**); occurrence discriminators preserved; prototype-era quirks flagged,
   never silently normalized.
3. **Validation service over the imported set** — zero failures under the O7 scoping; warning counts
   (synthetic FiscalNo, orphan DOCLOG, and the named data-quality findings) recorded as measured,
   as report content, not blockers.
4. **Re-measure and record** every backlog count at the pin; update the indicative figures. Under
   path (a) this is measurement at the **confirmed** pin `b917685…`, not at a new one.
5. **Render parity** — subject to the declared stop point in section 6.
6. **Overlapping-statement join test** — subject to the declared stop point in section 6.

**Out of scope, behind their own gates:** **Scope 7 (content-hash index swap)** stays behind its own
independent review round — prepared as its own reviewed change on a new migration, the P1-1a
migration untouched, applied only after that review passes. **Scope 8 (BRCode issuance)** stays
behind its own gate and its sequencing under the A3 resolution. Neither is started, prepared,
designed, or partially performed under this go-ahead.

**Scope 9 (records) runs transversally** throughout: `docs/p1-1b-status.md` with a control record
per imported table (**Initial + Expected = Result**), `docs/PROJECT-STATE.md` and
`docs/project-todo.md` kept truthful as work proceeds, clean multi-line commit bodies, no literal
`\n`, and each completed stage pushed. Amendment 5's repair rule binds: every records commit that
changes `p1-1b-status.md` or `p1-1b-o10-independent-review.md` must update `PROJECT-STATE.md` in the
same commit; a records commit that leaves them contradictory is itself a defect.

## 3 · The decided axis — rehearsal first; this go-ahead does not authorize the live pass

Miguel's decided axis for Scope 1 is **rehearsal on an available database first**, ending in an
independent adversarial review with an explicit **Accept/Reject** verdict recorded in the
repository, with the live pass withheld.

**Provenance of this axis, stated exactly.** The rehearsal-first / explicit-Accept-Reject /
live-withheld axis comes from **Miguel's current governed authoring instruction that ordered this
document** — not inferred from a prior record and not a standing authority carried over from one.
It is recorded here **in substance** and is deliberately **not presented as a verbatim quotation**;
no wording in this section is offered as Miguel's exact words. **The pin decision quoted in section
1 remains the only verbatim Miguel quotation in this document.** The axis is also consistent with
the standing prompt's own decision 3 and with every amendment's "no shared/live write before the
complete rehearsal passes" rule, which bind independently of this section.

**On "available database" and the governed isolation semantics.** "Rehearsal on an available
database" is the axis as instructed, and it is used consistently throughout this document. It does
**not** relax the isolation the governing sources require: where those sources specify the
rehearsal target — the standing prompt's decision 3, O8 step 4, O9 step 4, amendment 3, amendment 5
and the Piece D go-ahead — the target is a **disposable PostgreSQL 17 database**, created and
destroyed for the run, with **0 residual containers** afterwards. An available database is one the
rehearsal may create and dispose of for its own use; it is never a shared or live base, and no
write of any kind reaches a shared or live base under this go-ahead.

- **This go-ahead authorizes the rehearsal only.** The complete import — reference layer, history,
  validation, parity, join test — must run green end to end, **subject to the declared stop points
  in section 6**, against a disposable PostgreSQL 17 database before a single write reaches any
  shared or live base.
- **The rehearsal ends at a verdict, not at a claim.** An independent adversarial review is
  mandatory and must record **Accept** or **Reject** explicitly. On **Reject**: stop, record the
  findings, neutralize fail-closed at the branch tip exactly as the piece precedents define, and
  report. On **Accept**: record the verdict and stop, awaiting Miguel.
- **The live pass is withheld.** It requires **both** the rehearsal's recorded Accept **and** a
  later, express, governed Miguel authorization. Neither this document nor the rehearsal's Accept is
  that authorization.
- **When later authorized, the live pass runs exactly as the standing prompt defines it:** a **fresh
  pre-import dump of the live base**, its **SHA-256 recorded** and **`pg_restore --list` verified**,
  stored under the approved `SibylaBackups` hierarchy; then the import against the deployed base;
  then the validation service against live; then the join test's read-only assertions; evidence
  recorded sanitized with its hash. **If any live step diverges from the rehearsal result: stop,
  report, do not improvise a fix on the live base.**
- **Zero writes to any shared or live database before that**, of any kind, for any reason.

## 4 · Baselines, manifests, and fail-closed controls — literal and unchanged

**The five completeness baselines are 119 / 119 / 52 / 221 / 2,787**, plus the **two `Routine` rows
importing verbatim**:

| Named data-quality finding | Expected baseline | Origin |
|---|---:|---|
| `ENTMST.DirectDebit absent` | **119** | O9-D1 |
| `ENTMST.TaxIdVerificationStatus unverified` | **119** | O9-D2 |
| `DOCEFL.ItemClass unassigned` | **52** (O9-D3 qualifier below) | O9-D3 |
| `DOCFLG terminal without ResolutionEvidence` | **221** | O9-D5 |
| `DOCFLG snapshot ItemClass absent` | **2,787** | O10-D1 |
| The two pinned rows using `Routine` | import **verbatim** | O9-D4 |

**The 52 carries O9-D3's own qualifier, restated here in full.** O9-D3's expected initial count for
`DOCEFL.ItemClass unassigned` is **52 — and "the two authored rows count only if their recorded
state is `absent`."** The 52 imported source rows carry `NULL`/`absent`; the authored sentinel
`EF0000000` and the authored Monthly-gap rule `EF0000053` keep their recorded `authored`/`absent`
markers unchanged, and they enter the 52 **only** where that recorded state is `absent`. The
measurement must therefore state the population it counted, not just the number, so that the
qualifier is visibly satisfied rather than assumed.

**Measured deltas are recorded findings, not stops.** A measured data-quality count that differs
from its expected baseline is recorded with its measured value and flagged as a finding; it does not
stop the scope. **Identity-class conflicts stop the scope** — permanent-code conflicts or
reassignment, unknown vocabulary literals, natural-key collisions without a decided tiebreaker,
roster blob drift, an unrostered source surface, or a source row that cannot import without
inventing a permanent code. Under O9-P, a **new** completeness-class gap that no amendment
enumerated and that the corrected schema rejects is reported with its count and its affected rows
are **excluded with an explicit per-table exclusion record**; the import of everything else proceeds.

**DOCEFL manifest — exactly as governed.** The import manifest is exactly
**`EF0000001`–`EF0000052`**, every row with **`Imported = true`** and each field `extracted` from
the rostered blob at the pin; a source field that is absent imports as honest `absent`/`NULL`; a
source field that the accepted schema requires non-null and that cannot be transcribed is a **stop
and report**, never an invention. The authored rows seed alongside and keep their honest NULLs and
their recorded `authored`/`absent` markers: the **sentinel `EF0000000`** unchanged, and the
**Monthly-gap rule `EF0000053`** seeded **inactive behind its governed activation guard** (the
`RequireRunnableActiveDecisionDOCEFL` CHECK and the `ActivateDOCEFLRule` path). A DOCFLG instance
referencing any code **outside `EF0000000`–`EF0000052`** is a stop and report.

**DOCTYP — 19, and the twentieth stays excluded.** The DOCTYP import manifest remains exactly the
**19 transcribed rows**. The twentieth source row (`Bank Statement | External | Exclude`, blank
`DTCode`) is an explicit **C12-style exclusion**, reported with its exclusion citation; it cannot
import without inventing a permanent code. The accepted authored rule
`Bank Statement | External | Include` routed `ArchiveOnly` stands unchanged.

**OFDGAP / `document_gaps.json` stays out**, under **C12**: the gap detector is to be reimplemented,
not a table to import.

**The import fails closed on any unlisted vocabulary literal.** An unknown value is a finding that
stops the scope, never a row to coerce, translate, or default. Closed vocabularies close twice — at
the database and at the validator — for imported and native rows alike.

**C8 — five duplicate ENTBNK pairs: the standing condition, and the current governed fact.** Both
are on the record and both are stated here, because one is a rule and the other is a measurement.

- **The standing fail-closed condition is unchanged and binds the import.** C8's five duplicate
  `(CodeName, Company)` pairs **fail closed knowingly if they are still unmerged at source**. That
  rule is not waived, narrowed, or made conditional by anything below.
- **The condition is not currently triggered.** The source merge was **completed on Luís's behalf**
  under Miguel's 2026-08-06 authorization (`docs/AGENT-PROMPT-v5-P1-1b-c8-amendment.md`), while
  Luís was unavailable, retaining both `Flag` notes per pair, and remains flagged for his review on
  return.
- **The current shape at the confirmed pin, stated without misattribution.** At the confirmed pin
  `b91768513fc638381fbde91f0b576b08220a98f6` the source is **already merged**, so the current
  measured shape is **Initial 43 rows / 43 distinct keys / 0 duplicate groups / 0 rows in duplicate
  groups → Expected change 0 → Result 43 rows / 43 distinct keys / 0 duplicate groups / 0 rows in
  duplicate groups**. The five pairs are therefore not unmerged at source, and C8 passes exactly.
- **The 48 / 5 / 10 → 43/43/0/0 transition is the pre-merge control, and only its pre-merge part
  belongs to the pre-merge pin.** What was measured at the **pre-merge pin**
  `06825b54ec3855a96b5c49b352e2879b11971e39` is the **Initial 48 rows / 43 distinct keys / 5
  duplicate groups / 10 rows in duplicate groups** shape and the merge transition away from it; that
  Initial shape is **not** the shape at the confirmed pin and must never be attributed to it. Its
  **Result 43 rows / 43 distinct keys / 0 duplicate groups / 0 rows in duplicate groups** is the
  post-merge shape and **equals the current shape at the confirmed pin** stated above — the two are
  the same measured shape, not a coincidence of figures. Both records stand, each with its own pin.
- **Drift still fails closed.** If the ENTBNK surface at the confirmed pin is encountered with the
  five pairs still unmerged, or measures anything other than 43/43/0/0 — any duplicate group, any
  changed row count — that is an identity-class finding: **stop and report, never adapt.** Path (a)
  creates **no fresh C8 re-measurement obligation**; the fail-closed rule binds execution regardless
  of whether a measurement is required.
- **ENTBNK is a pinned-source C8 prerequisite and control, not an imported table.** Nothing here
  adds ENTBNK to the standing prompt's imported-table set of item 13, and no ENTBNK import is
  invented. The per-imported-table control record of item 49 therefore does not acquire an ENTBNK
  entry from this section; item 23 separately carries the C8 fail-closed verification.

**C13 — seven residual four-field collisions at the confirmed pin, all passing on `DetectedAt`.**
The standing prompt's wording — "C13's **three** residual FL collisions" — is the older **P1-0-pin**
figure, and it is **not** the figure at the confirmed pin; this document does not repeat it as
current. At `b91768513fc638381fbde91f0b576b08220a98f6` the recorded measurement is **2,787 DOCFLG
source rows; 2,780 distinct four-field `(EFCode, RelatedRecordType, RelatedRecordID,
SourceTextHash)` keys; 7 residual four-field collisions requiring the `DetectedAt` tiebreaker; and
2,787 distinct complete five-field keys with 0 collisions.** All seven **pass on the `DetectedAt`
tiebreaker** and remain visible for Luís's classification — the tiebreaker resolves them, it does
not hide, merge, or normalize them, and the import does not wait on that classification.

This reconciles the divergence between the standing prompt's wording and the current record
**without reopening anything**: C13's complete five-field key rule
`(EFCode, RelatedRecordType, RelatedRecordID, SourceTextHash, DetectedAt)` is unchanged, the
decided rule works exactly as intended at both figures, path (a) triggers **no C13 re-measurement
obligation**, and no decision, baseline, or accepted object is altered by stating the current
figure. The seven remain a Luís-side action, as `docs/PROJECT-STATE.md` already records.

## 5 · Piece D checklist item 5 discharges into Scope 1 — no longer deferred

Miguel decided Piece D's Observation 1 by **option (b)**, in
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-mapping-approval.md` (the Piece D test-plan gate approval,
2026-08-07). **That record's operative sentence is in Portuguese; the English below is a summary of
its effect, not a quotation of it** — no wording here is offered as Miguel's exact words, and the
pin decision in section 1 remains this document's only verbatim Miguel quotation. As summarized
here: checklist item 5 was formally carved out of Piece D's Accept scope; Piece D authored **no**
synthetic population imitating the five baselines (option (a) was rejected by name, precisely so
that Piece D's Accept could not imply a false confirmation using numbers chosen to match rather
than measured); Piece D claimed no confirmation of the real governed population and recorded **no
test** for item 5; and the confirmation of the real population of the five baselines and the two
`Routine` rows was **deferred to Scope 1**, with item 5 recorded as deferred, not skipped. The
eight-item Piece D checklist was closed in full by that same amendment.

**That obligation now attaches here and is no longer deferred.** Scope 1 must prove the **real
population** of the five baselines — 119 / 119 / 52 / 221 / 2,787, plus both `Routine` rows verbatim
— by **real measurement against the imported governed population**, with population/scope assertions
alongside the counts so that a matching count cannot be vacuous, sampled, or satisfied by a
synthetic fixture. Piece D's own framing of the required shape carries over: measured in the import
run itself, not stitched together from separate unrelated tests, and never asserted from a fixture
authored to match a number.

## 6 · Anticipated stop points — Miguel's decision, declared in advance, never improvised

Two stop points are foreseen. They are declared here so that meeting them is an execution of this
go-ahead, not an improvisation; and neither may be silently skipped, silently satisfied, or
resolved by judgment call.

**Stop point A — Scope 5, render parity.** The acceptance criterion says the seeded base reproduces
the FDR sheets through the **P1-12 renderer**, and **P1-12 does not exist**. The permitted
dispositions are exactly two, and no third:

- **(A1)** implement the **minimal read-only export path** sufficient to prove parity on the
  imported set — read-only, minimal-surface, no accepted object altered, no P1-2 work, its own
  tests; or
- **(A2)** **stop and report** with a **written deferral proposal for Miguel**.

Silently skipping parity is forbidden, and claiming parity untested is forbidden.

**Stop point B — Scope 6, the overlapping bank-statement join test.** Re-ingest an overlapping bank
statement and prove: every generated document re-anchors, **zero duplicates**, the seven aggregates
resolve, and **`UNIQUE (Company, BMCode)`** holds. Where the surface required to run that test does
not exist, or where any assertion cannot be proven honestly on the imported set, the disposition is
**stop and report** with the exact blocking evidence and a proposed resolution for Miguel's
decision — never a silent skip, never an adapted assertion, never a claimed pass.

Both stop points are reported as numbered observations with a proposed resolution, exactly as
Pieces A, B, C and D did; observations are never resolved silently.

## 7 · The Scope 1 consolidated checklist — one numbered, exhaustive list

Amendment 5 requires **one numbered, exhaustive checklist merging every applicable requirement from
every standing amendment**, and requires that **the implementer's evidence map and the reviewer's
disposition both key to that checklist and to nothing else.** This section is that checklist for
Scope 1. It merges the ordered Scopes 1–6, the baselines, manifests, exclusions and fail-closed
controls of section 4, Piece D checklist item 5 as discharged by section 5, both stop points of
section 6, Scope 1's **own fresh** amendment-4 preflight checks 1–6, the process/TDD/control-record/
review/live-stop obligations, and the "Report at the end" fields of section 11.

**Binding properties of this list.**

- **The evidence map and the reviewer's disposition key to this numbered list and to nothing else.**
  Every item — and every lettered sub-point — is dispositioned explicitly; a silent omission is a
  defect in itself.
- **A standing requirement found absent from this list is a stop-and-report**, never silently
  satisfied and never silently skipped. It is reported as a numbered Observation with a proposed
  resolution, and the list is amended by Miguel's decision, not by the implementer's judgment.
- **This list restates; it does not amend.** Where an item compresses a governing source, the source
  governs. No item here relaxes, widens, or reinterprets any decision, baseline, manifest, or
  fail-closed control, and nothing here is an authorization: the gates of section 8 and the
  non-authorizations of section 10 bind every item.
- **Nothing here is claimed as done.** Every item is an obligation on the sessions that execute
  Scope 1 after governed acceptance and the test-plan gate.

### Part A — Gates, preflight, and source discipline

1. **Governed records acceptance, pushed first.** This go-ahead is tracked and its acceptance
   recorded in `docs/p1-1b-status.md` **and** `docs/PROJECT-STATE.md` in the **same records commit**,
   committed and pushed **before any Scope 1 work of any kind** — before the test-plan gate, before
   any preflight, before any code, container, database, or importer action.
2. **Test-plan gate passed.** The checklist→test mapping required by section 8 step 2 is recorded,
   committed, pushed, and **explicitly approved by Miguel**, with every ambiguity, contract
   collision, or infeasibility reported as a numbered Observation with a proposed resolution. No
   code, test, helper, migration, script, container, database, or importer run precedes that
   approval.
3. **Preflight check 1 — pin reachable.** `b91768513fc638381fbde91f0b576b08220a98f6` resolves in the
   local prototype clone **and** in the fetched remote. Failure: **stop and report.**
4. **Preflight check 2 — no history rewrite.** The pin is an **ancestor** of live
   `refs/heads/main` (`git merge-base --is-ancestor`). Failure is a **hard stop**.
5. **Preflight check 3 — local clone anchored.** Local `HEAD` still equals the pin and the working
   tree is clean. A moved `HEAD` is a **hard stop**.
6. **Preflight check 4 — roster integrity at the pin.** The effective governed roster measures
   **49/49 blobs resolving to their recorded hashes, cell by cell, 0 mismatches, 0 resolve
   failures**, including the O8 `entbnk` substitution blob
   `70d418f6023bff68f0d642b4aff26c1ead1298be`. Failure: **stop and report, never adapt.**
7. **Preflight check 5 — surface integrity at the pin.** The direct pinned `Editor/Data` surface is
   exactly the rostered set: **48/48 direct blobs, exactly one `Backups` tree, 0 missing, 0 extra**.
   Failure: **stop and report, never adapt.**
8. **Preflight check 6 — divergence recorded as a finding, not a stop.** Record the live prototype
   tip SHA and the **hash and subject only** of every post-pin commit, with the explicit statement
   that **no post-pin content was read or adopted**. Then proceed.
9. **The preflight is this session's own, run fresh.** Adoption of another session's preflight is
   **inadmissible** — finding **D-A2-L1**, recorded and **not waived**. The records checkpoint
   preflight in `docs/AGENT-PROMPT-v5-P1-1b-scope1-pin-confirmation.md` does **not** discharge,
   pre-run, or substitute for it.
10. **Prototype read-only for the whole assignment.** Metadata, `git fetch`, `git show`,
    `git merge-base` only — never checkout, pull, merge, or write, at any point, for any reason.
11. **Non-adoption rule.** No file content, count, code, mapping, or value from **any** commit after
    the pin informs any Sibyla artifact — not a migration, fixture, test, validator expectation, or
    status record beyond item 8's hash-and-subject divergence log. Work that appears to *need*
    post-pin content is a design contradiction: **stop and report.**
12. **Every governed read is content-addressed at the confirmed pin.** No new pin is taken; path (b)
    is unavailable without a new governed Miguel decision.

### Part B — Scope 1: reference layer import

13. **The reference-layer set imports in full:** ENTMST, ENTALS, ITMMST, ITMALS, ENTITM, ITMCLS,
    MNGACC, SNCACC, COCACC, EXCRAT, DOCTYP rules, DOCEFL rules, DOCFLG instances,
    `user_observations.json`, `reference_only_documents.json`.
14. **Permanent codes preserved verbatim**, never reassigned, renumbered, or invented.
15. **Per-field provenance on anything not `extracted`**, with each imported field `extracted` from
    the rostered blob at the pin.
16. **Absence imports as absence.** A source field that is absent imports as honest `absent`/`NULL`
    — never an empty string, a sentinel, a default, a translation, or a backfill. A source field
    that the accepted schema requires non-null and that cannot be transcribed is a **stop and
    report**, never an invention.
17. **DOCEFL import manifest is exactly `EF0000001`–`EF0000052`**, every row with
    **`Imported = true`**, each field `extracted` from the rostered blob at the pin.
18. **The authored DOCEFL rows seed alongside**, keeping their honest NULLs and their recorded
    `authored`/`absent` markers: the **sentinel `EF0000000`** unchanged, and the **Monthly-gap rule
    `EF0000053`** seeded **inactive behind its governed activation guard** — the
    `RequireRunnableActiveDecisionDOCEFL` CHECK and the `ActivateDOCEFLRule` path.
19. **A DOCFLG instance referencing any code outside `EF0000000`–`EF0000052` is a stop and report.**
20. **DOCTYP import manifest is exactly the 19 transcribed rows.**
21. **The twentieth DOCTYP source row is an explicit C12-style exclusion** — `Bank Statement |
    External | Exclude`, blank `DTCode` — reported with its exclusion citation; it cannot import
    without inventing a permanent code. The accepted authored rule `Bank Statement | External |
    Include` routed `ArchiveOnly` stands unchanged.
22. **OFDGAP / `document_gaps.json` stays out**, under C12: the gap detector is to be reimplemented,
    not a table to import.
23. **C8 — the standing fail-closed control/test, not a fresh import-table control record.** The
    fail-closed condition holds unchanged: the five duplicate ENTBNK `(CodeName, Company)` pairs
    fail closed knowingly if still unmerged at source. At the confirmed pin the source is already
    merged and the current shape is **43 rows / 43 distinct keys / 0 duplicate groups / 0 rows in
    duplicate groups** (Initial 43/43/0/0 → Expected change 0 → Result 43/43/0/0); the older
    **48 / 5 / 10 → 43/43/0/0** transition is the **pre-merge** control at
    `06825b54ec3855a96b5c49b352e2879b11971e39` and is never attributed to the confirmed pin. Path
    (a) creates **no fresh C8 re-measurement obligation**; what this item requires is the
    fail-closed control/test — if execution encounters the five pairs still unmerged, or any
    duplicate drift or changed row count, that is an identity-class **stop and report, never
    adapt**. **ENTBNK is a pinned-source C8 prerequisite and control, not an imported table**: this
    item adds no ENTBNK entry to item 13's imported set and no ENTBNK control record to item 49.
24. **C13 — the complete five-field key rule is enforced unchanged**
    `(EFCode, RelatedRecordType, RelatedRecordID, SourceTextHash, DetectedAt)`, and the DOCFLG
    control record measures **2,787 source rows; 2,780 distinct four-field keys; 7 residual
    four-field collisions resolved by `DetectedAt`; 2,787 distinct complete keys / 0 collisions**.
    All residuals stay visible; none is hidden, merged, or normalized.
25. **The import fails closed on any unlisted vocabulary literal.** An unknown value is a finding
    that **stops the scope** — never a row to coerce, translate, or default.
26. **Closed vocabularies close twice** — at the database **and** at the validator — for imported
    and native rows alike, with unknown-value fail-closed coverage on both.
27. **The identity class stops the scope:** permanent-code conflicts or reassignment, unknown
    vocabulary literals, natural-key collisions without a decided tiebreaker, roster blob drift, an
    unrostered source surface, or a source row that cannot import without inventing a permanent
    code.
28. **The completeness class imports and is measured**, per O9-P; and a **new** completeness-class
    gap that no amendment enumerated and that the corrected schema rejects is reported with its
    count, its affected rows **excluded with an explicit per-table exclusion record**, and the
    import of everything else proceeds.

### Part C — Scope 2: 2026 history import (D4)

29. **DOCLOG, FDCHDR, FDCDTL and the governed Layer 5 set import** under D4.
30. **Grandfathering is derived and persisted at import** from each instance's own `DetectedAt`
    against the rule's `EnforcementStartsAt` — **never recomputed** afterwards.
31. **D5 `ReferenceOnly` rows carry no EntryCode.**
32. **The seven comma-joined payroll aggregates resolve through the ordered junction with exact
    cardinalities 2, 2, 2, 3, 3, 11, 15.**
33. **Occurrence discriminators are preserved.**
34. **Prototype-era quirks are flagged, never silently normalized.**

### Part D — Scope 3: validation over the imported set

35. **Validator failures are zero** under the O7 scoping.
36. **Warning counts are recorded as measured** — synthetic FiscalNo, orphan DOCLOG, and the named
    data-quality findings — as **report content, not blockers**.
37. **O7's scoping holds:** an imported historical row with NULL `CaptureQuality` is not a finding;
    a Sibyla-era row without it is.

### Part E — The five baselines and the real-population proof (Piece D item 5)

38. **The five completeness baselines are measured against the real imported governed population:**
    **119** (`ENTMST.DirectDebit absent`, O9-D1), **119** (`ENTMST.TaxIdVerificationStatus
    unverified`, O9-D2), **52** (`DOCEFL.ItemClass unassigned`, O9-D3 — **the two authored rows
    count only if their recorded state is `absent`**), **221** (`DOCFLG terminal without
    ResolutionEvidence`, O9-D5), **2,787** (`DOCFLG snapshot ItemClass absent`, O10-D1).
39. **The two pinned `Routine` rows import verbatim**, under the six-literal `ReviewPriority`
    vocabulary (O9-D4).
40. **The proof shape is Piece D's, carried over:** measured **in the import run itself**, not
    stitched together from separate unrelated tests or runs, with **population/scope assertions
    alongside the counts** so a matching count cannot be vacuous, sampled, or satisfied by a
    synthetic fixture — and **never** asserted from a fixture authored to match a number.
41. **A measured delta from a baseline is a recorded finding, not a stop** — recorded with its
    measured value and flagged.

### Part F — Scope 4: re-measurement

42. **Every backlog count is re-measured and recorded at the confirmed pin `b917685…`**, and the
    indicative figures are updated to the measured values, marked as measured at the confirmed pin
    and not at a new one.

### Part G — Scopes 5 and 6: the two declared stop points

43. **Stop point A — Scope 5, render parity.** Exactly two permitted dispositions and no third:
    **(A1)** the **minimal read-only export path** sufficient to prove parity on the imported set —
    read-only, minimal-surface, no accepted object altered, no P1-2 work, its own tests — with its
    measured parity result; or **(A2)** **stop and report** with a **written deferral proposal for
    Miguel**. Silently skipping parity is forbidden; claiming parity untested is forbidden.
44. **Stop point B — Scope 6, the overlapping bank-statement join test.** Re-ingest an overlapping
    bank statement and prove: every generated document **re-anchors**, **zero duplicates**, the
    seven aggregates **resolve**, and **`UNIQUE (Company, BMCode)`** holds. Where the required
    surface does not exist, or any assertion cannot be proven honestly on the imported set: **stop
    and report** with the exact blocking evidence and a proposed resolution — never a silent skip,
    never an adapted assertion, never a claimed pass.
45. **Both stop points are reported as numbered Observations with a proposed resolution**, exactly
    as Pieces A, B, C and D did; observations are never resolved silently.

### Part H — Scopes 7 and 8: explicitly out of scope

46. **Scope 7 (content-hash index swap) is not started, prepared, designed, or partially
    performed**, and is reported as not started with its gate named.
47. **Scope 8 (BRCode issuance) is not started, prepared, designed, or partially performed**, and is
    reported as not started with its gate named.

### Part I — Process, proof discipline, records, and topology (Scope 9)

48. **TDD where applicable**, from the pushed approval tip.
49. **One control record per imported table in the form `Initial + Expected = Result`**, counts at
    the confirmed pin, plus **every per-table exclusion record** raised under O9-P. The imported set
    is item 13's, unchanged; **ENTBNK is not among it** — it is a pinned-source C8 prerequisite and
    control carried by item 23, and this item creates no ENTBNK control record and no ENTBNK import.
50. **Claims equal assertions.** No status wording may exceed what a proof asserts; an overstated
    claim is a defect even where the code is correct.
51. **The proof-pattern annex binds** wherever Scope 1 adds or alters a surface: cross-company
    negative tests for every company-scoped object, predicate, or exemption; EF-versus-catalog
    store-type parity for every column added or altered; "unchanged" asserted by direct catalog
    comparison, never assumed; vocabularies closed twice.
52. **Minimal-surface discipline.** No accepted object is altered, dropped, re-owned, or replaced —
    the accepted P1-1a migration and every accepted Piece A/B/C/D object remain immutable. An
    apparent need to touch one is a **stop-and-report**, never a judgment call.
53. **Verification envelope:** build **0 warnings / 0 errors** on a clean rebuild; the ordinary,
    focused and disposable suites green; **0 residual containers**; `git diff --check` clean; exact
    changed-path/claim equality between the diff and the status record, item for item.
54. **Records run transversally:** `docs/p1-1b-status.md` (control record per imported table),
    `docs/PROJECT-STATE.md` and `docs/project-todo.md` kept truthful as work proceeds; clean
    multi-line commit bodies; **no literal `\n`**; each completed stage pushed.
55. **Amendment 5's repair rule binds:** every records commit that changes `p1-1b-status.md` or
    `p1-1b-o10-independent-review.md` **must update `PROJECT-STATE.md` in the same commit**; a
    records commit that leaves them contradictory is itself a defect.
56. **`docs/PROJECT-STATE.md`, `docs/p1-1b-status.md` and `docs/p1-1b-o10-independent-review.md` are
    mutually consistent**, confirmed explicitly.
57. **Work topology:** all Scope 1 work on **`feature/p1-1b-scope1`**, created from `origin/main`;
    no other branch carries Scope 1 work; publication for review by **merge request into `main`**;
    **ordinary merges only** — no rebase, squash, amend, reset, revert, cherry-pick, or force push,
    in either repository.
58. **MR-flow preflight, corrected form:** before synchronization local `main` must be an
    **ancestor** of `origin/main`, **zero commits ahead**, and **fast-forwardable**; a 0/0
    divergence is **not** required before synchronization and **is** required **after** the
    fast-forward completes.
59. **Binding forward rule 1:** a session that records it did not exercise an authority must not then
    exercise it without **first recording** that it has moved to exercise it.
60. **Binding forward rule 2:** **no Git topology is published, by direct push or MR, before the
    record describing it is committed and pushed.**

### Part J — The rehearsal's verdict and the live stop

61. **The rehearsal runs the complete ordered Scopes 1–6 end to end, subject to the declared stop
    points in section 6**, on an available database — a **disposable PostgreSQL 17** database under
    the governed isolation semantics of section 3 — with **zero writes to any shared or live
    database**, of any kind, for any reason.
62. **An independent adversarial review of the rehearsal is mandatory** and records an explicit
    **Accept** or **Reject** verdict in the repository. On **Reject**: stop, record the findings,
    **neutralize fail-closed at the branch tip** exactly as the piece precedents define, and report.
    On **Accept**: record the verdict and **stop**, awaiting Miguel.
63. **The live pass is withheld** and requires **both** the rehearsal's recorded Accept **and** a
    later, express, governed Miguel authorization. Neither this document nor the rehearsal's Accept
    is that authorization.
64. **When later authorized, the live pass runs exactly as the standing prompt defines it:** a
    **fresh pre-import dump of the live base**, **SHA-256 recorded**, **`pg_restore --list`
    verified**, stored under the approved `SibylaBackups` hierarchy; then the import against the
    deployed base; then the validation service against live; then the join test's read-only
    assertions; evidence recorded sanitized with its hash. **Any live step diverging from the
    rehearsal result: stop, report, do not improvise a fix on the live base.**

### Part K — Report at the end (fields, reproduced as checklist items)

65. **Every field of section 11 is reported, none dropped**, with out-of-scope fields reported as
    such and their holding gate named:
    - **(a)** commit hashes per stage;
    - **(b)** the pin and blob SHAs — **no new pin**; the confirmed pin plus Scope 1's **own fresh**
      roster (49/49 cell by cell) and direct surface (48/48 plus the `Backups` tree), with the
      check-6 divergence log by hash and subject only;
    - **(c)** per-table imported counts vs expected, as `Initial + Expected = Result`, plus every
      O9-P per-table exclusion record;
    - **(d)** validator results — failures zero; warnings as measured, including the data-quality
      register expected vs measured for 119 / 119 / 52 / 221 / 2,787 and the two `Routine` rows,
      every delta flagged;
    - **(e)** parity outcome or deferral (A1 or A2) — never "skipped", never claimed untested;
    - **(f)** join-test numbers, or the stop record with blocking evidence and a proposed
      resolution;
    - **(g)** hash-swap review reference — out of scope, gate named, nothing fabricated;
    - **(h)** BRCode issuance counts — out of scope, gate named, nothing fabricated;
    - **(i)** dump hashes — not applicable to the rehearsal, none taken and none claimed; required
      only for the separately authorized live pass;
    - **(j)** the exact list of what still separates the project from P1-1 acceptance, item by item;
    - **(k)** the amendment-carried additional fields: the data-quality register with any exclusion
      records; the **evidence map keyed item by item to this numbered checklist and to nothing
      else**; the **independent rehearsal review verdict in full** with its Critical/High/Medium/Low
      disposition; build, test and container evidence including 0 residual containers; and the
      mutual-consistency confirmation of item 56.
66. **Rehearsal and live are reported distinctly.** Every measured figure is labelled rehearsal or
    live; a rehearsal figure is never presented as a live result; no live field is populated before
    the live pass is separately authorized and performed. The report also states the gates passed
    and outstanding, every stop point reached and its disposition, and the standing statement of
    what remains unauthorized.

### Part L — Conflict, silence, and PROJECT-STATE precedence

67. **A conflict or a silence between sources is a stop-and-report.** Where the standing prompt, any
    amendment, this go-ahead, or any other governing source conflict with one another, or are silent
    on a point the work needs, **stop and report**. No gap is filled by interpretation, by preferring
    the more recent document, or by choosing the reading that lets work continue.
68. **A `docs/PROJECT-STATE.md` contradiction is a stop-and-report for Miguel, never silently
    resolved.** If `PROJECT-STATE.md` contradicts the standing prompt, any amendment, or this
    go-ahead, **stop and report the contradiction** for Miguel's decision. By that file's own
    precedence rule it is the repository's authoritative state; a contradiction is a governed
    discrepancy to be decided, never something to work around, to repair silently in passing, or to
    resolve by the implementer's judgment.

## 8 · Ordered execution — the gates, in order

1. **Governed records acceptance of this go-ahead.** Track this document and record its acceptance
   in `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` in the **same records commit**, **pushed
   before any Scope 1 work begins** — before the test-plan gate, before any preflight, before any
   code, container, database, or importer action. **This document only authors the go-ahead; it does
   not perform that records step.**

2. **Test-plan gate — mandatory, and it stops.** After the governed records acceptance and **before
   any implementation or execution of any kind**, record in `docs/p1-1b-status.md` a numbered
   mapping of **every item and every lettered sub-point of the section 7 consolidated checklist —
   items 1 through 68, without exception** — to the **exact test method(s) and exact verification
   commands** that will prove it, labelled **New**, **Strengthened**, or **Existing regression**,
   and by surface. The mapping is keyed to that checklist and to nothing else; an item that no test
   or command can prove is reported as an Observation, not left unmapped and not quietly folded into
   a neighbouring item. **Adversarially assess feasibility
   before requesting approval**, and report every ambiguity, contract collision, or infeasibility as
   a numbered **Observation with a proposed resolution** — never resolved silently. Then **commit,
   push, and STOP for Miguel's explicit approval.** No code, test, helper, migration, script,
   container, database, or importer run precedes that approval. Per amendment 5, a standing
   requirement found absent from the checklist is a **stop-and-report**, never silently satisfied
   and never silently skipped.

3. **Only after that approval: Scope 1's own fresh execution preflight, then the rehearsal.**
   - **The preflight is this session's own, run fresh.** Amendment 4's reformulated prototype
     preflight, read-only: (1) the pin resolves locally and in the fetched remote; (2) the pin is an
     ancestor of live `refs/heads/main` — failure is a hard stop; (3) the local clone is anchored,
     local `HEAD` equals the pin — a moved `HEAD` is a hard stop; (4) roster integrity at the pin,
     **49/49** blobs resolving to their recorded hashes, measured cell by cell; (5) surface
     integrity at the pin, the direct `Editor/Data` surface exactly the **48** rostered files. Any
     of checks 1–5 failing is **stop and report, never adapt**. Check (6) records divergence as a
     **finding, not a stop**: the live tip SHA and the hash and subject of every post-pin commit,
     with the explicit statement that no post-pin content was read or adopted.
   - **Adoption of another session's preflight is inadmissible** — finding **D-A2-L1**, recorded and
     **not waived**. The records checkpoint preflight in
     `docs/AGENT-PROMPT-v5-P1-1b-scope1-pin-confirmation.md` does **not** discharge, pre-run, or
     substitute for this one.
   - **Then the rehearsal, on an available database.** The complete ordered Scopes 1–6 run end to
     end, **subject to the declared stop points in section 6**, against a disposable PostgreSQL 17
     database under the governed isolation semantics of section 3, **TDD where applicable**, with a
     **control record per imported table in the form `Initial + Expected = Result`**, counts at the
     confirmed pin. Honest NULLs; identity class fails closed; completeness class imports and is
     measured; 0 residual containers; build 0 warnings / 0 errors; ordinary, focused and disposable
     suites green. Claims equal assertions: no status wording may exceed what a proof asserts. The
     evidence map keys item by item to the section 7 consolidated checklist and to nothing else.

4. **Independent adversarial review of the rehearsal.** A fresh independent adversarial review round
   with an explicit **Accept/Reject** verdict recorded in the repository, its disposition keyed item
   by item to the section 7 consolidated checklist and to nothing else. On **Reject**: neutralize
   fail-closed at the branch tip, record the findings, stop and report. On **Accept**: record the
   verdict.

5. **STOP, awaiting Miguel's express authorization for the live pass.** The rehearsal's Accept does
   not start the live pass and is not the live authorization. Nothing touches a shared or live
   database until Miguel's later governed authorization exists **and** the fresh, verified pre-import
   dump of section 3 exists.

## 9 · Work topology and the binding forward rules

- **All Scope 1 work lives on `feature/p1-1b-scope1`**, created from `origin/main`. No other branch
  carries Scope 1 work.
- **Push at every stage.** Nothing stays unpublished: each governed records commit, the test-plan
  mapping, the preflight and rehearsal evidence, and the review verdict are committed and pushed as
  they complete.
- **MR into `main` at the gates.** Publication for review happens by merge request into `main`.
- **Binding forward rule 1.** A session that records it did not exercise an authority must not then
  exercise it without **first recording** that it has moved to exercise it.
- **Binding forward rule 2.** **No Git topology is published, by direct push or MR, before the
  record describing it is committed and pushed.**
- **MR-flow preflight, corrected form.** Before synchronization, local `main` must be an **ancestor**
  of `origin/main`, **zero commits ahead**, and **fast-forwardable**. A 0/0 divergence is **not**
  required before synchronization; it **is** required **after** the fast-forward completes.
- **Ordinary merges only** — no rebase, squash, amend, reset, revert, cherry-pick, or force push, in
  either repository.

**`feature/p1-1b` is absent from the server after its merge, as expected. This is not a failure.**
Its **server-side absence is this authoring session's own read-only Git observation** — a live
`git ls-remote` check against the GOTT.Sibyla remote in this session, in the same category as the
ancestry and content-equality observations below, and not quoted from any record.
`80646b9acbe36d8c351998076d6269a38e467b71` — the accepted feature tip and second parent of the
adopted merge `fc205facf8c2e9728a9404832cead1a16f0e593d`, published to `main` through the
server-side merge `c277b16abffac3ba18833e811a67641e81fdf58a` — **is an ancestor of `origin/main`**,
and **all of its content is published**: the ancestry check passes and the content comparison
between `c277b16` and `80646b9` is empty. A deleted post-merge branch ref removes no history and
loses no content; the branch's absence is the expected end state of a completed merge, not drift
and not a gap in publication.

**Provenance of the absence, ancestry and content statements — measured here, not quoted.** These
three facts were **observed in this authoring session's own read-only Git prerequisite step** — the
fetch, the live feature-ref absence check, and the ancestry/content proofs described in section 12 —
against the GOTT.Sibyla remote and its fetched `origin/main`. After the fetch this session observed,
live: **`feature/p1-1b` absent on the server**; **`80646b9acbe36d8c351998076d6269a38e467b71` an
ancestor of `origin/main`**; and **`git diff c277b16..80646b9` empty (0 bytes)**. They are **not**
quoted from the records listed in "Follows", and this document does not present them as if they
were: the sources record the merge adoption, while the current absence, ancestry and
content-equality observations are this session's own. This is the single category of measured figure
in this document, and it is labelled as such wherever it appears.

## 10 · What this go-ahead does not authorize

- **The live pass**, or any write to any shared or live database, in any form, before the rehearsal
  Accept **and** Miguel's later express authorization **and** the fresh verified pre-import dump.
- **Scope 7** (content-hash index swap) and **Scope 8** (BRCode issuance) — both stay behind their
  own gates.
- **P1-2 work of any kind**, and **O5 work of any kind** (O5 remains the project's other open item;
  no production go-live claim).
- **Any prototype write**, and any reading or adoption of **post-pin** prototype content beyond the
  check-6 hash-and-subject divergence log.
- **Re-pinning**, now or by implication; path (b) requires a new governed Miguel decision.
- **Any change to a closed decision, a baseline, a manifest, or an accepted object** — O7, O8-D1/D2,
  O9-P, O9-D1…D5, O10-D1/D2 and D4–D9 remain closed and govern unchanged; the accepted P1-1a
  migration and every accepted Piece A/B/C/D object remain immutable; no P1-0 draft is edited beyond
  governed records corrections already authorized elsewhere.
- **History rewrite** in either repository.
- **Any project-evolution-page update.**
- **Resurrecting or cherry-picking**, in whole or in part, `b324a3e…`, `57f0f023…`, `7ea6c0f…`,
  `6f86023d…`, `b8fa033…`, or `bf5926e…` — all remain neutralized evidence only.
- **Any implementation or execution of any kind** — test, harness, helper, script, importer,
  container, database, or preflight — before Miguel's explicit approval of the checklist→test
  mapping at the test-plan gate.
- **Inventing any data value.** No value of any kind may be invented, guessed, defaulted,
  translated, coerced, backfilled, or chosen to match an expected figure. **Every value is either
  `extracted` from the confirmed pin `b91768513fc638381fbde91f0b576b08220a98f6` or honestly
  `NULL`/`absent`**, with per-field provenance on anything not extracted. A value the accepted schema
  requires and that cannot be transcribed from the pin is a **stop and report**, never an invention —
  as are a permanent code, a `DTCode`, an unlisted vocabulary literal, a count, and a fixture figure.
  Where the sources conflict on a value, or are silent on one the work needs, **the work stops** and
  reports it; it does not proceed on an interpreted value.
- **Merging the MR that publishes this document.** This go-ahead authorizes **only its own
  publication for review** via branch and merge request; the merge decision is Miguel's. That
  publication authority comes from **Miguel's current governed authoring instruction that ordered
  this document** — recorded here **in substance and not as a verbatim quotation**, exactly as
  section 3 records the rehearsal-first axis; the pin decision quoted in section 1 remains this
  document's only verbatim Miguel quotation.
- **Resolving a conflict or a silence between sources.** The standing prompt's rule binds
  unchanged: **if sources conflict or are silent, stop and report.** No gap is filled by
  interpretation, by preferring the more recent document, or by choosing the reading that lets work
  continue.
- **Proceeding against `docs/PROJECT-STATE.md`.** If `PROJECT-STATE.md` contradicts the standing
  prompt, any amendment, or this go-ahead, **stop and report the contradiction.** By that file's
  own precedence rule it is the repository's authoritative state; a contradiction is a governed
  discrepancy for Miguel to decide, never something to work around or to repair silently in
  passing.

## 11 · Report at the end

The standing prompt's "Report at the end" is reproduced field for field and adapted to the
rehearsal-first axis. **No field is dropped**; a field that is out of scope is reported as such,
naming the gate that holds it.

| # | Field (standing prompt) | How it is reported for Scope 1 |
|---:|---|---|
| 1 | **Commit hashes per stage** | Governed-acceptance commit; test-plan mapping commit; approval record; preflight/rehearsal evidence commits; the review-verdict commit. Rehearsal and live stages are reported as separate, explicitly labelled sets. |
| 2 | **The new pin and blob SHAs** | **No new pin is taken.** Report the confirmed pin `b91768513fc638381fbde91f0b576b08220a98f6` and, from Scope 1's **own fresh** preflight, the measured roster (49/49, cell by cell, mismatches and resolve failures) and direct surface (48/48 plus the `Backups` tree), with the check-6 divergence log by hash and subject only. |
| 3 | **Per-table imported counts vs expected** | One control record per imported table in the form **Initial + Expected = Result**, at the confirmed pin, plus every per-table exclusion record raised under O9-P. |
| 4 | **Validator results** | Failures must be **zero**; warnings as measured, including the synthetic-FiscalNo and orphan-DOCLOG counts and the named data-quality register — expected vs measured for 119 / 119 / 52 / 221 / 2,787 and the two `Routine` rows — with every delta flagged as a finding. |
| 5 | **Parity outcome or deferral** | Either the minimal read-only export path's measured parity result on the imported set (A1), or the written deferral proposal and the stop (A2). Never "skipped"; never claimed untested. |
| 6 | **Join-test numbers** | Re-anchored documents, duplicate count (expected **zero**), the seven aggregates resolved with their exact cardinalities, and the `UNIQUE (Company, BMCode)` assertion — or the stop record with blocking evidence and a proposed resolution. |
| 7 | **Hash-swap review reference** | **Out of scope under this go-ahead — Scope 7 is behind its own independent review gate.** Reported as not started, with the gate named; no reference is fabricated. |
| 8 | **BRCode issuance counts** | **Out of scope under this go-ahead — Scope 8 is behind its own gate.** Reported as not started, with the gate named; no counts are fabricated. |
| 9 | **Dump hashes** | **Not applicable to the rehearsal — no dump is taken and none is claimed.** Required and reported only for the later, separately authorized live pass: the fresh pre-import dump's **SHA-256** and its **`pg_restore --list`** verification, under the approved `SibylaBackups` hierarchy. |
| 10 | **The exact list of what still separates the project from P1-1 acceptance** | Reported in full and item by item. |

**Additional fields required by the amendments, carried in the same report:** the data-quality
register with expected vs measured counts and any O9-P per-table exclusion records (amendments 1 and
2); the evidence map keyed item by item to the **section 7 consolidated checklist** — and, through
it, to the approved test-plan mapping — and to nothing else (amendment 5); the reviewer's
disposition keyed to that same numbered checklist; the **independent rehearsal review verdict in
full**, with its Critical/High/Medium/
Low disposition; build, test and container evidence including 0 residual containers; and explicit
confirmation that `docs/PROJECT-STATE.md`, `docs/p1-1b-status.md` and
`docs/p1-1b-o10-independent-review.md` are **mutually consistent**.

**Rehearsal and live are reported distinctly.** Every measured figure is labelled as rehearsal or
live; a rehearsal figure is never presented as a live result, and no live field is populated before
the live pass is separately authorized and performed. The report also states, explicitly: the gates
passed and the gates outstanding; every stop point reached and its disposition; and the standing
statement of what remains unauthorized.

## 12 · What this session did — stated exactly

- **This document is authorization and gate specification only.** It stops, by design, before the
  governed-acceptance records step and before the test-plan gate.
- **No execution evidence exists under this go-ahead, and none is claimed.** In this session there
  was **no** acceptance record, **no** build, **no** test, **no** database, **no** container, **no**
  importer or import, **no execution preflight** — and no prototype preflight of any kind — and
  **no** live work. Except for the **feature-ref absence, ancestry and content observations**
  explicitly labelled as this session's own in section 9, no figure in this document is presented as
  measured by this session; every other figure cited is quoted from the governing records named in
  "Follows".
- **The Git work this session did perform, stated in full — the ordered prerequisite, and nothing
  beyond it.** This session's Git work was **the disclosed local `main` fast-forward
  synchronization, read-only remote/ancestry/content observations, and one local branch creation**:
  no commit, no push, no merge request, no merge, no rewrite. Under the MR-flow rule and binding
  forward rule 2, this session:
  1. **fetched and synchronized local `main`** with `origin/main`, **fast-forward only**, under the
     corrected MR-flow preflight of section 9 — local `main` an ancestor of `origin/main`, zero
     commits ahead, fast-forwardable before the synchronization, and 0/0 divergence after it;
  2. **ran a live read-only `git ls-remote` feature-ref absence check** and observed, after the
     fetch, that **`feature/p1-1b` is absent on the server**;
  3. **ran the required read-only ancestry and merge/content proofs** that section 9 records — that
     `80646b9acbe36d8c351998076d6269a38e467b71` is an ancestor of `origin/main`, and that the
     content comparison `c277b16abffac3ba18833e811a67641e81fdf58a..80646b9` is **empty (0 bytes)**;
     and
  4. **created `feature/p1-1b-scope1` locally from `origin/main`**, as section 9's topology
     requires.

  These are the ordered prerequisite to authoring on the correct branch — no merge, no rebase, no
  reset, no force push, and no history rewrite. **No prototype repository was touched**, in any way,
  at any point: no fetch, no read, no write. They are recorded here rather than implied, per binding
  forward rule 1.
- **What this session did not do, restated flatly.** It performed **no** governed acceptance, **no**
  execution preflight, **no** prototype preflight, **no** build, **no** tests, **no** database or
  container work, **no** importer or import, **no** live work, **no** commit, **no** push, and
  **no** merge request.
- **The governed acceptance of this go-ahead is deliberately the next session's work, not this
  one's.** Ordered execution step 1 of section 8 is a task for the session that performs it, exactly
  as the Piece D go-ahead handled its own acceptance step.
- **This document authorizes only its own publication for review** — by branch and merge request. It
  does **not** authorize merging that merge request.
- **This session touched exactly one path**, this document, and altered no other file, in either
  repository.
