# P1-0 — final sign-off (historical carve-out closed)

**Date:** 2026-08-05
**Accepted by:** Miguel Teixeira
**Status:** accepted and fully closed. The four-item carve-out recorded at the original sign-off
was closed by P1-0d; no current exclusion remains. Companion to `docs/p1-0-corrections.md`
(C1–C19) and `docs/p1-0-a-group-decisions.md` (A1–A7, C3, group B scope).

**Precedence:** `p1-0-corrections.md` → `p1-0-a-group-decisions.md` → **this file** → the P1-0
drafts. Where this file and a draft disagree, this file wins.

---

## The acceptance

**P1-0 is accepted and fully closed as of 2026-08-05. No item is currently excluded.** The four
items excluded at the original sign-off were a historical carve-out subsequently closed by P1-0d.
The drafts are the field-level authority for P1-1 as corrected by C1–C19, the group-A decisions,
and the four decisions below.

### What acceptance does *not* authorize

Unchanged from the original gate: **no migration against any shared or persistent database, no import of Luís's
live reference data, no 2026 history import, no merge to `main`, and no claim of P1-1 acceptance.**
P1-1a stays what it was — schema and validation service, disposable database, synthetic fixtures.

### Historical carve-out — subsequently closed by P1-0d

At this sign-off's date, **C9, C11, C12 and C15 were not accepted or signed off.** All four were
then partial because the required row-level values had not yet been recorded in this repository.
The contemporaneous gap was:

| Correction | What was missing at sign-off |
|---|---|
| C9 | The 19 exact DOCTYP tuples, including each DTCode and every source field |
| C11 | The complete DOCEFL seed rows needed to place and diff the sentinel row |
| C12 | The exact EFCode and complete DOCEFL row for the Monthly-gap detector |
| C15 | The literal ITMCLS `CLCode`s for *Banks / Financing* and *Revenue / Intercompany* |

The same historical carve-out included D6's exact BTCode and complete 14-field BNKMAT governance
row, plus A3's proposed natural keys for the `MatchGroupID` and `BRCode` buckets. The original
reasoning required a pinned, read-only prototype pass and forbade plausible inference: a plausible
seed and a real one are indistinguishable six weeks later. P1-0c correctly stopped when the pin
could not supply rows that C11, C12 and D6 themselves created; that assignment is now
**superseded and must not be rerun**.

**P1-0d subsequently closed the entire carve-out.** It transcribed C9's 19 DOCTYP rows and C15's
two ITMCLS mappings from pin `9359c67` with extraction provenance; authored the C11 sentinel,
C12 Monthly-gap and D6 BNKMAT rows with every field marked `authored` or `absent`; and resolved A3
from measurements at the pin (`MatchGroupID` is run-scoped, while `BRCode` uses the measured
collision-free key). These items are historical closure evidence, not live instructions or open
conditions.

### Nothing is blocked on Luís — and this correction is itself a lesson

**No Luís marker is an open question, and none is a gate.** This restates what
`p1-0-corrections.md` already says in its header and what
`FDR-to-Sibyla-decisions-for-Luis-v2.md` closes with — *"what is blocked on you: nothing,
strictly"* — because both were misread once already, on 2026-08-05, by a reader who took the
per-entry markers and skipped the paragraph framing them.

- **Seven decisions were taken on his behalf** against pinned data on 2026-08-04: C1, C2, C3, C4,
  C12, C19 and the singular `Receivable`. They are **decided, applied and implementable today.**
  He may object later and they are reversible until he does. That is a courtesy channel, not a
  dependency.
- **Two are actions in his own repository, not decisions**: merging the five duplicate ENTBNK
  pairs at source (C8) and classifying the three residual FL collisions (C13). C13 already passes
  import on the `DetectedAt` tiebreaker; C8 fails closed knowingly.
- **The 94.6% definition** is a reconciliation of two metrics, not an input. Sibyla's 55.9% is
  explicitly defined and stands on its own.

**Rule for anyone reading the correction register, human or agent: read its header before its
entries.** A *Needs Luís to confirm* marker means the decision is made. Treating it as pending
manufactures a blocker that was deliberately designed not to exist, and the design cost real
effort — the whole point of deciding on his behalf was to stop the .NET side waiting a week.

---

## S1 — `identifierType` gets a controlled vocabulary

**Decision: closed enumeration — `VAT`, `NIF`, `EORI`, `PassportNumber`, `NationalID`, `Other`.**
Validated case-sensitively like every other enum in the contract, failing closed on an unlisted
value.

The contract declared `identifierType` required, gave it its own confidence entry, and mandated
case-sensitive enum validation — against no vocabulary anywhere. That is not a documentation gap;
it is a rule that cannot be executed. Either side could have given way, and the field wins because
a party identifier that cannot be relied on is a party identifier nobody can decide from.

`Other` exists so an exotic identifier does not fail an otherwise good extraction — and a run of
`Other` values is a signal that the vocabulary needs a new member, which is a migration, not a
silent widening. Same discipline as `ItemClass`.

→ `p1-0-claude-extraction-contract.md`, and the vocabulary annex on the next regeneration. Closes
review item 1 and residual **B13**.

---

## S2 — DOCFLG snapshots `ItemClass` at detection

**Decision: the instance stores the `ItemClass` its rule carried when it fired. Changing a rule
never rewrites existing instances.**

Freeze decision #15 said snapshot; P1-6 said recomputed every run. Two phases of the same plan
said opposite things about one column, and the reversal was recorded nowhere — the review caught
it as a decision frozen in name only.

Snapshot wins for the same reason C3 chose immutability this morning: **a decision someone already
took must not change underneath them.** The phantom-backlog episode is the evidence — 2,616 open
items that were 93% Statuses and Annotations, and a queue whose meaning shifted as classifications
moved. A recomputing `ItemClass` reintroduces exactly that instability, one rule edit at a time.

**Historical consequence at sign-off:** the P1-6 text was stale and had to be corrected to say
snapshot. P1-0d subsequently made that correction; this is no longer an action for P1-0c, which is
superseded and must not be rerun. Leaving both statements in the plan would have been worse than
either one of them.

→ `p1-0-schema-mapping.md` DOCFLG, summary decision 15, and the P1-6 section of
`docs/project-todo.md`.

---

## S3 — the Legal archive sub-path

**Decision: `{Company}/Legal/{Subtype}/{Counterparty}/`.**

Subtype first. It is already a closed vocabulary in DOCTYP — Employment Contract, Customer
Contract, Supplier Contract, Bank Loan Agreement, Lease, Leasing/ALD, Insurance Policy,
License/Permit, NDA, Power of Attorney — so the segment is controlled rather than free text, which
is the same defect C16 fixed for the fiscal path.

The retrieval question that actually gets asked is *"where are all the insurance policies"* far
more often than *"everything we hold on this counterparty"*, and the second is a search, not a
directory walk. Period is not in the path: a multi-year contract's date says little about where
someone will look for it.

→ `p1-0-codes-taxonomy-archive.md` §3, `p1-0-schema-mapping.md` DOCARC. Closes the last undecided
half of the Nextcloud layout item.

---

## S4 — three defaults, confirmed

**The hash-index swap is scheduled to P1-1b.** Freeze decision #13 deferred it to "a reviewed later
migration" with no date and no phase, while two acceptance criteria depend on it. It is now
P1-1b, as its own reviewed migration — **never folded into the initial train**, which stays
squashable and untouched by it.

**Orphan DOCLOG has one definition:** *an EntryCode that resolves to no document in either FDCHDR
or the bank-generated document set, measured at the pin.* The three circulating figures — 129, 182
and 134 — were three measurements of three different things. That drift is the reason the D2
"stale rows" finding was nearly wrong: 134 turned out to be 89 retired identities, 18 future-dated
schedule rows, and the 27 that exposed a €142,835.50 payroll gap. Any other count is derived and
must say what it counts.

**B2, B3 and B4 were subsequently fixed by P1-0d in the operative lifecycle draft and do not block
sign-off.** The defects were real: Discard authority had been unbounded for `Posted` and
`ReferenceOnly`, *restore for review* named no target, and fresh captures had no defined legal entry
transition. The corrected draft requires a distinct authorized counter-signer for Discard from
`Posted` or `ReferenceOnly`; makes `RestoreForReview` target disposition `NULL` plus the existing
`DocumentStatus.AwaitingReview`; and defines the exact B4 entry statuses as
`DocumentStatus.Registered` for fresh captures, `DocumentStatus.RetryScheduled` while a malformed
response is retryable, `DocumentStatus.NeedsAttention` when retry is not scheduled or has been
exhausted, and `DocumentStatus.AwaitingReview` for schema-valid `NOT_A_DOCUMENT` captures. These
remain closed defect history, not current blockers.

**B1 is closed by `docs/p1-0-b1-decision.md`.** Byte storage is per capture and is never shared;
`RetainedContentHash` is only a duplicate-detection index. Reference counting is not implemented,
and purge removes only the selected capture's byte object as storage hygiene, never as erasure.
P1-1a implements the tombstone path under that invariant.

---

## What this changes operationally

At this sign-off's date, P1-1a no longer ran under a narrow exception to a closed gate: it ran under
an accepted phase with a named carve-out, in parallel with the then-planned P1-0c. P1-0d later
superseded P1-0c, closed the four carved-out corrections and resolved A3 by measurement, thereby
closing P1-0 completely. P1-0c must not be rerun.
