# P1-1b status — all four pieces Accepted; pin `b917685…` confirmed by path (a); Scope 1 ready to seek its own go-ahead

**Date:** 2026-08-07
**Authority:** Miguel
**Branch:** `feature/p1-1b`
**O8 records-amendment base:** `dabf3288ed86ce7c4c42d3e4b7099d13ff740cc1`

## 2026-08-08 merge adoption and publication — current record

The further P1-1b merge is complete and published. This section supersedes the frozen `80646b9`
authoring-state text as current state without altering that historical record.

**Miguel's decision, verbatim:**

> Adoto o merge local fc205fa. Não é criado outro merge, nem se usa reset, amend, rebase,
> revert, cherry-pick ou force push. Publica-se só se todas as verificações e a build
> passarem. O desvio da sessão anterior é registado como achado de governação, sem editar o
> texto congelado de 80646b9.

**Final topology:**

- Starting `main` SHA and first parent:
  `f1488acf4dfd6fb45fd836afcde5464e5c9d9ddf`.
- Accepted feature tip and second parent:
  `80646b9acbe36d8c351998076d6269a38e467b71`.
- Adopted local merge: `fc205facf8c2e9728a9404832cead1a16f0e593d`, with parents
  `f1488acf4dfd6fb45fd836afcde5464e5c9d9ddf` and
  `80646b9acbe36d8c351998076d6269a38e467b71`. It was adopted, not created by this line of
  sessions.
- GitLab server-side merge on `origin/main`:
  `c277b16abffac3ba18833e811a67641e81fdf58a`, subject
  `Merge branch 'merge/p1-1b-fc205fa' into 'main'`, with parents
  `f1488acf4dfd6fb45fd836afcde5464e5c9d9ddf` and
  `fc205facf8c2e9728a9404832cead1a16f0e593d`.
- `fc205facf8c2e9728a9404832cead1a16f0e593d` was published to `main` through
  `c277b16abffac3ba18833e811a67641e81fdf58a`.

**Corrected preflight — Pass.** Repository root was exactly
`D:/fileStorage/repos/GOTT.Sibyla`; exactly one worktree was registered; the working tree was clean
and staging was empty. Local `feature/p1-1b`, its origin-tracking ref, and live `ls-remote` were all
`80646b9acbe36d8c351998076d6269a38e467b71`, with divergence 0/0. Local `main` at
`fc205facf8c2e9728a9404832cead1a16f0e593d` was ancestral to `origin/main` at
`c277b16abffac3ba18833e811a67641e81fdf58a`, zero commits ahead and one behind; `git pull
--ff-only` fast-forwarded it to `c277b16abffac3ba18833e811a67641e81fdf58a`. After synchronization,
local `main`, `origin/main`, and live `ls-remote` were equal to
`c277b16abffac3ba18833e811a67641e81fdf58a`, with divergence 0/0.

**Publication checks:**

1. **Pass — exact parents.** The parent lists above were confirmed for both
   `c277b16abffac3ba18833e811a67641e81fdf58a` and
   `fc205facf8c2e9728a9404832cead1a16f0e593d`.
2. **Pass — adopted merge versus published result.** `git diff c277b16 fc205fa` was empty
   (**0 bytes**); `f1488acf4dfd6fb45fd836afcde5464e5c9d9ddf` is an ancestor of
   `fc205facf8c2e9728a9404832cead1a16f0e593d`; the MR introduced no content.
3. **Pass — accepted feature versus published result.** `git diff c277b16 80646b9` was empty
   (**0 bytes**).
4. **Pass — accepted paths and test object on `origin/main`.** In migration-then-SQL order:

   | Published path | Git blob ID |
   |---|---|
   | `src/Sibyla.Infrastructure/Persistence/Migrations/20260805180000_P11aFdrSchema.cs` | `497ce4ecbe63aa2c5fd7dd6eb2bcac01c6b48d0e` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/P11aSchemaSql.cs` | `74c5912cc85aebd99c1169a27217c67aa1955476` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/20260806180000_P11bPieceASchemaCompleteness.cs` | `a5ff78040a83440c771dc1b1ddde3c873bc88161` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceASchemaSql.cs` | `00b4bc2a988e1a54a5e2719d0fbc4814690d3782` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/20260806190000_P11bPieceBRegistryFieldProvenance.cs` | `d0beb8aafa78dc158318e6101277023f758edfaa` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceBSchemaSql.cs` | `bc9d958258a2715c23bb435868134a5d160bc9a3` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/20260806200000_P11bPieceCGovernedCommands.cs` | `0a111d0c981680f838dbcbbef1560cbce3eb77ba` |
   | `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceCSchemaSql.cs` | `398887002499404c80b9509564fd4369ac93a371` |

   `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` has `origin/main` blob
   `c5915524ffe355e8955e9254f8be40b008813f97`, exactly equal to candidate
   `a4d40aac429584baed3481d62c2f859dd4ad2860`.
5. **Pass — first build on the published MR result.** From `origin/main`
   `c277b16abffac3ba18833e811a67641e81fdf58a`, `dotnet clean GOTT.Sibyla.slnx -c Release` followed
   by `dotnet build GOTT.Sibyla.slnx -c Release --no-incremental` succeeded with **0 warnings / 0
   errors** in **00:00:35.16**. Ordinary `dotnet test
   tests/Sibyla.Tests/Sibyla.Tests.csproj -c Release --no-build` passed **646/646**, failed 0,
   skipped 0, duration **17 s**. This was the **first build run on the published MR result**.

**Governance finding — both halves are binding.** The `80646b9` entry said the merge had not
occurred and became stale one minute later when the same session created `fc205fa` without a new
record. Conversely, the merge was later published by MR but the required adoption record still did
not exist. The `80646b9` text remains untouched and was exact when written; this record supersedes
it as current state.

**Binding forward rules, in the spirit of D-A2-L1:**

1. A session that records it did not exercise an authority must not then exercise it without first
   recording that it has moved to exercise it.
2. No Git topology is published, by direct push or MR, before the record describing it is committed
   and pushed.

**Corrected MR-flow preflight rule:** before synchronization, local `main` must be an ancestor of
`origin/main`, zero commits ahead, and capable of a fast-forward. A 0/0 divergence is not required
before synchronization; it is required after the fast-forward completes.

**Scope boundary:** this records session does not author the Scope 1 go-ahead, start Scope 1 or its
execution preflight, run any importer or import, write any shared or live database, touch the
prototype, perform O5, alter the pin, baselines, closed decisions, or accepted objects, update the
project-evolution page, or merge this records MR.

## 2026-08-07 Scope 1 re-pin checkpoint — Miguel confirms the pin by path (a)

Amendment 4's **Scope 1 re-pin checkpoint** — the confirm-pin-or-re-pin decision that sits after
Piece D's Accept and before any Scope 1 restart — **is now satisfied**. The full record is
`docs/AGENT-PROMPT-v5-P1-1b-scope1-pin-confirmation.md`. The checkpoint became reachable when
candidate `a4d40aac429584baed3481d62c2f859dd4ad2860` received its independent **Accept — 0
Critical, 0 High, 0 Medium, 1 Low (D-A2-L1)**, published at
`744424df167af52b9680d0f46bfca50225422138`; **all four pieces A, B, C, and D are accepted.**

**Miguel's decision, verbatim:**

> Confirmo o pin b91768513fc638381fbde91f0b576b08220a98f6 como snapshot de importação
> histórica. Caminho (a) do amendment 4. A evolução pós-pin do protótipo é tratada como
> importações governadas posteriores sob as decisões já fechadas D4–D9.

**Path (a), not path (b).** `b91768513fc638381fbde91f0b576b08220a98f6` is confirmed as the
historical-import snapshot; post-pin prototype evolution is handled as later governed imports
under the already-closed **D4–D9** additive-period-imports decisions. **No O11-class re-pin was
made or authorized**, so none of path (b)'s preconditions is triggered: no re-verification at a
new pin, no re-measurement of the five baselines, no C8 (43/43/0/0) or C13 re-measurement, no
DOCTYP manifest re-check, and no `EF0000053`/authored-code re-check against a changed
`permanent_code_ledger.json`. **Nothing in any closed decision is reopened** — O8-D1/D2, O9-P,
O9-D1…D5, O10-D1/D2, and D4–D9 govern unchanged; baselines remain **119 / 119 / 52 / 221 /
2,787** with both `Routine` rows still importing verbatim; the non-adoption rule stands.

**Amendment-4 preflight, run fresh in this session** — read-only against
`D:/fileStorage/repos/invoice-skill-build` after `git fetch`, measured immediately before this
record was written. This is **this session's own run, not adoption of another session's result**,
honouring D-A2-L1's binding disposition.

1. Pin resolves locally and in the fetched remote — **Pass**.
2. Pin is an ancestor of live `origin/main` `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` — **Pass**.
3. Local clone `HEAD` equals the pin and the working tree is clean — **Pass**.
4. Effective governed roster measured **cell by cell**: **49/49, 0 mismatches, 0 resolve
   failures** — **Pass**; O8 `entbnk` substitution blob
   `70d418f6023bff68f0d642b4aff26c1ead1298be`.
5. Direct pinned `Editor/Data` surface: **48/48 direct blobs, exactly one `Backups` tree, 0
   missing, 0 extra** — **Pass**.
6. Divergence recorded as metadata only, per check 6: live prototype tip
   `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`; post-pin commits by hash and subject only —
   `1e841a4f9a88cd6a5e90e6632dff54185be9949e` (*Complete Stage 10 Round 8 reconciliation and
   mapping updates*) and `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` (*Apply Stage 10 Round 8
   revenue review updates*). **No post-pin content was read or adopted.**

This is the **records checkpoint preflight, not Scope 1's execution preflight**; it does not
discharge or substitute for the fresh preflight the session that performs Scope 1 must run itself.

**Scope 1 is ready to seek its own go-ahead.** It has **not** started: no Scope 1
execution preflight has run, no Scope 1 go-ahead exists, and no importer/import, shared or live
database write, prototype write, O5, baseline, closed-decision, or project-evolution-page work was
performed or authorized. Item 5's real-population proof remains deferred to Scope 1; O5 remains
the project's other open item. This pass is records-only across exactly three paths —
`docs/AGENT-PROMPT-v5-P1-1b-scope1-pin-confirmation.md`, this file, and `docs/PROJECT-STATE.md` —
with no build, test, container, or database run, and **no post-pin prototype content read,
inspected, or adopted** (checks 4–5 used only the authorized pin-anchored roster/surface
measurement).

**Merge authority — granted, not yet exercised.** Miguel authorizes **a further, normal merge of
`feature/p1-1b` into `main`**, permitted only **after this exact three-path pin-confirmation
commit is committed and pushed**. **Ordinary merge commit only — no rebase, squash, amend, reset,
or force push.** This further merge is **not** `f1488ac`, the earlier `feature/p1-1b`→`main` merge
that was **already performed**; `f1488ac` is past history and is not the authorization being
exercised here. That further merge is **not performed by this records pass**; it changes no pin,
baseline, closed decision, or accepted object, and it neither starts Scope 1 nor supplies Scope 1's
go-ahead or execution preflight. **This pass states no merge SHA solely because the merge has not
occurred yet** — that is a fact about this pass, not a standing prohibition; the later merge
session records the actual SHA. **This grant retires forward — as statements of current
authority only — the dated "No merge is authorized or performed" lines recorded earlier**,
including the one in the 2026-08-07 Piece D ordered-instruction-4 Accept entry below (and that
entry's "Authority now open" paragraph) and the like lines in earlier records entries. Those
lines **remain accurate at their recorded moments** and are **left unedited**: they are frozen
historical statements of what was authorized when they were written, superseded as current state
by this paragraph and by nothing else.

## 2026-08-07 Piece D ordered instruction 4 — independent integration review: Accept

Candidate `a4d40aac429584baed3481d62c2f859dd4ad2860` received the separately authorized fresh
independent integration-focused review in an exclusively-review session. **Verdict: Accept — 0
Critical, 0 High, 0 Medium, 1 Low (D-A2-L1).** The full record is in
`docs/p1-1b-o10-independent-review.md` ("Piece D attempt #2 integration review — Accept"). Nothing in
the implementer's summary was trusted; every figure was independently measured.

**D-R1 closed at the root, and proven non-vacuous.** The rejected candidate's `EnsureMigrated`→`Down`
→capture-S0 sequence is deleted outright. S0 now comes from a separate database
(`sibyla_piece_d_oracle_<guid>`, distinct from cycle database `sibyla_p11a`), created empty and
migrated directly from empty only through `20260805180000_P11aFdrSchema`, captured in class-fixture
`InitializeAsync` before any `[Fact]` while the cycle database is asserted empty, held immutable and
never recaptured or rebased. Equality was **not** accepted as proof of itself: four original
adversarial probes were executed and fully removed before the verdict — (A) an extra table injected
into the oracle breaks `S0==S2` at the logical snapshot; (B) a cluster-global role created after
`Down` breaks it via `role|…`, proving S2 exposes leaked global state; (C) forcing all four
`ImportEvidenceRow` checkpoints to return an equal-but-empty set still fails at
`Expected: 4, Actual: 0`, closing exactly the hole D-R2 named; (D) a hostile pre-existing
`sibyla_piece_c_executor` makes **all 61 Facts fail, 0 pass, in 139 ms**, proving the fixture fails
closed and initializes before every Fact.

**D-R2 closed.** Cardinality 4 plus the four exact `pg_get_constraintdef` values are asserted at all
four checkpoints, then dictionary and index equality; probe C proves the checkpoint assertions fire
independently of equality. No generated-name contract is created.

**Inventory verified against the correct base.** Because the Reject #1 neutralization restored the
test file to the pre-candidate blob, inventory is measured against `bf5926e…`. Measured `[Fact]`
counts: `a052909…` **55**, `bf5926e…` **61**, `a4d40aa…` **61**; added `[Fact]` lines in the
remediation delta **0**. Exactly 0 new test methods, 1 new helper, 1 new fixture, 1 strengthened
method, 4 unchanged regressions. The only deleted line in the whole base→candidate test diff is the
class declaration, so the four regressions are byte-identical to the approved base.

**Test-case orderer assessed and judged within the approved inventory** — an interface on the already
approved fixture plus one attribute, implementing D-R1-O2's approved fixed execution order. Probe E
removed the attribute and reproduced the implementer's honest 60/61 observation
(`role|sibyla_piece_c_non_owner_probe`), proving it load-bearing; probe B proves it does not mask a
genuine `Down` leak. Not a finding.

**Independently reproduced envelope:** clean Release rebuild 0 warnings/0 errors; ordinary 646/646;
Registry 33/33; focused Piece D 1/1; four exact regressions 4/4; canonical runner 61/61 on PostgreSQL
**17.10**; `git diff --check` clean working and cached; 0 residual and 0 running `sibyla-p11*`
containers; exactly three changed paths; all eight accepted migration/SQL blobs byte-identical;
`RejectTerminalDOCFLGMutationFn` stable live at S0/S2 `525`/`48af12cf…` and S1/S3 `1107`/`f9bfc42f…`.
Recorded history hashes `71112d8e…` and `f9e37bb2…` reproduced exactly. A stale-assembly trap was hit
after the probes (`Copy-Item` restored an older timestamp, so MSBuild reused the Probe-E assembly and
a run reported 60/61); it was root-caused, the assembly rebuilt `--no-incremental`, and the suite
re-run at **61/61** — reported here rather than hidden.

**Independent amendment-4 preflight, run fresh this session,** read-only against
`D:\fileStorage\repos\invoice-skill-build`: pin resolves locally and remotely; pin is an ancestor of
live `main` `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`; local clone anchored at the pin with a clean
tree; the governed 49-blob roster measured cell by cell **49/49, 0 mismatches, 0 resolve failures**
(with the O8 `entbnk.json` substitution `70d418f6…`); direct surface **48/48 blob files plus 1
`Backups` tree, 0 delta**; check 6 metadata only, reproducing post-pin `1e841a4` and `3dd4150`. No
post-pin content was read or adopted.

**Finding D-A2-L1 (Low) — preflight adoption is not admissible as execution evidence.** The
implementing session did not run the amendment-4 preflight itself; it adopted the host's immediately
preceding session's run, which Piece D checklist item 1's requirement that checks 1–5 "pass fresh"
does not permit. A preflight is a point-in-time drift/tamper detector and checks 2–3 are hard stops
precisely because they detect third-party mutation between sessions. Severity is **Low** because the
disclosure is honest (so "claims equal assertions" is not violated), because amendment 4 itself states
pinned reads are content-addressed and live freshness "has no bearing" on Pieces A–D, and because this
review executed all six checks fresh with identical results — no drift occurred. **The finding is
recorded, not waived:** preflight adoption is inadmissible for any future piece, stage, or Scope 1
work under this prompt family; each session runs its own. Miguel did not pre-decide this and may
overrule it.

**Authority now open:** Accept authorizes Scope 1 **only to seek its own preflight and the
confirm-pin-or-re-pin checkpoint** against pin `b917685…`. Scope 1 is **not** started by this review.
**No merge is authorized or performed.** Item 5's real-population proof remains deferred to Scope 1;
O5 remains the project's other open item. All probes were removed before the verdict; the test file
is byte-identical to candidate blob `c5915524…` and the working tree is clean.

## 2026-08-07 Piece D attempt #2 — ordered instruction 3 candidate and evidence map

Only ordered instruction 3 was executed from pushed approval tip
`a0529093838b2fd95d40c5057db6dd896e9b85fc`. This is a candidate record, not an Accept/Reject
verdict or self-review. Ordered instruction 4 has not begun and requires separate authority. Scope
1, item 5, O5, merge, project evolution, importer/import execution, shared/live database work, and
all accepted-object changes remain unauthorized.

### Hard start and amendment-4 evidence

At start, the repository was exactly `D:/fileStorage/repos/GOTT.Sibyla`, branch
`feature/p1-1b`; local `HEAD`, `origin/feature/p1-1b`, and live `ls-remote` all equalled
`a0529093838b2fd95d40c5057db6dd896e9b85fc`; divergence was `0/0`; status and staging were empty;
exactly one worktree was registered. The host's immediately preceding fresh read-only amendment-4
preflight is adopted as execution evidence: pin `b91768513fc638381fbde91f0b576b08220a98f6`
resolved locally/remotely and was an ancestor of `origin/main`; the read-only prototype clone was
anchored and clean; roster measurement was 49/49 with 0 mismatches/resolve failures (O8 ENTBNK
substitution blob `70d418f6023bff68f0d642b4aff26c1ead1298be`); the direct pinned surface was 48/48 files plus one
tree with delta 0. Check 6 was metadata only: live/local main
`3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`, post-pin commit hash/subjects only
`1e841a4f9a88cd6a5e90e6632dff54185be9949e` (*Complete Stage 10 Round 8 reconciliation and mapping
updates*) and `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` (*Apply Stage 10 Round 8 revenue review updates*).
No post-pin content was read or adopted, and this session did not repeat that content inspection.

Static D-R1-O3 feasibility passed before mutation: `Category=P11aDatabase` occurs on only
`P11aDisposableDatabaseTests`; the canonical runner supplies one shared connection string to that
class; xUnit class-fixture initialization precedes every Fact; no other class participates in that
category/connection. The fixture also implements the class test-case orderer so the combined cycle
runs first, after immutable S0 capture and before any Fact can create cluster-global probe roles.
The initial full-run attempt honestly exposed why this fixed order is required: 60/61 passed but
S0/S2 differed after earlier Facts left `sibyla_piece_c_non_owner_probe` in the cluster. No catalog
surface was excluded or normalized around that finding; ordering was made explicit under approved
D-R1-O2, after which the canonical runner passed 61/61.

### Strict TDD record

The smallest RED added only the approved class-fixture surface and no test method. Command:

```powershell
dotnet test tests\Sibyla.Tests\Sibyla.Tests.csproj --filter "Category=P11aDatabase&FullyQualifiedName~P11aDisposableDatabaseTests.Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up" --no-restore
```

It ran in a fresh disposable `postgres:17-alpine` container from
`2026-08-07T15:49:57.3670486Z` to `2026-08-07T15:50:36.8453390Z`, exited 1, and failed 0/1 for the
intended missing behavior: `InvalidOperationException: Piece D pristine P1-1a oracle is not
implemented.` It was not a typo/compile failure; cleanup left 0 `sibyla-p11*` containers. After the
minimum fixture/helper implementation, the same slice ran from `2026-08-07T15:53:59.9207914Z` to
`2026-08-07T15:54:21.6749262Z`, exited 0, and passed 1/1; cleanup again left 0 containers. Refactoring
occurred only after that GREEN.

### D-R1 / D-R1-O1 / D-R1-O2 / D-R1-O3

- New helper `CreatePieceDPristineP11aOracleDatabaseAsync` creates the unique oracle database in
  the same PostgreSQL 17 invocation, proves runner/oracle empty and distinct, migrates the oracle
  directly from empty only through `20260805180000_P11aFdrSchema`, captures immutable S0, and
  drops the database on failed initialization.
- New `PieceDPristineP11aOracleFixture` is an xUnit `IAsyncLifetime` class fixture. Before any Fact
  it asserts no cluster-global `sibyla_piece_c_executor`, no user catalog/history in the runner,
  creates and retains S0, and owns fail-safe forced oracle cleanup. Fixed class ordering runs the
  combined Fact first and Facts in the class do not execute in parallel.
- The strengthened combined method uses fixture S0 and the separate cycle database's S1/S2/S3.
  The final focused run (`2026-08-07T16:00:15.0516947Z`, exit 0, 1/1) observed distinct names
  `sibyla_p11a` and `sibyla_piece_d_oracle_<unique-guid>`, both initially empty;
  S0==S2 logical+physical, S1==S3 complete logical, and S0!=S1. History hashes were
  S0/S2 `71112d8e521d4c97c01bcc11f4f66e23bc5eea82176c191d347c66d25e9f7e23` and S1/S3
  `f9e37bb2c2ce97bc3781e1727a5849fb97bae218b6a13697a33028072f7035b2`.
- Option A remains exact: physical `attnum` diagnostics are retained/emitted for S1 and S3 and
  excluded only from S1/S3 logical equality; S0/S2 retains physical equality. No curated catalog
  roster or lossy count replaced the dynamic complete snapshot.

### D-R2 / D-R2-O1

The combined method reuses unchanged `ImportEvidenceRowUniqueConstraints` and
`ImportEvidenceRowIndexes` at S0/S1/S2/S3. Every checkpoint asserts exactly four UNIQUE
constraints and the four approved literal definitions, then asserts dictionary/name equality and
index equality across all checkpoints. The within-run names observed were
`ImportEvidenceRow_Id_CompanyCode_TargetTable_TargetPermanen_key`,
`ImportEvidenceRow_Id_TargetTable_TargetPermanentCode_key`,
`ImportEvidenceRow_ImportBatchId_SourceTable_SourcePermanent_key`, and
`ImportEvidenceRow_ImportBatchId_SourceTable_SourceRecordKey_key`; they are evidence, not a new
generated-name contract.

### Inventory, unchanged regressions, and immutable objects

Relative to rejected candidate `bf5926e3bba9afca394baf669f95c72506886056`, both candidate and
this attempt contain exactly 61 Facts: **0 new test methods, 1 new helper, 1 new fixture, 1
strengthened shared method, and 4 unchanged regression methods**. Normalized method-source SHA-256
HEAD/worktree equality for the four regressions is respectively:
`f6f79b1410b8a402ffaa289290e2461ffdf546e4431981477be4b0ed5ba3668f`,
`3698fc7757e6a4f607a8952e3fcf90bd03ebb025746d3f77edaaeb8209a7747c`,
`79e04aa878ccf27d4d549911dca83f7eedf1c1c6e3d09420f4ec18beb6358d25`, and
`025118e8e47b8ef88e23af03d45cbf8663119db4225e4944350f47774847127f` in the approved A/B/C-down
then Piece-A-ImportEvidenceRow order. Their explicit disposable slice passed 4/4.

All eight accepted migration/SQL files remained equal at HEAD/index/worktree with blobs, in order:
`497ce4ecbe63aa2c5fd7dd6eb2bcac01c6b48d0e`,
`74c5912cc85aebd99c1169a27217c67aa1955476`,
`a5ff78040a83440c771dc1b1ddde3c873bc88161`,
`00b4bc2a988e1a54a5e2719d0fbc4814690d3782`,
`d0beb8aafa78dc158318e6101277023f758edfaa`,
`bc9d958258a2715c23bb435868134a5d160bc9a3`,
`0a111d0c981680f838dbcbbef1560cbce3eb77ba`, and
`398887002499404c80b9509564fd4369ac93a371`. Live normalized
`pg_get_functiondef` proved `RejectTerminalDOCFLGMutationFn` stable across each cycle state:
S0/S2 size/hash `525` / `48af12cf84952c279610fea3909ed6c83a6b866fa9f63bf69e10ea01427e8283`;
S1/S3 size/hash `1107` / `f9bfc42f4499aa6f2b96cf267d9b2919f9229757af6f5985048327e4afbff391`.
No function text is reproduced here.

### Final measured envelope

- clean Release rebuild: exit 0, 0 warnings / 0 errors;
- ordinary suite: 646/646; exact Registry class: 33/33;
- focused strengthened Piece D: 1/1; four exact unchanged regressions: 4/4;
- canonical `scripts/run-p11a-disposable-tests.ps1`: 61/61 on PostgreSQL 17;
- working `git diff --check`: clean; added-line secret scan: 0 matches without printing values;
- pre-record changed path was only the test file; the final candidate path set is exactly the test
  file plus this record and `docs/PROJECT-STATE.md`;
- every disposable execution reported 0 residual containers; final canonical runner reported 0
  residual and 0 running containers.

One broad exploratory filter, `FullyQualifiedName~Registry`, exited 1 because it unintentionally
selected two `P11aDatabase` tests without a provisioned harness (33 passed, 2 failed for the missing
required connection). The corrected exact Registry-class command above passed 33/33; the failed
selector is retained here rather than hidden.

**State:** Piece D attempt #2 candidate published, awaiting separately authorized ordered
instruction 4. No verdict is issued here.

## 2026-08-07 Piece D Reject #1 — remediation approval recorded (records only)

Miguel's approval, recorded verbatim:

> Aprovo a remediação da Piece D: D-R1, D-R2, D-R1-O1, D-R1-O2, D-R1-O3 e D-R2-O1.

`docs/AGENT-PROMPT-v5-P1-1b-piece-d-remediation-approval.md` approves the complete Step 2 mapping
below as the binding test plan for the second and final Piece D attempt before escalation. **D-R1**
and **D-R2** are approved item by item, together with all four observations:

- **D-R1-O1:** “one disposable run” means one PostgreSQL 17 container/test invocation with two
  isolated databases, one pristine accepted-P1-1a oracle and one cycle database.
- **D-R1-O2:** execution order is fixed; immutable S0 is captured before any Piece C
  cluster-global role, with unique database names, fail-safe cleanup, no parallel combined-method
  execution, and no S0 recapture/rebase.
- **D-R1-O3:** `PieceDPristineP11aOracleFixture` uses class-fixture lifecycle before any Fact and
  fails closed on a non-fresh cluster or an ordering/shared-connection precondition that cannot be
  statically guaranteed.
- **D-R2-O1:** every S0–S3 checkpoint asserts cardinality four and the four exact
  `pg_get_constraintdef` values; within-run dictionary equality compares observed names without
  creating a stable contract over generated names.

The approved implementation inventory remains exactly **0 new test methods, 1 new helper, 1 new
test fixture, 1 strengthened shared test method, and 4 unchanged existing regression methods**.
Option A, D-M2-A, and D-M3-A+ remain operative. All accepted objects,
`RejectTerminalDOCFLGMutationFn`, and all eight accepted migration/SQL files remain untouched. Every
previously-Pass surface remains a regression requirement. A second Piece D Reject stops and
escalates to Miguel.

**Authority after this commit is pushed:** ordered instruction **3 only** is authorized, TDD first,
from this pushed approval tip, applying exactly the approved D-R1/D-R2 remediation contract. This
records step does not authorize or perform implementation, build, test, database, container, or
preflight work. It does **not** authorize ordered instruction 4, Scope 1, item 5, O5, merge,
project-evolution work, importer/import execution, shared/live database work, migration/DDL changes,
or any accepted-object change.

## 2026-08-07 Piece D Reject #1 — Step 2 remediation mapping (records only)

This mapping defines the proposed second/final Piece D remediation attempt before escalation; the
implementation attempt has not begun, and this mapping is not an approval. Miguel approved only the
scope to map both binding findings; he has **not** approved this mapping. No remediation
implementation may begin until Miguel explicitly approves **D-R1, D-R2, and Observations D-R1-O1,
D-R1-O2, D-R1-O3, and D-R2-O1** below. A second Piece D Reject stops and escalates to Miguel.

Authority remains: rejected candidate `bf5926e3bba9afca394baf669f95c72506886056`; Reject record
`8755b049e24190179eeebcbb21e0f9d7f9c9e092`; published neutralization
`46946c6e3aae5e366e5d601a3aea9d0677b3f200`; approved base
`9ba2bdd468be32d1de36f7ee7cd9d1607949dc6a`.

### D-R1 — High — Test harness / disposable PostgreSQL 17

- **New helper:** add exactly `CreatePieceDPristineP11aOracleDatabaseAsync`. Within the same
  disposable PostgreSQL 17 container/run it creates a second, isolated database, migrates it
  directly from empty only through `20260805180000_P11aFdrSchema`, captures immutable S0 before
  any A+B+C `Up` occurs in the other database, and must never derive S0 after a full-tip/`Down`
  cycle. It is owned and called by the new fixture before any Fact, not lazily by the combined
  method.
- **New test fixture:** add exactly `PieceDPristineP11aOracleFixture` using xUnit
  `IAsyncLifetime`/class-fixture lifecycle. Its initialization runs before any `[Fact]` in
  `P11aDisposableDatabaseTests`, asserts the canonical runner's fresh PostgreSQL cluster entry
  precondition (no cluster-global `sibyla_piece_c_executor`; the pristine runner database has no
  applied Piece A/B/C history), calls `CreatePieceDPristineP11aOracleDatabaseAsync`, creates and
  migrates the isolated oracle only to `20260805180000_P11aFdrSchema`, captures immutable S0, and
  retains it for the strengthened method. Fixture cleanup drops the oracle database fail-safely.
  Miguel must explicitly approve the class-fixture lifecycle and new fixture surface.
- **Strengthened method:** retain and strengthen the historical candidate method
  `Piece_d_combined_cumulative_up_down_up_over_a_plus_b_plus_c_matches_accepted_p1_1a_and_is_stable`.
  S0 is the fixture's pre-Fact immutable snapshot; S1/S2/S3 come from a separate cycle database.
  The combined Fact may execute later and brings that database to full tip, `Down` to P1-1a for S2,
  then `Up` for S3.
  `Assert.Equal(S0,S2)` therefore compares independent origins; `Assert.Equal(S1,S3)` retains the
  determinism proof; `Assert.NotEqual(S0,S1)` retains sensitivity. The snapshot covers complete
  logical and physical state, including roles, ACLs, functions, triggers, constraints, indexes,
  and migration history, normalizing only non-contractual physical identities. The method proves
  both databases began empty and independent, their migration histories are correct, and cleanup
  completes.
- **Existing regressions:** re-run unchanged
  `Piece_a_down_is_exact_and_up_down_up_is_catalog_stable`,
  `Piece_b_down_is_exact_and_up_down_up_is_catalog_stable`, and
  `Piece_c_down_is_exact_and_up_down_up_is_catalog_stable`. They remain regression evidence and do
  not replace the independent oracle.

Future commands, recorded exactly and **not run in this authoring pass**:

```powershell
dotnet test tests/Sibyla.Tests/Sibyla.Tests.csproj --filter "Category=P11aDatabase&FullyQualifiedName~P11aDisposableDatabaseTests.Piece_d_combined_cumulative_up_down_up_over_a_plus_b_plus_c_matches_accepted_p1_1a_and_is_stable"
powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/run-p11a-disposable-tests.ps1
git diff --check
```

The focused method command is run only inside an already-provisioned disposable harness. The full
runner and `git diff --check` are followed by an exact changed-path comparison against this approved
mapping.

### D-R2 — Low — `ImportEvidenceRow` constraint/index assertion surface

- **Strengthened:** inside the same strengthened combined method/run, reuse unchanged
  `ImportEvidenceRowUniqueConstraints(connectionString)` and
  `ImportEvidenceRowIndexes(connectionString)` at S0/S1/S2/S3. At every checkpoint assert
  cardinality exactly 4 and these exact `pg_get_constraintdef` values literally:
  1. `UNIQUE NULLS NOT DISTINCT ("ImportBatchId", "SourceTable", "SourcePermanentCode")`
  2. `UNIQUE NULLS NOT DISTINCT ("ImportBatchId", "SourceTable", "SourceRecordKey")`
  3. `UNIQUE ("Id", "TargetTable", "TargetPermanentCode")`
  4. `UNIQUE ("Id", "CompanyCode", "TargetTable", "TargetPermanentCode")`

  Then assert `uniqueS0 == uniqueS1 == uniqueS2 == uniqueS3` and
  `indexS0 == indexS1 == indexS2 == indexS3`. Equality alone never substitutes for the checkpoint
  cardinality and literal definitions.
- **Existing regression:** re-run unchanged
  `Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up`.
  It remains secondary evidence and does not replace the in-method S0–S3 literal assertions.

Its exact future focused command, again only in an already-provisioned disposable harness, is:

```powershell
dotnet test tests/Sibyla.Tests/Sibyla.Tests.csproj --filter "Category=P11aDatabase&FullyQualifiedName~P11aDisposableDatabaseTests.Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up"
```

It is accompanied by the exact focused Piece D command, full canonical runner, `git diff --check`,
and exact changed-path comparison already recorded above.

### Adversarial feasibility observations — explicit approval required

1. **Observation D-R1-O1 — one run vs independent oracle ambiguity.** A genuinely independent
   pristine P1-1a oracle cannot be produced by the database that first applied full tip and ran
   `Down`. Proposed resolution: “one disposable PostgreSQL 17 run” means one container/test
   invocation holding two isolated databases, with S0 captured from the pristine database before
   any A+B+C `Up` in the cycle database. This preserves one container/run and oracle independence.
   Miguel must explicitly approve this interpretation; if the contract means exactly one database,
   D-R1 is infeasible and work must hold/escalate.
2. **Observation D-R1-O2 — cluster-global roles/order sensitivity.** Roles are cluster-wide. The
   pristine S0 snapshot must therefore be captured before the cycle database creates Piece C
   role(s); S2 after `Down` must match that fixed S0 and detect any leaked global role. Proposed
   resolution: fixed execution order, unique database names, guaranteed drop/cleanup, and no
   parallel execution for the combined method. S0 is never recaptured or rebased after the cycle.
   Miguel must explicitly approve this resolution.
3. **Observation D-R1-O3 — fixture lifecycle / shared-cluster ordering collision.** Calling the
   helper only inside the combined Fact is too late if earlier Facts in the same class have already
   migrated the canonical runner's shared cluster to Piece C and created cluster-global
   `sibyla_piece_c_executor`; Piece C `Up` explicitly fails when that role already exists. “No
   parallel execution” alone guarantees neither a pristine cluster nor method order. Proposed
   resolution: `PieceDPristineP11aOracleFixture` owns/calls the helper during class-fixture
   initialization before any Fact and fails closed on the fresh-cluster preconditions above.
   Implementation verification must statically confirm `Category=P11aDatabase` shared-connection
   participation and fail closed if another class can mutate the cluster before this fixture. If
   class-fixture initialization cannot be guaranteed before every shared-cluster mutation under the
   canonical runner, D-R1 remains infeasible and implementation must hold/escalate. Miguel must
   explicitly approve this resolution.
4. **Observation D-R2-O1 — exact definitions vs constraint names.** The finding requires four
   constraints and four exact definitions; the accepted Piece A regression asserts those values,
   not stable auto-generated names. Proposed resolution: bind cardinality and exact
   `pg_get_constraintdef` values at every checkpoint, while retaining dictionary equality—and thus
   names—across checkpoints without creating a new contract that fixes generated constraint names.
   Miguel must explicitly approve this resolution.

No other collision was found by this adversarial assessment; that is an authoring assessment, not
execution evidence. Inventory: **0 new test methods, 1 new helper, 1 new test fixture, 1 strengthened
shared test method, and 4 unchanged existing regression methods** (three Piece A/B/C down/up methods plus one
Piece A `ImportEvidenceRow` method). All surfaces that passed the rejected candidate/checklist must
regress unchanged; no previous surface is reopened. Option A, D-M2-A, and D-M3-A+ remain operative;
accepted objects and `RejectTerminalDOCFLGMutationFn` remain untouched. Item 5, Scope 1, O5, merge
authority, and the project-evolution page remain outside scope.

**Gate:** stop here pending Miguel's explicit approval of D-R1, D-R2, and all four Observations
D-R1-O1, D-R1-O2, D-R1-O3, and D-R2-O1. This mapping is published by its own records-only commit;
this entry does not predeclare that commit's SHA. No build, test, database, container, or implementation
ran; no `migration`/`DDL`/`src`/`Designer`/`ModelSnapshot`/`script`/`importer` surface changed, and no
execution result is claimed.

## 2026-08-07 Piece D Reject #1 — Step 1 records-first neutralization

Piece D **Reject #1 is neutralized**, as required by amendment 3's per-piece Reject rule. The only
candidate implementation path,
`tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs`, is restored byte-exactly in the
additive neutralization commit/tip to approved D-M3-A+ tip
`9ba2bdd468be32d1de36f7ee7cd9d1607949dc6a`. Candidate
`bf5926e3bba9afca394baf669f95c72506886056` and Reject commit
`8755b049e24190179eeebcbb21e0f9d7f9c9e092` remain immutable historical evidence; neither is
rewritten or erased.

Measured Git blob identity for the restored test is:

| Location | Blob ID |
|---|---|
| approved tip `9ba2bdd…` | `06bcc991e0cac6ff43697251ae131a1c97063d22` |
| additive neutralization commit/tip: `HEAD`, index, and working tree | `06bcc991e0cac6ff43697251ae131a1c97063d22` |
| pre-neutralization Reject tip `8755b04…` | `1397dc1963cd5153c5c406e7d1c18394876f4ba6` |
| rejected candidate `bf5926e…` | `1397dc1963cd5153c5c406e7d1c18394876f4ba6` |

The eight accepted migration/SQL paths were measured at `9ba2bdd…`, the pre-neutralization tip,
and the additive neutralization commit/tip; they remain byte-identical throughout:

| Accepted path | Measured Git blob ID |
|---|---|
| `src/Sibyla.Infrastructure/Persistence/Migrations/20260805180000_P11aFdrSchema.cs` | `497ce4ecbe63aa2c5fd7dd6eb2bcac01c6b48d0e` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/P11aSchemaSql.cs` | `74c5912cc85aebd99c1169a27217c67aa1955476` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/20260806180000_P11bPieceASchemaCompleteness.cs` | `a5ff78040a83440c771dc1b1ddde3c873bc88161` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceASchemaSql.cs` | `00b4bc2a988e1a54a5e2719d0fbc4814690d3782` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/20260806190000_P11bPieceBRegistryFieldProvenance.cs` | `d0beb8aafa78dc158318e6101277023f758edfaa` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceBSchemaSql.cs` | `bc9d958258a2715c23bb435868134a5d160bc9a3` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/20260806200000_P11bPieceCGovernedCommands.cs` | `0a111d0c981680f838dbcbbef1560cbce3eb77ba` |
| `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceCSchemaSql.cs` | `398887002499404c80b9509564fd4369ac93a371` |

Binding High **D-R1** and Low **D-R2** remain binding and no remediation is implemented. Miguel has
approved the future remediation-mapping scope for **both D-R1 and D-R2**; authoring that mapping is
**Step 2** and is deliberately not performed or sketched here. **Option A, D-M2-A, and D-M3-A+**
remain operative. The accepted `RejectTerminalDOCFLGMutationFn` is untouched. Item 5 and Scope 1,
O5, merge authority, and the project-evolution page retain their existing governance; this step
changes none of them. A second Piece D Reject stops and escalates to Miguel under amendment 3.

This records-first neutralization changes only the restored test and the three preserved records.
Step 1 requires their normal additive commit and push; this records-writing passage does not itself
perform either operation, and the future commit SHA is deliberately not invented. No build, test,
database, container, remediation-mapping implementation, history rewrite, AGENT-PROMPT change, or
project-evolution-page change is part of the step.

## 2026-08-07 Piece D ordered instruction 4 — independent integration review: Reject

The fresh independent integration review compared Piece D candidate
`bf5926e3bba9afca394baf669f95c72506886056` with approved D-M3-A+ tip
`9ba2bdd468be32d1de36f7ee7cd9d1607949dc6a` and recorded **Reject: 0 Critical, 1 High, 0 Medium,
1 Low**. The exact candidate delta is limited to
`tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs`, this file, and
`docs/PROJECT-STATE.md`; no migration, DDL, `src/`, Designer, ModelSnapshot, script, importer, O5,
baseline, or pin path changed.

All eight accepted migration/SQL blobs match base, candidate, and worktree exactly, with the IDs
listed in the candidate evidence below. The extracted `RejectTerminalDOCFLGMutationFn` also matches
base, candidate, and `HEAD` byte for byte: **1,099 normalized bytes**, SHA-256
`398fe93dc5f2dadfa9bbc87ccd7a12b8886cfcb90fe99a8f51ae9107d1f8855c`.

Independent reproduction measured Release build **0 warnings / 0 errors**; ordinary **646/646**
on a fresh rerun after the current Debug build; registry **33/33**; focused Piece D **6/6**; the
exact seven mapped regressions **7/7**; and the full
`scripts/run-p11a-disposable-tests.ps1` PostgreSQL 17 suite **61/61**. Working and cached diff checks
were clean, and cleanup left **0 residual / 0 running** `sibyla-p11*` containers.

The review records binding **High D-R1**: the combined S0→S1→S2→S3 test calls
`EnsureMigrated(full tip)`, then migrates down to P1-1a and captures S0. S0 is therefore produced by
the candidate `Down`, not by an independent pristine accepted-P1-1a oracle; S2 is merely a second
execution of the same `Down`. `Assert.Equal(S0, S2)` can pass if every `Down` leaves identical
residue, so checklist item 3 Phase 2 — post-Down equals accepted P1-1a exactly — is not proven. This
central proof-strength failure is not waived by green tests.

Binding **Low D-R2** records that item 4 compares `ImportEvidenceRow` helper outputs at S0–S3 but
the combined method does not assert cardinality four or the four exact definitions; equal empty or
partial sets could pass. The pre-existing Piece A test does assert count 4 and all four exact
definitions and passes within the 61/61 full runner, and the complete catalog snapshot also includes
constraints and indexes. That mitigation makes D-R2 Low, while leaving Piece D item 4's own literal
all-four assertion incomplete.

Confirmed non-findings remain: Option A is otherwise correctly shaped; D-M2-A returns exact `23503`
plus `DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`, with the imported Open `NULL` /
`MATCH SIMPLE` proof correct; D-M3-A+ proves first append, no matching audit, unchanged same
provenance, exact second overwrite failure `23514` / `terminal DOCFLG rows are append-only`, exact
terminal-row append-only behavior, value checkpoint, and transaction rollback; and the effective
writer roster shape is correct under the approved mapping.

**Disposition:** Piece D is **Rejected** and stopped. Passing tests do not overcome D-R1. Per the
governing instruction, no remediation is authorized or performed. Scope 1 remains unauthorized,
item 5 remains deferred to Scope 1, O5 remains the only project-open item, and no merge is authorized
or performed.

## 2026-08-07 Piece D ordered instruction 3 — candidate implementation and measured evidence

Ordered instruction 3 only was executed from pushed D-M3-A+ approval tip
`9ba2bdd468be32d1de36f7ee7cd9d1607949dc6a`. Immediately before editing, the root was
`D:/fileStorage/repos/GOTT.Sibyla`, the branch was `feature/p1-1b`, local `HEAD`, fetched
`origin/feature/p1-1b`, and live `ls-remote` all equalled that SHA, divergence was `0/0`, status and
staging were empty, and only the primary worktree was registered.

### Amendment-4 preflight, fresh and read-only

Checks 1–5 passed against `D:/fileStorage/repos/invoice-skill-build`: pin
`b91768513fc638381fbde91f0b576b08220a98f6` resolved locally and through fetched `origin/main`, was
an ancestor of live `origin/main`, and equalled local clone `HEAD`; the effective roster (substituting
only `Editor/Data/entbnk.json` to `70d418f6023bff68f0d642b4aff26c1ead1298be`) measured **49/49,
0 mismatches**; the direct pinned `Editor/Data` surface measured **48/48, 0 missing, 0 extra**,
excluding `Backups`. Check 6 recorded metadata only: live tip
`3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`; post-pin commits `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`
(*Apply Stage 10 Round 8 revenue review updates*) and
`1e841a4f9a88cd6a5e90e6632dff54185be9949e` (*Complete Stage 10 Round 8 reconciliation and mapping
updates*). **No post-pin content was read or adopted.**

### Item-8 TDD RED → GREEN

The exact D-M3-A+ standalone test
`Piece_d_owner_level_forged_evidence_guc_bypasses_reject_terminal_docflg_mutation_is_reproduced`
was authored first. Its initial run produced genuine expected RED: compilation failed only with
three `CS0103` references to the deliberately still-missing provenance snapshot harness. The
minimum deterministic snapshot was then added and the same test passed **1/1** on fresh PostgreSQL
17. The final test keeps those queries inline so the approved inventory remains six tests plus one
shared helper. In one rolled-back transaction it proves an imported `Resolved` row with initially
`NULL` evidence accepts the matching-forged-GUC first append with every other column unchanged,
creates exactly zero matching `P11aCommandAudit` rows, preserves the same single byte/value-identical
`ItemClass` provenance row, then rejects the second overwrite with SQLSTATE `23514` and exact message
`terminal DOCFLG rows are append-only`, leaving the first value intact.

### Checklist 1–8 evidence map, as amended

1. **Preflight and surface:** the six checks above passed and the eight-file byte-identity test
   passed. Exactly three paths are changed: this file, `docs/PROJECT-STATE.md`, and
   `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs`. No migration, DDL, `src/`,
   Designer, ModelSnapshot, script, importer, Scope 1, O5, shared/live database, or prototype path
   changed.
2. **Complete deterministic snapshot:** `PieceDCumulativeCatalogSnapshot` dynamically enumerates
   all non-system schemas and their relations, live columns/types/defaults/generation/nullability/
   ACLs, owners, schema ACLs, roles/attributes/memberships, constraints and exact definitions/
   deferrability, indexes, governed triggers, functions/procedures with owners/expanded ACLs/
   security/search-path/signatures/results/language/exact definitions, and EF history. Complete
   logical and separately emitted physical artifacts were each deterministic at fixed state; no
   curated roster or lossy count is the equality oracle.
3. **Combined S0→S1→S2→S3:** the one mapped test passed. S0 logical+physical equalled S2;
   complete logical S1 equalled S3; S0 differed from S1. Under Option A physical diagnostics were
   excluded only from S1/S3 logical equality and emitted separately. Fresh diagnostics measured
   `DOCFLG.ImportEvidenceRowId`/`ImportTargetTable` at attnums **30/31 at S1** and **32/33 at S3**;
   S1 physical SHA-256 was
   `fa5e9bff9eac8ec62a3873ea1295e628cede7e06732e2f1269fbb9464f10bbfa`.
4. **R7:** inside that same combined method/run, all four exact `ImportEvidenceRow` UNIQUE
   definitions and backing index definitions were identical at S0, S1, S2, and S3.
5. **Real baselines:** no Piece D test or claim was authored. The real 119 / 119 / 52 / 221 /
   2,787 population and two `Routine` rows remain deferred to Scope 1; no synthetic count theatre.
6. **Unknown `ItemClass`:** the new native/imported `DOCFLG` test passed in D-M2-A form. Each
   active-company row began `Open`; each single atomic Open→Resolved update set `ItemClass='Bogus'`
   plus evidence/resolver/time and failed with exact SQLSTATE `23503` and exact constraint
   `DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`; the imported Open NULL/MATCH SIMPLE
   row remained allowed. The company-scoped validator test passed with one in-scope absent DOCEFL
   finding and one absent DOCFLG finding and proved no placeholder coercion.
7. **Full envelope:** clean Release rebuild **0 warnings / 0 errors**; ordinary **646/646**;
   registry **33/33**; focused Piece D **6/6**; exact seven regressions **7/7**; repository full
   disposable runner **61/61** on PostgreSQL 17; working and cached `git diff --check` clean; exact
   path/claim equality; added code secret scan **0 matches**; Docker cleanup **0 residual / 0
   running** `sibyla-p11*` containers.
8. **Direct-DML boundary:** the combined method measured identical complete effective-role rosters
   at S1 and S3 using PostgreSQL's effective table/column privilege functions; every non-owner/
   non-superuser role, including `sibyla_piece_c_executor`, had all six direct `DOCFLG` DML routes
   false. The standalone owner probe reproduced the known first-append limitation and the stricter
   no-overwrite boundary exactly as D-M3-A+ requires.

The six focused tests were
`Piece_d_all_accepted_migration_files_remain_byte_identical_before_during_and_after`,
`Piece_d_cumulative_catalog_snapshot_is_complete_deterministic_and_set_based`,
`Piece_d_combined_cumulative_up_down_up_over_a_plus_b_plus_c_matches_accepted_p1_1a_and_is_stable`,
`Piece_d_docflg_unknown_non_null_item_class_is_rejected_transitively_by_the_composite_docefl_fk_native_and_imported`,
`Piece_d_registry_validator_flags_absent_item_class_and_never_a_placeholder_post_cumulative_up`,
and `Piece_d_owner_level_forged_evidence_guc_bypasses_reject_terminal_docflg_mutation_is_reproduced`.

The exact seven separately executed regressions all passed: the four
`RegistryValidationServiceTests` imported/native × DOCEFL/DOCFLG unknown-`ItemClass` methods;
`Piece_a_reports_all_five_honest_historical_completeness_findings`;
`Piece_c_assign_item_class_rejects_unknown_item_class_literal`; and
`Piece_c_assign_item_class_enforces_the_closed_d8_vocabulary_at_the_command_boundary`.

### Immutable accepted-object proof

Before and after implementation and the full envelope, `HEAD` and working-tree blob IDs matched:

| Path | Blob ID |
|---|---|
| `20260805180000_P11aFdrSchema.cs` | `497ce4ecbe63aa2c5fd7dd6eb2bcac01c6b48d0e` |
| `P11aSchemaSql.cs` | `74c5912cc85aebd99c1169a27217c67aa1955476` |
| `20260806180000_P11bPieceASchemaCompleteness.cs` | `a5ff78040a83440c771dc1b1ddde3c873bc88161` |
| `P11bPieceASchemaSql.cs` | `00b4bc2a988e1a54a5e2719d0fbc4814690d3782` |
| `20260806190000_P11bPieceBRegistryFieldProvenance.cs` | `d0beb8aafa78dc158318e6101277023f758edfaa` |
| `P11bPieceBSchemaSql.cs` | `bc9d958258a2715c23bb435868134a5d160bc9a3` |
| `20260806200000_P11bPieceCGovernedCommands.cs` | `0a111d0c981680f838dbcbbef1560cbce3eb77ba` |
| `P11bPieceCSchemaSql.cs` | `398887002499404c80b9509564fd4369ac93a371` |

The last blob contains the accepted `RejectTerminalDOCFLGMutationFn`; its extracted definition was
also compared directly between `HEAD` and the working tree and was byte-identical: both normalized
definition SHA-256 values were
`398fe93dc5f2dadfa9bbc87ccd7a12b8886cfcb90fe99a8f51ae9107d1f8855c` (1,099 characters). No
accepted object changed.

**Disposition:** a Piece D ordered-instruction-3 candidate now exists, but it is **NOT accepted**.
Ordered instruction 4 has **not begun** and must run in a fresh independent session. Scope 1 remains
unauthorized, item 5 remains deferred to Scope 1, and O5 is unaffected and remains the only
project-open item.

## 2026-08-07 Piece D D-M3-A+ mapping amendment — Miguel's approval recorded; D-M3 closed

This is a governed records-only entry. Miguel decided D-M3 with this exact approval sentence,
recorded verbatim:

> Aprovo D-M3-A+

This selects **D-M3-A+** as the binding amendment to Piece D item 8's standalone owner-level
forged-GUC probe. Its fixture is an imported `DOCFLG` row (`ImportEvidenceRowId IS NOT NULL`), is
terminal (`Status='Resolved'`), and begins with `ResolutionEvidence IS NULL` under the accepted
O9-D5 historical exemption. In one transaction that is rolled back, the probe must prove two
ordered assertions: first, a direct `UPDATE` from `NULL` to a non-null evidence value succeeds while
the forged `sibyla.docflg_evidence_append_id` matches `FlagInstanceID`; second, while that same
forged GUC remains set, a direct `UPDATE` attempting to replace the now-populated evidence fails
with SQLSTATE `23514` and exact message `terminal DOCFLG rows are append-only`.

The first update is the real accepted bypass, contained only by the item-3/item-8 effective roster
proving zero non-owner/non-superuser direct `DOCFLG` DML reachability. The second proves that bypass
is limited, by accepted design, to one first append and permits no overwrite. The existing exact
post-state assertions remain binding at their correct checkpoints: the raw direct first append
creates no `P11aCommandAudit` command row; `RegistryFieldProvenance` remains the same single
`ItemClass` provenance row unchanged; and the failed second update leaves the first appended value
intact. The entire transaction is rolled back.

D-M3 is closed. Piece D still has no candidate and has not received an Accept. No accepted object
changes: `RejectTerminalDOCFLGMutationFn` remains byte-identical. Ordered instruction 3 TDD is
re-authorized only after the exact three-path records commit containing
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-mapping-amendment-c-approval.md`, this file, and
`docs/PROJECT-STATE.md` is independently reviewed, committed, and pushed; TDD then starts fresh
from that pushed tip. Scope 1 remains unauthorized pending Piece D's fresh independent Accept, and
O5 remains the only project-open item. No migration, DDL, `src/`, test, fixture implementation,
helper, importer, Scope 1, O5, shared/live database, container, stage, commit, or push action is
authorized or performed by this records entry. No merge is authorized or performed.

The immediately following D-M3 stop remains intact as historical evidence. This entry and the
operative item-8 mapping below supersede it only for current execution authority.

## 2026-08-07 Piece D D-M2-A ordered instruction 3 — item-8 collision, clean stop at D-M3

This is the governed clean-stop record of the latest Piece D TDD attempt from starting tip
`9c3a0c19eccbce9a4d9b97d303a8b8f584af4442`. Amendment-4 preflight passed fresh: the effective
roster measured **49/49** and the direct pinned surface measured **48/48**. The six-test focused
Piece D progression reached **5/6 green**, including item 6 in its approved D-M2-A form.

The standalone item-8 test then failed with SQLSTATE `23514` and exact message
`terminal DOCFLG rows are append-only`. The accepted `RejectTerminalDOCFLGMutationFn` exception
requires `OLD."ResolutionEvidence" IS NULL AND NEW."ResolutionEvidence" IS NOT NULL`, together
with an imported terminal row, a forged `sibyla.docflg_evidence_append_id` matching
`FlagInstanceID`, and every other column unchanged. The then-approved literal fixture instead began
terminal with `ResolutionEvidence` already populated and attempted to overwrite it. Its expected
successful overwrite is therefore impossible without a new decision. The accepted function was not
weakened, and the test expectation was not changed silently. This is gate/stop **D-M3**, not a
candidate.

### D-M3 measured clean-stop disposition

The parent operator measured the disposition live at starting tip
`9c3a0c19eccbce9a4d9b97d303a8b8f584af4442`:

- worktree status and staging were empty; `git diff --check` was clean;
- `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` had identical `HEAD` blob and
  worktree hashes, both `06bcc991e0cac6ff43697251ae131a1c97063d22`, proving byte-identical
  transient-edit removal;
- all eight accepted migration/SQL paths matched their `HEAD` blobs, with **0 mismatches**;
- no commit followed the starting tip and **0 `src/`/`tests/` paths changed after it**;
- Docker reported **0 residual** and **0 running** `sibyla-p11*` containers; and
- the Git worktree registry contained only `D:/fileStorage/repos/GOTT.Sibyla`; the prior
  `D:/fileStorage/repos/GOTT.Sibyla-piece-d` path was absent.

These are measured disposition facts, not assumptions. No Piece D candidate exists. No migration,
DDL, accepted-object, `src/`, test, fixture implementation, helper, importer, Scope 1, O5,
shared/live database, or container work survived the stopped attempt. D-M3 required Miguel's
explicit amendment before any Piece D TDD could resume.

## 2026-08-07 Piece D D-M2-A mapping amendment — Miguel's approval recorded; D-M2 closed

This is a governed records-only entry. Miguel decided D-M2 with this exact approval sentence,
recorded verbatim:

> Aprovo D-M2-A

This selects **D-M2-A** exactly as published below under "D-M2 alternatives for Miguel's
decision" and makes it the binding amendment to Piece D mapping item 6. The native and imported
proof rows for an active company each start `Open`; each performs exactly one atomic Open→terminal
`UPDATE` setting `ItemClass='Bogus'` together with `Status='Resolved'`, `ResolutionEvidence`,
`ResolvedBy`, and `ResolvedAt`; every orthogonal CHECK and prerequisite, including provenance
prerequisites, is satisfied; and each rejection asserts SQLSTATE `23503` plus exact constraint name
`DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`. The separate NULL/`MATCH SIMPLE`
proof targets remain on an imported `Open` row. The company-scoped validator test expectation
repair is ordinary item-6 scope under this amendment, not a separate decision.

D-M2 is closed. Piece D still has no candidate and has not received an Accept. Ordered instruction
3 TDD is re-authorized only after the exact three-path records commit containing
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-mapping-amendment-b-approval.md`, this file, and
`docs/PROJECT-STATE.md` is independently reviewed, committed, and pushed; TDD then starts fresh
from that pushed tip. Scope 1 remains unauthorized pending Piece D's fresh independent Accept, and
O5 remains open. No implementation, migration, DDL, `src/`, test, fixture, script, importer,
database, container, shared/live operation, O5 content, project-evolution, stage, commit, push,
merge, rebase, or reset action occurred in this authoring pass.

The immediately following D-M2 stop and its three alternatives remain intact as historical
evidence. This entry and the operative item-6 mapping below supersede them only for current
execution authority.

## 2026-08-07 Piece D Option A ordered instruction 3 — new item-6 collision, clean stop, Miguel decision required

This is the governed record of the fresh Codex TDD attempt from pushed approval tip
`6554a8ed71fb0992b198e4b9d2e2e276d62b9cd4`. The hard initial state passed exactly: repository
root `D:/fileStorage/repos/GOTT.Sibyla-piece-d`; detached `HEAD`, freshly fetched
`origin/feature/p1-1b`, `FETCH_HEAD`, and live `ls-remote` all equalled that SHA; the worktree was
clean; standalone Codex authentication reported `Logged in using ChatGPT`.

The amendment-4 preflight then passed fresh and read-only. Pin
`b91768513fc638381fbde91f0b576b08220a98f6` resolved, remained an ancestor of live
`origin/main`, and equalled the prototype clone's local `HEAD`. The effective O8 roster measured
**49/49 resolved, 0 mismatches** and the direct pinned `Editor/Data` surface measured **48/48,
0 missing, 0 extra**. The first roster script honestly produced one mismatch because it parsed the
retained pre-C8 `entbnk.json` blob instead of applying the adjacent governed substitution; after
reading that substitution rule and replacing only `entbnk.json`'s expected blob with
`70d418f6023bff68f0d642b4aff26c1ead1298be`, the required effective roster passed 49/49. Check 6
read metadata only: live tip `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`, with post-pin
commits `3dd4150…` (`Apply Stage 10 Round 8 revenue review updates`) and `1e841a4…` (`Complete
Stage 10 Round 8 reconciliation and mapping updates`). No post-pin content was read or adopted.

### Measured vertical TDD evidence

- The first complete logical/physical snapshot slice had two genuine RED query defects: PostgreSQL
  `42703` because the `user_schemas` CTE omitted `nspowner`/`nspacl`, then `42725` because catalog
  `"char"` fields required explicit text casts. After those two narrow corrections, item 2 passed
  **1/1** in **8.7137s**, proving both complete dynamically enumerated logical state and separate
  live-column `ordinal_position`/`attnum` diagnostics deterministic at a fixed state.
- Item 1's first execution was a genuine RED because VSTest's process working directory was not the
  repository root, so its Git pathspec returned no entry. Anchoring Git from `AppContext.BaseDirectory`
  fixed only that harness defect; the eight-file blob/working-tree identity proof then passed
  **1/1** in **9.6066s**.
- The single combined item-3 method — with item 4 uniqueness/index assertions and item 8's dynamic
  effective-writer roster folded into the same S0→S1→S2→S3 run — passed on its first execution,
  **1/1** in **8.8943s**. It proved complete logical S1==S3, exact logical+physical S0==S2,
  S0!=S1 sensitivity, all four `ImportEvidenceRow` UNIQUE/index definitions unchanged at every
  checkpoint, and identical S1/S3 effective-writer rosters with zero non-control-plane direct
  `DOCFLG` writers. Fresh physical diagnostics showed
  `DOCFLG.ImportEvidenceRowId`/`ImportTargetTable` at attnums **28/29 in S1** and **30/31 in S3**;
  S1's physical-artifact SHA-256 was
  `90a2da0c1a1360d08e3ae88373a52725dd43538e4ccfa442e5dd9c724b06b045`. These fresh values are
  observations, not universal allocator constants.
- The two item-6 tests then ran together and produced **0 passed / 2 failed**, total test time
  **8.1961s**. The validator test's expected two DOCEFL findings measured one because the validator
  is company-scoped. That is an ordinary, repairable test-fixture expectation within existing item-6
  scope once D-M2 is approved, not a separate governance decision; it was not continued after the
  governing collision. The governing failure was the exactly mapped native `DOCFLG` direct-UPDATE
  proof. For a valid ACTIVE-company row — the only non-vacuous fixture for this mapping — the
  exhaustive `Status` partition cannot reach the composite DOCEFL FK: `Open`/`InReview` with an
  unknown non-null `ItemClass` is rejected first by the accepted P1-1a lifecycle CHECK
  `CHECK (NOT ("Status" IN ('Open','InReview') AND "ItemClass"<>'Decision'))` as `23514`, while
  `Resolved`/`Superseded`/`Waived` mutation is rejected first as `23514` by Piece C's accepted
  replacement of `RejectTerminalDOCFLGMutationFn`. A nonterminal row in an inactive company can
  instead return `23503` early from `RequireActiveCompanyRegistryFn`, but that is the wrong object
  and cannot satisfy the composite-FK proof: SQLSTATE alone would make this anti-vacuity trap look
  like success. Any amended proof expecting `23503` must assert both SQLSTATE and exact constraint
  name `DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`, because other foreign keys and
  triggers also return `23503`. The prospective fixture already satisfied
  `CK_DOCFLG_ProspectiveSnapshot`, and its `SourceTextHash` satisfied the accepted `md5-12` shape;
  neither approved fixture correction can remove this higher-priority accepted-object collision.

The active-company native `23514` collision above was empirically observed by this Codex TDD
attempt. The subsequent fresh independent review was static/read-only: it confirmed the governing
collision and that the alternatives below are publishable, but did not independently reproduce the
database observation.

### D-M2 alternatives for Miguel's decision

No alternative below changes an accepted object, migration, or DDL.

- **D-M2-A (recommended):** retain the approved test name and matrix, but make the native and
  imported active-company proof rows each start Open and perform one atomic Open→terminal `UPDATE`
  that changes `ItemClass='Bogus'` together with `Status='Resolved'`, `ResolutionEvidence`,
  `ResolvedBy`, and `ResolvedAt`. Satisfy every orthogonal CHECK and provenance prerequisite. Assert
  SQLSTATE `23503` **and** exact constraint name
  `DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`. Keep the separate NULL/`MATCH SIMPLE`
  proof targets as an Open imported row. This preserves both the mutation proof and the matrix.
- **D-M2-B:** use a direct terminal `INSERT` for native and imported rows with every orthogonal
  prerequisite satisfied; assert the same `23503` and exact constraint name, and rename the test and
  matrix to state that the proof is on insert. This is weaker than A because it proves a write, not
  mutation.
- **D-M2-C:** accept the empirically observed `23514` fail-closed lifecycle barrier and rename and
  rewrite the matrix accordingly. This is explicitly weaker, supplies no direct executable proof of
  the composite FK, and is not recommended.

### Stop disposition

This is a new literal checklist/accepted-object collision, so the instruction to stop rather than
self-authorize governs. Changing the mapped native UPDATE to an INSERT, changing the expected
constraint/SQLSTATE, or altering/bypassing an accepted CHECK/trigger would change the approved
proof or accepted objects. None was done. Item 8's standalone owner probe, the seven mapped
existing regressions, and the final verification envelope were not started after the stop.

All transient changes to `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` were
removed byte-for-byte; no migration, SQL, `src/`, Designer, ModelSnapshot, importer, harness,
script, O5, Scope 1, shared/live database, stage, commit, or push action occurred. **No Piece D
candidate exists.** New gate **D-M2** requires Miguel to amend and re-approve item 6's native
schema proof by choosing D-M2-A, D-M2-B, D-M2-C, or another explicit resolution before any Piece D
implementation item resumes. Item 5 remains deferred to Scope 1; Scope 1 remains unauthorized. O5
continues independently on its disjoint surface.

## 2026-08-07 Piece D Option A mapping amendment — Miguel's approval recorded; D-M1 closed

This entry performs the governed records-only approval stage for
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-mapping-amendment-a-approval.md`. Miguel's exact approval
sentence is recorded verbatim:

> Aprovo a opção A e o mapping Piece D revisto

Miguel thereby selects **Option A** exactly as published in the governing stop below and closes
D-M1. Physical `ordinal_position` / PostgreSQL `pg_attribute.attnum` remains dynamically captured,
deterministic, and reported as a separate physical diagnostic artifact. It is excluded **only**
from the S1/S3 logical-equality tuple. Every other governed logical catalog property remains in the
complete dynamically enumerated equality oracle: there are no curated table/function/role lists and
no lossy count substitution.

S0/S2 remains the exact P1-1a restoration proof, including physical metadata where applicable.
S1/S3 compares the complete logical state, while the physical diagnostics for both states are
emitted and any drift remains visible rather than normalized away. The measured
`DOCFLG.ImportEvidenceRowId` S1=`30` / S3=`32` `attnum` is retained as historical empirical
evidence, not imposed as a universal allocator constant unless the test observes it fresh. Item 2's
determinism proof now covers both the logical snapshot and the separate physical diagnostic at a
fixed state.

Every other Piece D mapping item remains exactly as previously approved. There is no migration,
DDL, `src/`, Designer, ModelSnapshot, baseline, pin, O8/O9/O10, item 5, Scope 1, or O5 decision
change. Item 5 remains deferred to Scope 1. Scope 1 remains unauthorized until Piece D receives a
fresh independent **Accept**.

Ordered instruction 3 is re-authorized only after the exact three-path records commit is
independently reviewed, committed, and pushed. TDD must start fresh from that pushed tip. Until
those records conditions are complete, no Piece D implementation item resumes.

The stop record immediately below is preserved intact as historical evidence. It is superseded
**only for implementation authority** by this explicit Option A amendment; its measurement,
cleanup, blob IDs, failed-test evidence, and account of why the prior authority required a stop
remain authoritative historical evidence.

## 2026-08-07 Piece D ordered instruction 3 — measured mapping collision, clean stop, Miguel decision required

This is the governed record of the authorized Codex TDD attempt of ordered instruction 3 from the
pushed Piece D mapping-approval tip. The approved mapping was implemented only far enough to measure
its literal contract. That measurement found a deterministic collision between approved checklist
items 2 and 3 and the accepted, immutable Piece A migration. The attempt stopped immediately; every
transient implementation/test edit was removed. **No Piece D implementation candidate exists. No
mapping amendment or migration remediation is selected or authorized by this record.**

### Amendment-4 preflight and immutable-source evidence

- Pin `b91768513fc638381fbde91f0b576b08220a98f6` resolved, was an ancestor of `origin/main`, and the
  prototype clone's `HEAD` equalled the pin.
- The effective O8 roster measured **49/49, 0 mismatches**; the pinned direct `Editor/Data` surface
  measured **48/48, 0 missing and 0 extra**.
- Check 6 inspected metadata only and recorded
  `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` (`Apply Stage 10 Round 8 revenue review updates`) and
  `1e841a4f9a88cd6a5e90e6632dff54185be9949e` (`Complete Stage 10 Round 8 reconciliation and mapping
  updates`). No post-pin content was read or adopted.

### TDD evidence and governing hard stop

The initial focused RED compile failure was genuine: two transient test-code references used the
nonexistent `RegistryValidationResult.FindingIds`. The disposable container used for that run was
removed. After correcting only that transient compile defect, the second focused disposable
PostgreSQL 17 run discovered **6 Piece D tests: 2 passed, 4 failed**, total test time **15.7404s**.

The following two tests passed immediately and are recorded honestly as passes, not fabricated RED:

- `Piece_d_all_accepted_migration_files_remain_byte_identical_before_during_and_after`
- `Piece_d_cumulative_catalog_snapshot_is_complete_deterministic_and_set_based`

The governing failure was the approved item-3 equality assertion. `snapshotS0 == snapshotS2`
passed, but `snapshotS1 == snapshotS3` failed. The first exact mismatch was
`DOCFLG.ImportEvidenceRowId`: physical ordinal/`attnum` **30 at S1** and **32 at S3**. Accepted Piece
A `Down` drops `DOCFLG.ImportTargetTable` and `DOCFLG.ImportEvidenceRowId`; PostgreSQL retains the
dropped-column attribute-number slots, so the second `Up` re-adds those columns after those slots.
The approved item-2 snapshot explicitly includes `ordinal_position`, and item 3 literally requires
exact `snapshotS1 == snapshotS3`. Omitting or normalizing physical ordinals would weaken the
approved mapping; changing accepted migration content is forbidden by Piece D's no-migration scope.
This is therefore a literal item-2/item-3 mapping collision requiring Miguel's explicit amendment,
not an implementation detail this attempt may self-remediate.

The other three failures were repairable transient fixture/test issues, but work did not continue
after the governing stop: a native prospective `DOCFLG` fixture with `NULL` snapshot fields hit
`CK_DOCFLG_ProspectiveSnapshot`; an authored `SourceTextHash` was invalid in a `DOCFLG` FK fixture;
and Npgsql rejected a parameterized multi-statement owner probe. They do not supersede, soften, or
independently reproduce the governing S1/S3 collision.

### Item-by-item stop state

| Item | State at clean stop |
|---|---|
| 1 | Preflight and eight-file blob identity passed. |
| 2 | Transient determinism/complete-roster test passed. |
| 3 | **Blocked** by the measured `attnum` 30→32 S1/S3 collision. |
| 4 | Captures occurred, but assertions were not reached. |
| 5 | Remains deferred to Scope 1; no test, exactly as approved. |
| 6 | RED reached; fixture correction and the seven mapped regressions were not continued after the hard stop. |
| 7 | Full verification envelope was not run because of the hard stop. |
| 8 | Roster was captured; assertions and the corrected owner probe were not completed. |

All eight accepted migration/SQL files remained byte-identical throughout:

| Accepted file | Blob ID |
|---|---|
| `20260805180000_P11aFdrSchema.cs` | `497ce4ecbe63aa2c5fd7dd6eb2bcac01c6b48d0e` |
| `P11aSchemaSql.cs` | `74c5912cc85aebd99c1169a27217c67aa1955476` |
| `20260806180000_P11bPieceASchemaCompleteness.cs` | `a5ff78040a83440c771dc1b1ddde3c873bc88161` |
| `P11bPieceASchemaSql.cs` | `00b4bc2a988e1a54a5e2719d0fbc4814690d3782` |
| `20260806190000_P11bPieceBRegistryFieldProvenance.cs` | `d0beb8aafa78dc158318e6101277023f758edfaa` |
| `P11bPieceBSchemaSql.cs` | `bc9d958258a2715c23bb435868134a5d160bc9a3` |
| `20260806200000_P11bPieceCGovernedCommands.cs` | `0a111d0c981680f838dbcbbef1560cbce3eb77ba` |
| `P11bPieceCSchemaSql.cs` | `398887002499404c80b9509564fd4369ac93a371` |

### Clean stop and independent read-only review

After transient cleanup, the worktree had **zero changed or staged paths**, `git diff --check` was
clean, and there were **zero residual `sibyla-p11*` containers**. Accordingly, there is no candidate
to review, accept, reject, neutralize, or resurrect.

A fresh independent Claude CLI review in read-only Plan Mode confirmed from the approved documents,
Piece A SQL, and PostgreSQL semantics that the collision is deterministic and that no compliant
implementation exists under the current authority. It classified the approved mapping defect as
Reject-worthy High and recommended Option A below over Option B. It **did not independently
reproduce the measured 30/32 values**, because its mode permitted read-only inspection only; this
record does not overstate that review as a second empirical reproduction.

### Exact Miguel decision required — no option adopted here

- **Option A — recommended:** amend items 2 and 3 so physical `ordinal_position`/`attnum` is still
  captured and reported diagnostically but is excluded from the S1/S3 equality tuple. Retain every
  logical column property and the complete dynamically enumerated object coverage. This preserves
  the mapping's logical catalog-equivalence proof while making the accepted PostgreSQL drop/re-add
  semantics visible rather than normalizing them away silently.
- **Option B — not recommended:** reopen the accepted Piece A migration to preserve `attnum`. This
  requires separate authority and violates Piece D's current no-migration scope.

**Implementation remains stopped on all eight items until Miguel explicitly chooses a resolution
and re-approves the amended mapping.** Scope 1 remains unauthorized. O5 continues independently on
its own disjoint authority and surface. Per the same-commit record rule, this stop record and the
corresponding current-state correction in `docs/PROJECT-STATE.md` move together.

## 2026-08-07 Piece D test-plan gate — Miguel's approval recorded

This entry performs the Records instruction of
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-mapping-approval.md`. It records Miguel's explicit approval of
the twice-corrected Piece D checklist→test mapping below, decides both reported observations, and
authorizes ordered instruction 3 only after this three-path records commit is pushed. Miguel's
operative sentence is recorded verbatim:

> "Aprovo o mapping Piece D na íntegra: itens 1, 2, 3, 4, 6, 7 e 8 como escritos; aprovo a
> Observação 2 — a lista correta é de oito ficheiros de migração, não seis, e a questão dos
> ficheiros Designer/ModelSnapshot fica fora do âmbito deste item; **decido e emendo o checklist do
> go-ahead pela Observação 1, opção (b): o item 5 fica formalmente fora do Accept do Piece D, a
> confirmação da população real das cinco baselines e das duas linhas Routine fica diferida para o
> Scope 1, e o checklist de oito itens fica assim integralmente fechado — só agora autorizo o
> início da implementação de todos os itens 1–4 e 6–8, e do item 5 conforme reformulado.**"

### Decision: approved in full, with both observations decided by name

1. **Observation 1 — option (b), real-population confirmation deferred to Scope 1.** Checklist
   item 5 is formally carved out of Piece D's Accept. Piece D authors no synthetic population to
   imitate the five baselines, claims no confirmation of the real governed population, and records
   no test for item 5. Scope 1 carries the real-population confirmation when import creates the
   governed rows. This closes item 5 for Piece D; it does not leave implementation partially
   authorized or the checklist open.
2. **Observation 2 — alternative (i), eight migration files.** Item 1's byte-identity assertion
   covers the measured roster of eight accepted migration/SQL files, two for each of P1-1a and
   Pieces A, B, and C. The single Designer file and shared ModelSnapshot are explicitly outside
   this assertion's roster and may not be changed or silently added to it.

Items 1, 2, 3, 4, 6, 7, and 8 are approved exactly as written in the twice-corrected mapping. The
approved inventory remains **6 new tests + 1 helper, 2 strengthened tests, 7 existing regressions
re-run, 14 verification commands, and no test for item 5**. Ordered instruction 3 is now
authorized, TDD first, from the pushed approval tip: test/harness/helper and the two records files
only; no migration content, no `src/` change, no importer or Scope 1 work, and no shared/live
database write. Scope 1 remains unauthorized until Piece D's independent integration review records
Accept.

### Verification of this approval records stage

| Verification | Result |
|---|---:|
| Paths committed together | exactly **3** — this approval document, `docs/p1-1b-status.md`, and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, fixture, helper, or test paths changed | **0** |
| Prototype, database, or container operations | **0** |
| Baselines / pin / O8–O10 decisions changed | **0** |

No build or test result is claimed for this documentation-only approval stage.

## 2026-08-07 Piece D go-ahead — acceptance recorded

This step performs the records portion of **ordered instruction 1 of
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md`**, which requires tracking the go-ahead document and
recording its acceptance in this file and in `docs/PROJECT-STATE.md` **in the same records commit**,
pushed before any test-plan/mapping work begins. This governed records commit's exact scope is
three paths, tracked and committed together, no other path: the go-ahead document itself
(`docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md`, dated 2026-08-06), `docs/p1-1b-status.md`, and
`docs/PROJECT-STATE.md`. The unrelated O5 files (`deploy/o5/`, `scripts/run-o5-acceptance.ps1`) are
outside this piece's scope, remain untracked, and were neither read nor touched by this step.

Live Git state verified fresh rather than trusted before authoring this commit: local `HEAD` =
`origin/feature/p1-1b` = `01f625a2ad166a72edfbea6823cc8e56b5c8e574`, tree otherwise clean aside from
the go-ahead document (tracked by this same commit) and the unrelated, untouched O5 files noted
above.

**Authority and content, restated from the go-ahead.** Piece C has a recorded independent Accept —
candidate `ce983b2cb1397f53ec5dbe47d5b568cb025288ec`, verdict 0 Critical / 0 High / 0 Medium / 0
Low, recorded in `docs/p1-1b-o10-independent-review.md` ("Piece C candidate review — Accept") and
in this file, at the commit recording that verdict, `01f625a2ad166a72edfbea6823cc8e56b5c8e574`. Per
amendment 3, `docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md` is Piece D's own go-ahead — its content
was pre-authorized by amendment 3, this document starts it. It reopens no decision. The five
baselines remain 119 / 119 / 52 / 221 / **2,787**; the two `Routine` rows still import verbatim; the
pin remains `b91768513fc638381fbde91f0b576b08220a98f6`.

**Accepted implementations, from the live records:** Piece A `f6f297b…`, Piece B `7059809…` (the
B-R1 remediation of rejected candidate `b8fa033…`, reviewed and accepted at `256da9c…`), and Piece C
`ce983b2…`, reviewed and accepted at `01f625a…`. Monolithic rejects `b324a3e…`, `57f0f023…`, and
`7ea6c0f…`, and piece candidates `6f86023d…` (Piece A Reject #1) and `b8fa033…` (Piece B Reject #1),
remain **neutralized evidence only** — never resurrected, never cherry-picked, not even in part.

**What this go-ahead authorizes, restated.** Piece C's Accept authorizes Piece D to seek its own
go-ahead; that go-ahead has now been given and is accepted. **Piece D may now start under amendment
3.** Piece D adds no new migration content — it is an integration gate verifying that Pieces A + B +
C together, run cumulatively on top of the accepted P1-1a catalog, are byte-exact-invertible and
complete. No production, shared, or live database write of any kind; no importer execution; no
Scope 1 work. **Scope 1 remains unauthorized until Piece D's own independent Accept.**

**Where Piece D now stands: the checklist→test mapping gate (ordered instruction 2), not yet
started.** The go-ahead's eight-item consolidated checklist — (1) preflight and exact allowed
surface, (2) R2 cumulative `pg_catalog` snapshot, (3) combined cumulative Up→Down→Up proof, (4) R7
end-to-end, (5) the five baselines in one single combined disposable run, (6) unknown `ItemClass`
fails closed end to end, (7) the full verification envelope, and (8) the roster/direct-DML
trust-boundary probe — has **not yet been mapped** to test methods or verification commands. **No
checklist→test mapping has been recorded. No implementation, test, harness, migration, database, or
container work of any kind has run under this go-ahead.** Per the go-ahead's own text, no code,
test, helper, migration, container, or database run may precede Miguel's explicit approval of that
mapping, and that approval has not been sought or given.

**What this step did and did not do.** Documentation only. This records commit's content is exactly
the go-ahead document, tracked as-is, plus these two records files — `docs/p1-1b-status.md` and
`docs/PROJECT-STATE.md`. No implementation, migration, model, constraint, trigger, role, grant,
test, fixture, importer, prototype, database, container, service, deployment, or live-data work
occurred. No checklist→test mapping work has begun. Scope 1 remains unauthorized pending Piece D's
own independent Accept. O5 remains the project's only other open item; no baseline, decision, or
O8/O9/O10 closure is changed by this step.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Paths this records commit tracks together | exactly **3** — the go-ahead document (`docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md`), `docs/p1-1b-status.md`, and `docs/PROJECT-STATE.md` — no other path |
| Implementation, migration, model, constraint, trigger, role, grant, fixture, or test paths changed | **0** |
| Checklist→test mapping work performed | **0** |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `01f625a2ad166a72edfbea6823cc8e56b5c8e574`, tree otherwise clean aside from the go-ahead document (tracked by this same commit) and the unrelated, untouched O5 files noted above |
| This commit's push timing | to be pushed before any checklist→test mapping work begins, per ordered instruction 1 |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. The last independently reproduced
figures remain those of the Piece C candidate review Accept record immediately below.

## 2026-08-07 Piece D test-plan gate — checklist→test mapping, adversarial feasibility assessment, and observations, awaiting Miguel's approval

This step performs the records portion of **ordered instruction 2 of
`docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md`** only: map each of the go-ahead's eight
consolidated checklist items to exact proposed test method(s)/verification commands, adversarially
assess feasibility before requesting approval, and report every ambiguity or contract collision as
a numbered Observation for Miguel's explicit decision — never resolved silently. **No
implementation, test, helper, migration, container, or database work of any kind has run to
produce this mapping.** Every proposed test name, helper name, migration ID, table/constraint/
function name, and command cited below was confirmed by direct read-only inspection of the live
accepted migrations and the live test project against the accepted records base inspected
immediately before this mapping — `1349155fd66a535def70d7c3b9828adb42256b10` (`docs(p1-1b): accept
Piece D go-ahead`) — stated as that inspected base, not as the branch tip, since this mapping's own
records commit necessarily advances the tip past it; not invented or assumed.

### Read-only inspection performed for this mapping

- `docs/PROJECT-STATE.md` (sole current-state authority, read in full before anything else).
- `docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md` (the go-ahead and its eight-item checklist, read
  in full).
- `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-5.md` (checklist discipline, proof-pattern annex,
  test-plan gate rules, read in full and quoted below where cited).
- `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-4.md` (the reformulated six-check prototype preflight,
  read in full).
- `docs/p1-1b-status.md` (Piece C's own test-plan-gate mapping and evidence map, used as the format
  precedent; the Piece A/B/C evidence-map rosters, used to ground the additive-base file/object
  inventory) and `docs/p1-1b-o10-independent-review.md` ("Piece C candidate review — Accept").
- `src/Sibyla.Infrastructure/Persistence/Migrations/P11aSchemaSql.cs`, `P11bPieceASchemaSql.cs`
  (read in full), `P11bPieceBSchemaSql.cs`, `P11bPieceCSchemaSql.cs`, and their four companion
  `Migration` wrapper classes — exact migration IDs, `ImportEvidenceRow`/`DOCFLG`/`DOCEFL` DDL,
  roles, grants, and functions.
- `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` (every existing `[Fact]` name,
  the three existing per-piece catalog-snapshot helpers, the `ImportEvidenceRow` constraint/index
  helpers, the migrator mechanism, the non-owner-probe-role helper, and the forged-GUC probe
  pattern).
- `tests/Sibyla.Tests/Persistence/P11bPieceCContractTests.cs`,
  `tests/Sibyla.Tests/Registry/RegistryValidationServiceTests.cs` (existing `ItemClass`-vocabulary
  validator regression tests, exact names).
- `scripts/run-p11a-disposable-tests.ps1`, `tests/Sibyla.Tests/Sibyla.Tests.csproj` (the single
  `Category=P11aDatabase` trait/filter mechanism; confirmed no separate PieceA/PieceB/PieceC/PieceD
  category exists or is needed).
- Repo-wide search for the literal baseline figures (`2787`, `221`, `52`, `119`), for any
  `Importer`/`ImportService`/`ImportPipeline` class, and for role-reachability helpers
  (`has_table_privilege`, `has_any_column_privilege`, `pg_auth_members`) — grounding Observation 1
  and item 8's design.

The unrelated untracked `deploy/o5/` and `scripts/run-o5-acceptance.ps1` were not read, staged, or
touched, per the go-ahead's own scope and the instruction governing this step.

### Correction pass — this mapping was not ready for Miguel's approval as originally recorded

A fresh independent review of this mapping's original draft found one Critical, two High, and two
Medium/Low findings, all applied below: (Critical) item 2's `pg_catalog` snapshot had been narrowed
to a curated seven-table/four-function list instead of the go-ahead's own complete relevant
surface; (High) item 6 omitted the two existing `DOCFLG`-snapshot validator regression tests and an
explicit coverage matrix; (High) item 8's owner-level bypass test lacked literal assertions for its
audit and provenance post-state; (Medium) the test-inventory table double-counted item 4 against
item 3's shared run and undercounted item 6's existing regressions, and the gate statement carved
out a partial-start authorization the checklist's own exhaustiveness does not permit; (Low)
Observation 2's Designer-file sub-question implied up to four `.Designer.cs` companions where
exactly one exists. **Every finding is corrected in place below.** This correction changes what is
being asked of Miguel, not the fact that his explicit approval is still outstanding: **the mapping
remains awaiting Miguel's explicit decision on Observation 1 and Observation 2, exactly as before —
no implementation of any kind is authorized by this records step, before or after this correction
pass.**

### Second correction pass — a further independent review found four more findings, applied in place below

A second independent review of this mapping, after the first correction pass above, found one High
and three Medium findings, all applied below: (High) item 8's roster/direct-DML check was mapped as
a second, separate `[Fact]` and disposable run instead of folding into item 3's own combined method
exactly as item 4 already is — duplicating item 3's own proof surface and inflating the new-method
count; (Medium) Observation 1's fixture evidence cited only the 119-row synthetic fixture and
asserted "exactly one exception" and "no equivalent fixture for 52," when a second synthetic
fixture — a 52-row `DOCEFL` population in
`Database_backed_registry_validation_is_clean_and_exercises_query_sensitive_semantics`
(`P11aDisposableDatabaseTests.cs:53-62`, `generate_series(1,52)`) — already exists and is equally
uncorrelated to the real governed historical population; (Medium) item 6's description of
`Piece_a_reports_all_five_honest_historical_completeness_findings` overclaimed that all four
`RegistryValidationCheck` members fire in that one test, when only the two absence checks fire on
NULL/absent data there and the two vocabulary checks are proven separately, by the imported/native
unknown-literal tests; (Medium) the test-inventory table and every dependent count still reflected
the pre-fold, seven-method figure. **Every finding is corrected in place below.** This correction
again changes what is being asked of Miguel, not the fact that his explicit approval is still
outstanding: **the mapping remains awaiting Miguel's explicit decision on Observation 1 and
Observation 2, exactly as before — no implementation of any kind is authorized by this records
step, before, between, or after either correction pass.**

### Legend — test surfaces, status labels, and fixture/run-phase labelling

| Label | Meaning |
|---|---|
| **New Disposable test** | A new `[Fact]` under `[Trait("Category","P11aDatabase")]`, appended to the existing `P11aDisposableDatabaseTests` class, run only via `scripts/run-p11a-disposable-tests.ps1` (`--filter Category=P11aDatabase`), never part of the ordinary `dotnet test` run. |
| **Existing regression** | An already-accepted, already-passing test re-run unmodified to prove it still holds after Piece D's cumulative sequence; no new code. |
| **Strengthened** | An already-accepted test whose *shape* is reused but whose *scope* is widened (e.g. from one piece's `Down` to the cumulative A+B+C `Down`, or from a narrow per-piece snapshot to the item-2 cumulative snapshot). |
| **Verification command** | A command run and its output asserted against, not a `[Fact]` — e.g. `dotnet build`, `git diff --check`, the preflight's `git` commands, the residual-container check. |
| **S0 / S1 / S2 / S3** | **New labelling introduced by this mapping — not prior art.** A repo-wide search of `docs/p1-1b-status.md`, `docs/PROJECT-STATE.md`, and every test file found no existing S0–S3 fixture/run-phase convention anywhere (only unrelated prose uses of "S2" as an old O10 schema-stage label). Defined here, for this mapping only, exactly as checklist item 3's own three phases: **S0** = the accepted P1-1a catalog, migrated to tip `20260805180000_P11aFdrSchema` only, before the combined `Up`; **S1** = Phase 1, immediately after the single combined `Up` completes through Piece C's tip `20260806200000_P11bPieceCGovernedCommands`; **S2** = Phase 2, immediately after the combined `Down` back to `20260805180000_P11aFdrSchema`; **S3** = Phase 3, immediately after re-applying the combined `Up` a second time. |

### The checklist being mapped

The eight items of `docs/AGENT-PROMPT-v5-P1-1b-piece-d-goahead.md`'s consolidated checklist,
restated by number only (full text in that document, not reproduced here): (1) preflight and exact
allowed surface; (2) R2 cumulative `pg_catalog` snapshot; (3) combined cumulative Up→Down→Up proof;
(4) R7 `ImportEvidenceRow` end-to-end; (5) the five baselines, one run; (6) unknown `ItemClass`
fails closed end to end; (7) full verification envelope; (8) roster/direct-DML trust-boundary
probe.

---

### 1 · Preflight and exact allowed surface

**Verification command; not a test. Existing regression** — the same six git-only commands Pieces
A/B/C already ran under the amendment-4 reformulated preflight, reused verbatim (metadata only,
never checkout/pull/merge): `git rev-parse b91768513fc638381fbde91f0b576b08220a98f6` (check 1, pin
reachable locally and in the fetched remote); `git merge-base --is-ancestor b917685… origin/main`
(check 2, no history rewrite); `git rev-parse HEAD` compared against the recorded pin-anchored
local `HEAD` (check 3); `git rev-parse b917685…:<path>` for every one of the 49 rostered blobs
against their recorded hashes (check 4); a directory listing of `Editor/Data` at the pin compared
against the 48-file roster (check 5); and for check 6, `git log b917685…..origin/main --oneline`
recorded by hash and subject only, with an explicit statement that no post-pin content was read or
adopted. Checks 1–5 failing is a hard stop, per amendment 4; check 6 is a documentation obligation,
not a pass/fail gate.

**New Disposable test** `Piece_d_all_accepted_migration_files_remain_byte_identical_before_during_and_after`
— asserts, via `git hash-object` of each accepted migration file's working-tree content compared
against the blob SHA `git ls-tree HEAD` records for that exact path, that byte-identity holds
immediately before this piece's own disposable run and again immediately after it completes (Piece
D touches no tracked migration file, so this is a static git-state assertion bracketing the
database work, not itself database-dependent).

**Feasibility finding — see Observation 2.** The checklist's own text says "**All six** accepted
P1-1a/Piece A/Piece B/Piece C migration files remain byte-identical." Direct inspection of
`src/Sibyla.Infrastructure/Persistence/Migrations/` finds **eight**, not six: two files per piece
(`<Timestamp>_<Name>.cs` migration wrapper + `<Name>SchemaSql.cs` DDL) across four pieces —
`20260805180000_P11aFdrSchema.cs`/`P11aSchemaSql.cs`,
`20260806180000_P11bPieceASchemaCompleteness.cs`/`P11bPieceASchemaSql.cs`,
`20260806190000_P11bPieceBRegistryFieldProvenance.cs`/`P11bPieceBSchemaSql.cs`,
`20260806200000_P11bPieceCGovernedCommands.cs`/`P11bPieceCSchemaSql.cs`. This test is written to
assert byte-identity across the correct eight-file roster; the discrepancy itself is reported, not
silently corrected — see Observation 2.

---

### 2 · R2 cumulative `pg_catalog` snapshot over the complete relevant surface

**Critical correction applied to this item.** The prior draft of this mapping narrowed the snapshot
to a curated seven-table list (`ENTMST`, `DOCEFL`, `DOCFLG`, `ImportEvidenceRow`,
`RegistryFieldProvenance`, `P11aCommandAudit`, `CompanyRegistry`) and a curated four/five-function
list. That narrowing is removed here: the go-ahead's own item 2 text requires the *complete*
relevant surface, not a hand-picked subset, and a named-list `WHERE` clause is exactly the kind of
selected-table narrowing item 2 forbids — a schema object added, renamed, or dropped outside the
curated list would silently escape comparison. The helper below instead enumerates every user
object dynamically, by schema membership, never by a fixed name list, and item 3's S0/S2 and
S1/S3 comparisons (below) use this complete oracle, not a subset of it.

**New helper** `PieceDCumulativeCatalogSnapshot(string connectionString)` — a full-surface,
deterministically normalized snapshot (every query `ORDER BY`s its own key, every structured
record/result set built into a canonical multi-line string with a stable field order, never a
row/object count), scoped to every non-system schema (`nspname NOT IN ('pg_catalog',
'information_schema') AND nspname NOT LIKE 'pg\_temp\_%' AND nspname NOT LIKE 'pg\_toast%'` — in
this database, `public` only, but the query itself names no schema, so it is not itself a curated
list) and covering:
- `information_schema.columns` for **every table in scope, with no table-name filter** — full
  column list (name, ordinal position, type, `column_default`, `is_nullable`,
  `is_generated`/`generation_expression`, `character_maximum_length`/`numeric_precision`/
  `numeric_scale` where applicable) for every user table the accepted P1-1a+A+B+C schema actually
  contains, not a named subset.
- `pg_class`/`pg_namespace` owners, `pg_class.relacl` (table-level ACLs), and `pg_namespace.nspacl`
  (schema-level ACLs), for every user relation and schema in scope, plus `pg_attribute.attacl` for
  every column of every such relation (present or absent — absence of a column ACL is asserted, not
  skipped) — every user object owner/ACL, schema/table/column ACLs included, literally.
- `pg_roles` (`rolname`, `rolsuper`, `rolinherit`, `rolcreaterole`, `rolcreatedb`, `rolcanlogin`,
  `rolreplication`, `rolbypassrls`) for every non-system role (`rolname NOT LIKE 'pg\_%'`), and
  `pg_auth_members` translated to `(member_rolname, group_rolname, admin_option)` triples — every
  role, membership, and attribute relevant to effective state, not limited to the roles named
  elsewhere in this mapping.
- `pg_constraint` — `conname`, `contype`, `pg_get_constraintdef(oid)`, `condeferrable`,
  `condeferred` — names, exact definitions, and deferrability, for every constraint on every table
  in scope.
- `pg_indexes` — `indexdef`, exact definitions, for every index on every table in scope.
- `pg_trigger` — `tgname`, `tgtype` (timing/event decoded), `tgenabled`, `tgdeferrable`,
  `tginitdeferred`, and the invoked function name, for every trigger on every table in scope.
- `pg_proc`/`pg_get_functiondef(oid)` for **every user function/procedure in scope, with no
  name-list filter** (`pronamespace` in the same non-system schema set, `proowner` not a built-in
  role) — owner, `proacl` (via `information_schema.routine_privileges`), `prosecdef`, `proconfig`
  (`search_path`), identity arguments, return type, language, and exact body text, for every
  function or procedure the accepted schema actually contains, not the four or five named elsewhere
  in this mapping.
- `"__EFMigrationsHistory"` — `MigrationId`, `ProductVersion` rows.

**New Disposable test** `Piece_d_cumulative_catalog_snapshot_is_complete_deterministic_and_set_based`
— calls the helper twice back-to-back against the same unmodified database state and asserts
byte-identical output (the snapshot mechanism must be proven deterministic *before* it is trusted
as the comparison oracle for item 3), then asserts the snapshot's own object roster matches the
measured, already-accepted counts from the Piece A/B/C evidence maps (8 triggers, 4 Piece B trigger
functions, 3 Piece C functions including the one approved exception, 1 Piece C role) as a sanity
floor only — this roster-count check never substitutes for the proof itself: the proof used by item
3 is full string/tuple-set equality over the complete, dynamically-enumerated snapshot above, never
a count comparison and never narrowed to a selected-table subset, satisfying the go-ahead's "never
as lossy counts" and "complete relevant surface" requirements directly.

---

### 3 · Combined cumulative Up→Down→Up proof, one disposable PostgreSQL 17 run — items 4 and 8's roster share this same method and run

**High correction applied to the item 3/item 4 relationship.** The prior draft proposed a second,
separate new `[Fact]` for item 4. That double-counted the proof surface against a single cumulative
run: item 4's own checkpoints are identical to item 3's S0–S3, so item 4 is mapped into item 3's own
method below as additional assertions over the same fixture and run, not as its own Fact. See the
item 4 section immediately following for the exact shared-method statement and its assertions.

**High correction applied to the item 3/item 8-roster relationship (second independent review).**
The prior draft proposed a second, separate new `[Fact]` and disposable run for item 8's
roster/direct-DML check. That again double-counted the proof surface: item 8's roster claim needs
exactly two checkpoints, immediately after the first combined `Up` and again after the second, which
are precisely item 3's own S1 and S3 — so item 8's roster check is folded into item 3's own method
below, measured at S1 and again at S3 in sequence, not as its own Fact or container. Item 8's
separate owner-level bypass probe (`Piece_d_owner_level_forged_evidence_guc_bypasses_reject_terminal_docflg_mutation_is_reproduced`)
is unaffected by this fold and remains its own standalone `[Fact]`, run at tip — see the item 8
section below for both halves.

**Strengthened** — widens the existing shape of `Piece_a_down_is_exact_and_up_down_up_is_catalog_stable`
/ `Piece_b_down_is_exact_and_up_down_up_is_catalog_stable` /
`Piece_c_down_is_exact_and_up_down_up_is_catalog_stable` (each: narrow per-piece snapshot, one
piece's own `Down`) into one cumulative test, using item 2's complete, dynamically-enumerated
catalog snapshot (never the curated seven-table subset) as the comparison oracle, and the full
three-piece `Down`.

**New Disposable test** `Piece_d_combined_cumulative_up_down_up_over_a_plus_b_plus_c_matches_accepted_p1_1a_and_is_stable`
— using the already-live migrator mechanism (`context.Database.GetService<IMigrator>().MigrateAsync(migrationId)`),
in one disposable container:
1. `MigrateAsync("20260805180000_P11aFdrSchema")` → capture `snapshotS0` (item 2's helper) plus
   `uniqueS0`/`indexS0` (item 4's two reused helpers, below, called in the same step).
2. `MigrateAsync()` (no argument, applies through tip `20260806200000_P11bPieceCGovernedCommands` —
   the combined `Up` over A+B+C in one call, since EF applies every pending migration in dependency
   order) → capture `snapshotS1`/`uniqueS1`/`indexS1` (**Phase 1**), plus `rosterS1` — for every
   role in the non-owner/non-superuser class (item 8's roster query, above), all six of
   `has_table_privilege(rolname,'"DOCFLG"','INSERT'|'UPDATE'|'DELETE'|'TRUNCATE')` (the four
   table-level checks) and `has_any_column_privilege(rolname,'"DOCFLG"','INSERT')` /
   `has_any_column_privilege(rolname,'"DOCFLG"','UPDATE')` (the two column-level checks — `DELETE`
   and `TRUNCATE` have no column-level grant form in Postgres, so no third/fourth column-level check
   exists to capture), captured inline in this same step, no separate helper.
3. `MigrateAsync("20260805180000_P11aFdrSchema")` again (EF runs Piece C's `Down`, then Piece B's,
   then Piece A's, in that order, automatically) → capture `snapshotS2`/`uniqueS2`/`indexS2`
   (**Phase 2**).
4. `MigrateAsync()` again → capture `snapshotS3`/`uniqueS3`/`indexS3` (**Phase 3**), plus `rosterS3`
   — the same inline roster query as step 2, captured a second time.

**Literal assertions (item 3):** `Assert.Equal(snapshotS0, snapshotS2)` — the combined `Down` equals
the accepted P1-1a catalog **exactly**, not the pre-`Down` A+B+C tip and not a partial match, using
item 2's complete oracle; `Assert.Equal(snapshotS1, snapshotS3)` — the second `Up` reproduces the
first exactly; `Assert.NotEqual(snapshotS0, snapshotS1)` — a sanity assertion proving the snapshot
mechanism is genuinely sensitive to A+B+C's content, ruling out a vacuously-passing comparator (this
is the "why this test proves the claim, not a lossy proxy" justification).

**Literal assertions (item 8's roster, folded into this same method, measured at S1 and again at S3
in sequence):** at `rosterS1` and again at `rosterS3`, for every role in the non-owner/non-superuser
class, all six checks are `false` at both checkpoints — the four table-level
`has_table_privilege(rolname,'"DOCFLG"','INSERT'|'UPDATE'|'DELETE'|'TRUNCATE')` calls, plus the two
column-level `has_any_column_privilege(rolname,'"DOCFLG"','INSERT')` /
`has_any_column_privilege(rolname,'"DOCFLG"','UPDATE')` calls (`DELETE`/`TRUNCATE` have no
column-level grant form in Postgres — a grantee either holds the table-level privilege or does not —
so no third/fourth column-level check exists to assert) — specifically confirming
`sibyla_piece_c_executor`, which holds only `EXECUTE` on
`AppendDOCFLGResolutionEvidence`/`AssignDOCEFLItemClass`, never a direct table or column grant, has
zero direct `DOCFLG` reachability, table-level or column-level, both immediately after the first
combined `Up` and again after the second. **Fail-closed stop clause, stated per the go-ahead's own
text:** if either `rosterS1` or `rosterS3` ever shows any of the six checks true for the non-owner
class, that is a hard test failure and a stop-and-report requiring Miguel's explicit decision — Piece
D has no migration content and cannot remediate a discovered writer by altering DDL.

**Fixture/run phase:** S0 → S1 → S2 → S3, all within one disposable PostgreSQL 17 container, one
test method, one run — satisfying "one disposable PostgreSQL 17 run" literally, and (per item 8)
literally measuring the roster twice in that same sequential run, at S1 and again at S3, not in a
separate run.

---

### 4 · R7 end-to-end — `ImportEvidenceRow`'s four `UNIQUE` constraints — mapped into item 3's method, not a separate Fact

**Existing regression, strengthened, sharing item 3's method and run** — reuses the existing
private helpers `ImportEvidenceRowUniqueConstraints(connectionString)`
(`P11aDisposableDatabaseTests.cs:557`) and `ImportEvidenceRowIndexes(connectionString)` (`:577`)
**unmodified**, called at the same four S0–S3 checkpoints already captured inside item 3's own
`Piece_d_combined_cumulative_up_down_up_over_a_plus_b_plus_c_matches_accepted_p1_1a_and_is_stable`
method and run — **no separate container and no separate `[Fact]` for item 4.** Piece C's own item
13 already deferred this exact end-to-end proof to Piece D ("re-verified again end-to-end in Piece
D; that is Piece D's own gate, not this one's").

**Literal assertions (item 4, evaluated inside item 3's method):** the exact `pg_get_constraintdef`
text of all four `UNIQUE` constraints (`UNIQUE NULLS NOT DISTINCT
("ImportBatchId","SourceTable","SourcePermanentCode")`; `UNIQUE NULLS NOT DISTINCT
("ImportBatchId","SourceTable","SourceRecordKey")`;
`UNIQUE ("Id","TargetTable","TargetPermanentCode")`;
`UNIQUE ("Id","CompanyCode","TargetTable","TargetPermanentCode")`) and their backing
`pg_indexes.indexdef` text are identical at S0==S1==S2==S3. **Why this proves the claim, not a
lossy proxy:** direct inspection of `P11bPieceASchemaSql.cs`, `P11bPieceBSchemaSql.cs`, and
`P11bPieceCSchemaSql.cs` confirms none of the three pieces' `Up` or `Down` blocks ever names
`ImportEvidenceRow` in an `ALTER TABLE`/`DROP CONSTRAINT`/`DROP INDEX` statement, so identity
across all four phases is a direct, not incidental, proof that no piece silently altered this
table's uniqueness surface, cumulatively or individually — independent of, and in addition to, item
2's complete catalog snapshot already covering this same table's constraints/indexes as part of its
non-curated surface.

---

### 5 · The five baselines, one single end-to-end disposable run — **infeasible as written; blocked pending Observation 1**

No test is committed for this item. Direct inspection (detailed in Observation 1 below) establishes
that **none of the five baseline counts, nor the two `Routine` rows, can be measured against the
real governed population inside this repo today**: no importer exists in `src/` or `scripts/`,
Scope 1 has never run, and no fixture anywhere in the test project loads a dataset at anything near
this scale. Two of the five baseline numbers, 119 and 52, each have an authored **synthetic** fixture
matching that count — 119 via `Piece_a_validator_round_trips_119_unreferenced_imported_entity_nulls`
and 52 via the `generate_series(1,52)` `DOCEFL` fixture (`P11aDisposableDatabaseTests.cs:53-62`) —
but neither reconciles against real historical data, and no fixture anywhere combines all five
counts against the real governed population. This item cannot be mapped to a committed test without Miguel's explicit decision among
the alternatives in Observation 1; per the go-ahead's own instruction, this is reported, not
resolved silently, and no test name is proposed as final.

---

### 6 · Unknown `ItemClass` fails closed end to end, both imported and native rows

**Operative mapping as amended by D-M2-A (binding):** the native and imported proof rows for an
active company each start `Open`. Each performs exactly one atomic Open→terminal `UPDATE` setting
`ItemClass='Bogus'` together with `Status='Resolved'`, `ResolutionEvidence`, `ResolvedBy`, and
`ResolvedAt`. Every orthogonal CHECK and prerequisite, including provenance prerequisites, must be
satisfied so the intended composite FK is the rejecting object. Each rejection must assert both
SQLSTATE `23503` and exact constraint name
`DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`. The separate NULL/`MATCH SIMPLE`
proof targets remain on an imported `Open` row. Repairing the company-scoped validator test
expectation is ordinary item-6 scope under this amendment, not a separate decision. This paragraph
supersedes only the pre-D-M2 direct-UPDATE test shape described later in this item; every other
item-6 mapping obligation and every other Piece D item remains unchanged.

**Schema-surface finding, stated precisely rather than assumed:** `DOCEFL.ItemClass` carries a
direct inline `CHECK ("ItemClass" IN ('Decision','Status','Annotation'))` (`P11aSchemaSql.cs:379`,
untouched by Piece A's `DROP NOT NULL`) — closed at the schema level directly. `DOCFLG.ItemClass`
carries **no such direct CHECK anywhere** — confirmed by reading `P11aSchemaSql.cs` and
`P11bPieceASchemaSql.cs` in full; no `CHECK` naming `DOCFLG`'s `"ItemClass"` literal set exists.
Its vocabulary closure is instead **transitive**, via the original unnamed composite foreign key
`("EFCode","ItemClass","ReviewPriority","BlockingLevel") REFERENCES "DOCEFL"(...)`: because
`DOCFLG."ReviewPriority"` and `DOCFLG."BlockingLevel"` are unconditionally `NOT NULL` (never
relaxed by any piece — only `ItemClass` was), `MATCH SIMPLE` only ever skips this FK when
`ItemClass` itself is `NULL`; whenever `ItemClass` is non-null, all four FK columns are non-null
and the FK always engages, rejecting any value that does not match an existing `DOCEFL` row's own
(CHECK-bound) class. This is confirmed closed, not assumed — and is stated as an FK-mediated
closure, not a same-table `CHECK`, so as not to claim a schema object that does not exist.

**High correction applied to this item.** The prior draft of this mapping omitted the two existing
`DOCFLG`-snapshot validator regression tests (`RegistryValidationServiceTests.cs:563` and `:582`)
and did not present an explicit coverage matrix. Both are added below, together with the matrix.

**Existing regression** (validator surface, in-memory, no DB —
`tests/Sibyla.Tests/Registry/RegistryValidationServiceTests.cs`), four methods, confirmed present at
these exact names by direct inspection (lines 527, 545, 563, 582):
`Piece_a_validator_fails_closed_on_unknown_non_null_imported_docefl_item_class`,
`Piece_a_validator_fails_closed_on_unknown_non_null_native_docefl_item_class`,
`Piece_a_validator_fails_closed_on_unknown_non_null_imported_docflg_snapshot_item_class`, and
`Piece_a_validator_fails_closed_on_unknown_non_null_native_docflg_snapshot_item_class` — all four
re-run unmodified as Piece D regression, covering both governed tables (`DOCEFL` and `DOCFLG`) and
both provenance classes (imported and native) at the validator layer — plus
`Piece_a_reports_all_five_honest_historical_completeness_findings`.

**Medium correction applied to this test's description (second independent review).** The prior
draft claimed this one test confirms all four `RegistryValidationCheck` members fire. Direct
inspection of the test's own fixture and assertions corrects this: `Piece_a_reports_all_five_honest_historical_completeness_findings`
proves the two **absence** checks — `RegistryValidationCheck.DoceflItemClassUnassigned` and
`DocflgSnapshotItemClassAbsent` — fire on NULL/absent `ItemClass` data and produce a named finding,
never a coerced placeholder; the two **vocabulary** checks — `DoceflItemClassVocabulary` and
`DocflgSnapshotItemClassVocabulary` — remain `Success`/0 on that same NULL/absent fixture, because
an absent value is never an unknown-literal value. The vocabulary checks firing on an actual unknown
literal is proven separately, not by the five-findings test: the four existing imported/native
validator tests named immediately above prove unknown-vocabulary firing across both `DOCEFL` and
`DOCFLG`; the two Piece C command tests named below prove command-boundary closure for `DOCEFL`; and
the new `DOCFLG` disposable test in this item's coverage matrix proves schema-level closure.

**Existing regression** (command surface): `Piece_c_assign_item_class_rejects_unknown_item_class_literal`
(disposable) and `Piece_c_assign_item_class_enforces_the_closed_d8_vocabulary_at_the_command_boundary`
(`P11bPieceCContractTests.cs`, static SQL-text contract) — the governed write path's own
first-statement fail-closed check, independent of and prior to the FK. **`DOCFLG` has no governed
assignment command of its own** — its `ItemClass` is completed only as a side effect of
`AssignDOCEFLItemClass`'s `DOCEFL`-keyed call (Piece C's own `AssignDOCEFLItemClass` function body,
`P11bPieceCSchemaSql.cs`) — so the command-surface regressions above are asserted for `DOCEFL` only;
`DOCFLG`'s own command-layer closure is the FK-mediated schema finding stated above and the new
disposable test below, not a `DOCFLG`-specific command.

**Coverage matrix — DOCEFL/DOCFLG × imported/native × validator/schema/command, every cell
accounted for, none silently assumed:**

| Table · surface | Imported | Native |
|---|---|---|
| **DOCEFL, validator** | `Piece_a_validator_fails_closed_on_unknown_non_null_imported_docefl_item_class` (existing regression) | `Piece_a_validator_fails_closed_on_unknown_non_null_native_docefl_item_class` (existing regression) |
| **DOCEFL, schema** | direct inline `CHECK` on `DOCEFL."ItemClass"` (`P11aSchemaSql.cs:379`) — applies identically regardless of imported/native; confirmed by inspection, no separate test needed | same |
| **DOCEFL, command** | `Piece_c_assign_item_class_rejects_unknown_item_class_literal` / `..._enforces_the_closed_d8_vocabulary_at_the_command_boundary` — applies identically regardless of imported/native; confirmed by inspection, no separate test needed | same |
| **DOCFLG, validator** | `Piece_a_validator_fails_closed_on_unknown_non_null_imported_docflg_snapshot_item_class` (existing regression) | `Piece_a_validator_fails_closed_on_unknown_non_null_native_docflg_snapshot_item_class` (existing regression) |
| **DOCFLG, schema** | `Piece_d_docflg_unknown_non_null_item_class_is_rejected_transitively_by_the_composite_docefl_fk_native_and_imported` (new, below) — imported-row case | same new test — native-row case, same method, both rows asserted |
| **DOCFLG, command** | not applicable — no `DOCFLG`-specific assignment command exists; closure is schema-level (FK) only, per above | not applicable, same reason |

**New Disposable test** `Piece_d_docflg_unknown_non_null_item_class_is_rejected_transitively_by_the_composite_docefl_fk_native_and_imported`
— bypassing the governed command (an owner-level probe, since item 8 establishes no non-owner role
can reach `DOCFLG` DML at all), creates one native proof row (`ImportEvidenceRowId IS NULL`) and
one imported proof row (`ImportEvidenceRowId IS NOT NULL`) for an active company, each initially
`Open`. Against each row it performs exactly one atomic Open→terminal `UPDATE` that sets
`ItemClass='Bogus'`, `Status='Resolved'`, `ResolutionEvidence`, `ResolvedBy`, and `ResolvedAt`
together, with every orthogonal CHECK and provenance prerequisite already satisfied. **Literal
assertions:** both attempts fail with Postgres SQLSTATE `23503` `foreign_key_violation` (not
`23514` `check_violation`) and exact constraint name
`DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey`; the assertion names the FK, never a
`DOCFLG`-level `CHECK`. Separate NULL/`MATCH SIMPLE` proof targets remain on an imported `Open`
row and prove honest `ItemClass=NULL` is accepted unchanged, never coerced to a placeholder.

**New Disposable test** `Piece_d_registry_validator_flags_absent_item_class_and_never_a_placeholder_post_cumulative_up`
— re-runs the validator against the disposable database post-cumulative-`Up` (not just the offline
unit tests above) over a small fixture spanning native × imported × `DOCEFL` × `DOCFLG`, asserting
`NULL`/absent rows produce the named non-blocking finding and no row's `ItemClass` is ever read
back as a placeholder literal. Its expected finding count and fixture rows are company-scoped to
the validator invocation's company; repairing the prior cross-company expectation is ordinary
item-6 test-fixture scope under D-M2-A and does not change the validation contract.

---

### 7 · Full verification envelope

All **verification commands, existing regression** — no new test code, reusing every mechanism
already established by Pieces A/B/C unmodified:

| Verification | Command |
|---|---|
| Clean rebuilding build | `dotnet build GOTT.Sibyla.slnx -c Release --no-incremental` — 0 warnings, 0 errors |
| Ordinary suite | `dotnet test --no-build` (default `Category!=P11aDatabase` filter from `Sibyla.Tests.csproj:8`) |
| Focused registry tests | `dotnet test --filter "FullyQualifiedName~RegistryValidationServiceTests"` — the existing non-DB validator unit-test class, unmodified |
| Focused integration tests | `dotnet test --filter "FullyQualifiedName~P11aDisposableDatabaseTests&FullyQualifiedName~Piece_d"` against a live disposable container — the new Piece D `[Fact]`s run in isolation |
| Full disposable suite | `scripts/run-p11a-disposable-tests.ps1` (unmodified — already filters `Category=P11aDatabase`, which will include the new `Piece_d_*` facts without any script change) |
| `git diff --check` | clean |
| Exact changed-path/claim equality | the implementation commit's diff is compared path-for-path against this mapping's own committed test/helper inventory, item for item |
| Residual containers | `docker ps -a --filter "name=sibyla-p11" --format "{{.Names}}"` — expected empty |

Per the test-plan gate's own instruction and amendment 5's proof-pattern annex, **no suite total is
projected here** — every figure above will be measured fresh at implementation time and reported
then, not predicted now.

---

### 8 · Roster/direct-DML trust-boundary probe

**Exact catalog queries and role-expansion semantics, specified now as the go-ahead requires:**
Postgres's built-in `has_table_privilege(rolname, '"DOCFLG"', 'INSERT')` / `'UPDATE'` / `'DELETE'`
/ `'TRUNCATE'` cover table-level direct DML — four checks. Column-level direct DML is covered
separately by `has_any_column_privilege(rolname, '"DOCFLG"', 'INSERT')` /
`has_any_column_privilege(rolname, '"DOCFLG"', 'UPDATE')` — two more checks, six total — the
authoritative Postgres function for "does this role hold the named privilege on any column of this
relation," used deliberately instead of the single-column `has_column_privilege`, since the roster
check must cover every column of `DOCFLG`, not one named column. `DELETE` and `TRUNCATE` have no
column-level grant form in Postgres (a grantee either holds table-level `DELETE`/`TRUNCATE` or does
not; Postgres defines no per-column `DELETE`/`TRUNCATE` privilege), so `INSERT`/`UPDATE` are the only
two checks with a column-level form to assert. All six already implement full
membership/inheritance/`PUBLIC` resolution per Postgres's own privilege-resolution semantics — this
is proposed over a hand-rolled recursive `pg_auth_members` graph traversal because it is both
simpler and authoritative (these are the same functions Postgres itself consults to authorize a real
`INSERT`/`UPDATE`/`DELETE`/`TRUNCATE`, so there is no daylight between the test oracle and the
enforced behavior). Roster query: `SELECT rolname, rolsuper FROM pg_roles WHERE rolname NOT LIKE
'pg\_%'`, classified into **owner/superuser control-plane** (`rolsuper = true`, or the
connecting/migrating role itself — direct inspection confirms `DOCFLG` carries no explicit
`ALTER TABLE ... OWNER TO`, so its effective owner is whichever role ran the migration; in the
disposable harness this is the `docker run postgres:17-alpine` default superuser) versus
**application/executor/importer** (every other role — at minimum `sibyla_piece_c_executor`, the
only non-superuser role any of these four migrations creates).

**Folded into item 3's own method, not a separate Fact (second independent review correction).**
The roster/direct-DML trust-boundary check is `Piece_d_combined_cumulative_up_down_up_over_a_plus_b_plus_c_matches_accepted_p1_1a_and_is_stable`
(item 3's own new method, above) — no `Piece_d_zero_application_writer_roster_holds_after_first_and_second_cumulative_up`
Fact, and no separate container or run, exists. It measures the roster literally at S1 and again at
S3, in sequence, inside that same combined `Up→Down→Up` run — see item 3 above for the exact
`rosterS1`/`rosterS3` captures, the literal assertions (every non-owner/non-superuser role's six
checks — four `has_table_privilege` and two `has_any_column_privilege` — `false` at both
checkpoints, `sibyla_piece_c_executor` named specifically), and the fail-closed stop clause. This
mirrors exactly how item 4 is already folded into item 3's method rather than kept as its own Fact.

**High correction applied to this test.** The prior draft asserted only that the raw `UPDATE`
succeeds, with vague "audit/provenance" wording not backed by an assertion. Below, every literal
assertion is stated exactly, including the precise, schema-grounded reason a provenance claim is or
is not supportable, and the probe is required to run inside a transaction that is rolled back.

**Operative superseding amendment — D-M3-A+ (binding):** the standalone owner-level probe retains
its approved name, but its fixture is an imported `DOCFLG` row (`ImportEvidenceRowId IS NOT NULL`),
terminal with `Status='Resolved'`, and initially has `ResolutionEvidence IS NULL` under the accepted
O9-D5 historical exemption. In one transaction that is rolled back, with
`sibyla.docflg_evidence_append_id` forged to match `FlagInstanceID`, it proves two ordered
assertions: (a) the first direct `UPDATE`, `NULL` to a non-null evidence value with every other
column unchanged, succeeds; (b) the second direct `UPDATE`, attempting to replace that now-populated
evidence with another value while the same forged GUC remains set, fails with SQLSTATE `23514` and
exact message `terminal DOCFLG rows are append-only`. After the first append, the matching
`P11aCommandAudit` command-row count is exactly zero and the same single `ItemClass`
`RegistryFieldProvenance` row remains unchanged; after the failed second update, the first appended
value remains intact. The entire transaction is rolled back. The first append is the real accepted
bypass and remains contained only by item 3/item 8's zero-non-owner/non-superuser-direct-writer
roster; the second assertion proves the bypass permits one first append, never overwrite.
`RejectTerminalDOCFLGMutationFn` remains byte-identical. This paragraph supersedes only the
pre-D-M3 fixture and success assertion retained immediately below as historical mapping text.

**Historical pre-D-M3 standalone-probe mapping, superseded by D-M3-A+ above:**

**New Disposable test** `Piece_d_owner_level_forged_evidence_guc_bypasses_reject_terminal_docflg_mutation_is_reproduced`
— extends the existing forged-GUC pattern already proven at
`Piece_c_evidence_append_exception_cannot_be_exploited_by_forged_guc_and_direct_dml` (`:3118`) to a
direct, owner-level, non-command `UPDATE` on a terminal, already-resolved `DOCFLG` row (fixture:
`Status='Resolved'`, `ResolutionEvidence` pre-set to a known value, one pre-existing
`RegistryFieldProvenance` row for that same `FlagInstanceID` from the fixture's `DOCEFL`/`DOCFLG`
`ItemClass` assignment, `Marker='authored'`), setting `sibyla.docflg_evidence_append_id` to that
row's own `FlagInstanceID` and issuing `UPDATE "DOCFLG" SET "ResolutionEvidence"='owner-probe
evidence' WHERE "FlagInstanceID"=$1` directly, with no governed command called. **The whole probe
runs inside an explicit transaction that is rolled back before the test ends** (`BEGIN`, read every
post-state below, then `ROLLBACK` — or an ambient `NpgsqlTransaction` disposed without
`CommitAsync`), so no residual forged state survives into any other test sharing the same disposable
container.

**Literal assertions, all measured before rollback:**
1. The raw `UPDATE` **succeeds** — `Record.ExceptionAsync` returns `null`; no `PostgresException` of
   any `SqlState` is thrown.
2. `SELECT "ResolutionEvidence" FROM "DOCFLG" WHERE "FlagInstanceID"=$1` reads back exactly
   `'owner-probe evidence'` — the literal value the raw `UPDATE` wrote, confirming the mutation took
   effect and was not silently no-opped by a `BEFORE UPDATE` trigger.
3. `SELECT count(*) FROM "P11aCommandAudit" WHERE "TargetId"=$1 AND "Action" IN
   ('AppendDOCFLGResolutionEvidence','AssignDOCEFLItemClass')` is exactly `0` — by construction, not
   assumption: direct inspection of `P11bPieceCSchemaSql.cs` confirms every `P11aCommandAudit`
   `INSERT` is authored inside `AppendDOCFLGResolutionEvidence`/`AssignDOCEFLItemClass` themselves;
   no trigger on `DOCFLG` ever writes `P11aCommandAudit`, so a raw `UPDATE` that never calls either
   function cannot produce a matching row, and this assertion proves exactly that, not a broader or
   vaguer "no audit trail" claim.
4. `SELECT "Marker","ValueHash" FROM "RegistryFieldProvenance" WHERE "TargetTable"='DOCFLG' AND
   "TargetCode"=$1` returns the **same single row, unchanged**, that existed before the raw
   `UPDATE`. **The precise, non-guessed reason, stated from the accepted trigger surface:**
   `RegistryFieldProvenance` is scoped by construction to the `ItemClass` field only (Piece B's
   `RegistryFieldProvenance` table and Piece C's `AssignDOCEFLItemClass`/cardinality-trigger
   surface); `ResolutionEvidence` has no `RegistryFieldProvenance` row of its own and no accepted
   schema object ever writes one for it. The one `DOCFLG`-side trigger that could touch this table
   on an `UPDATE`, `RejectStaleProvenanceOnDocflgResolutionFn` (`P11bPieceBSchemaSql.cs`), only acts
   when `NEW."Status"` transitions **into** `'Resolved'/'Superseded'/'Waived'` **from**
   `'Open'/'InReview'`; this fixture's row is already `'Resolved'` before and after the raw
   `UPDATE`, so that trigger's own condition is false and it is a structural no-op here. The
   assertion is therefore a precise, supported claim — provenance is untouched because nothing in
   the accepted schema ever routes a `ResolutionEvidence`-only mutation through
   `RegistryFieldProvenance` — not the vague "audit/provenance" wording this correction removes.

**What this test does and does not claim, stated per the go-ahead's own framing:** this is evidence
explaining *why* the zero-reachable-application-writer roster (folded into item 3's method, above)
is security-relevant — the DDL-level boundary is the only one enforced. **Success here — the raw
`UPDATE` succeeding — is the expected, already-accepted owner/superuser trust-boundary limitation,
not a denial and not a newly discovered defect.** The test's own doc-comment and assertion messages
state explicitly that this is **not** a claim that `RejectTerminalDOCFLGMutationFn` enforces a
capability boundary at owner/superuser level (already known false per the Piece C independent-review
non-binding observation, `docs/p1-1b-o10-independent-review.md`, "Piece C candidate review —
Accept") — an owner/superuser connection is, and remains, outside every trigger's threat model by
design, and this test exists to keep that limitation measured and visible, not to fail on it.

---

### Observations — reported, not resolved silently

#### Observation 1 — item 5 is infeasible as written; the checklist cannot be closed without an explicit decision

**Measured/read-only evidence:**
- Repo-wide search for the literal figures `2787`/`2,787`, `221`, `52`, `119` finds them **only as
  prose** in governance documents (`docs/p1-1b-status.md`, `docs/PROJECT-STATE.md`,
  `docs/project-todo.md`, the `AGENT-PROMPT-v5-P1-1b-o9/o10-amendment*.md` files) — never as a seed
  file, fixture, or populated test dataset.
- `docs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md` and `-o10-amendment.md` state directly that these
  are **row counts at the external FDR prototype pin** `b91768513fc638381fbde91f0b576b08220a98f6`
  (119 `ENTMST` rows twice over, 52 `DOCEFL` rows, 221 terminal `DOCFLG` rows, 2,787 = every
  `DOCFLG` instance of the 52 unassigned rules) — repeatedly and explicitly labelled "**expected
  baselines**," "measured at import; a differing measured value is recorded and flagged, not a
  stop," never closed by a completed measurement.
- No importer exists in this repo: a search for `Import(er|Service|Pipeline|Runner)` classes under
  `src/` returns no match; a search for Python scripts finds only an unrelated Hermes
  document-evidence plugin; `scripts/run-p11a-disposable-tests.ps1` only spins up a container and
  runs existing `[Fact]`s. Scope 1 — the reference-layer/2026-history import against that pin — is
  confirmed "gated and unstarted" (`docs/PROJECT-STATE.md`) and has never run to completion (one
  prior attempt stopped at gate C8, before any container or database existed).
- **Medium correction applied to this bullet (second independent review).** The prior draft cited
  only the 119-row fixture and claimed "exactly one exception" and "no equivalent fixture for 52,
  221, or 2,787." Direct inspection finds a **second** synthetic fixture at this same authored-count
  scale: `Database_backed_registry_validation_is_clean_and_exercises_query_sensitive_semantics`
  (`P11aDisposableDatabaseTests.cs:53-62`) inserts **exactly 52 synthetic `DOCEFL` rows** (and 52
  matching `RegistryFieldProvenance` rows) via `generate_series(1,52)`, alongside
  `Piece_a_validator_round_trips_119_unreferenced_imported_entity_nulls` (`:409-456`), which authors
  **exactly 119 synthetic rows** via `generate_series(1,119)`, tagged `SYNTH-PIECE-A-COUNT`. **Both
  are authored synthetic counts, not a reconciliation against real historical data** — the 52-row
  fixture happens to match the `DOCEFL` baseline number and the 119-row fixture happens to match the
  `ENTMST`/unreferenced-null baseline number, but neither is derived from or measured against the
  real governed population, so **neither satisfies item 5.** No fixture anywhere in the test project
  reproduces the five baselines as a single combined governed population, and none exists for 221,
  2,787, or the two `Routine` rows at all.

**Alternatives, with the exact prerequisite each would require:**
- **(a) Narrow item 5 to a mechanism proof.** Extend the existing 119-row and 52-row synthetic
  pattern to author matching synthetic populations for all five numbers plus the two `Routine` rows,
  all seeded and counted within one combined disposable run. This satisfies "one run" and "no
  importer execution" **literally**, but does **not** satisfy "full population" honestly for the
  five numbers — it is exactly the "synthetic count theatre" this checklist item's own text
  forbids. **Requires:** an explicit amendment or Miguel decision stating item 5 is being narrowed
  from "confirm the real governed baseline" to "confirm the counting/reporting mechanism is
  correct," with that narrowing recorded as a checklist change, not silently assumed.
- **(b) Defer item 5's real-population claim to Scope 1.** O10-D1 already anticipates this:
  "measured at import; a differing measured value is recorded and flagged, not a stop." Piece D's
  own Accept would then explicitly **not** cover item 5's literal baseline-count claim, and Scope
  1's own eventual acceptance criteria would carry it instead. **Requires:** an explicit go-ahead
  amendment carving item 5 out of Piece D's Accept scope, since the go-ahead's own text currently
  lists it as one of Piece D's eight binding checklist items with no such carve-out.
- **(c) Report the impossibility and hold, as done here.** Per this step's own governing
  instruction ("if the accepted repository does not currently contain the full governed imported
  dataset/fixture, state the literal checklist collision/impossibility instead of proposing
  synthetic count theatre"), this is the default finding of this mapping: **item 5 cannot be
  satisfied by Piece D today, and no test is committed for it.**

**Proposed resolution, distinguished from authorization:** this mapping recommends **(b)** — defer
the real-population claim to Scope 1, where it belongs given Scope 1 is the only place these rows
will ever actually exist — over (a), because (a) would let Piece D's Accept imply a false
confirmation of the real governed baselines using numbers chosen to match rather than measured.
**This is a recommendation only; it is not a decision, and implementation may not proceed on item 5
under either (a) or (b) until Miguel explicitly chooses.**

#### Observation 2 — checklist item 1's "six" accepted migration files undercounts the real roster; the correct count is eight

**Measured/read-only evidence:** direct inspection of
`src/Sibyla.Infrastructure/Persistence/Migrations/` finds two files per piece across four accepted
pieces (P1-1a, Piece A, Piece B, Piece C) —
`20260805180000_P11aFdrSchema.cs`/`P11aSchemaSql.cs`,
`20260806180000_P11bPieceASchemaCompleteness.cs`/`P11bPieceASchemaSql.cs`,
`20260806190000_P11bPieceBRegistryFieldProvenance.cs`/`P11bPieceBSchemaSql.cs`,
`20260806200000_P11bPieceCGovernedCommands.cs`/`P11bPieceCSchemaSql.cs` — **eight** files total,
not six. The go-ahead's own "Accepted implementations" section lists all four pieces (P1-1a, A, B,
C) as the additive base, so the discrepancy is not about which pieces are included — it is a stale
count, most plausibly carried over from Piece C's own pre-acceptance evidence maps, which correctly
said "six" when only P1-1a+A+B were yet fixed and Piece C's own two files were still in-flight.

**Alternatives:**
- **(i)** Treat "six" as a drafting artifact and assert byte-identity across the correct eight-file
  roster (adopted by item 1's proposed test above).
- **(ii)** Hold the literal checklist text as binding and assert only the original six, treating
  Piece C's own two files as out of scope for this specific checklist item's literal wording
  (inconsistent with the go-ahead's own additive-base definition, and would leave Piece C's
  migration files unverified by this checklist item — not recommended).

**Secondary, unresolved sub-question, stated exactly rather than implied.** Direct inspection of
`src/Sibyla.Infrastructure/Persistence/Migrations/` finds exactly **one** EF-generated
`*.Designer.cs` file among the accepted P1-1a/Piece A/Piece B/Piece C roster —
`20260805180000_P11aFdrSchema.Designer.cs` — not one per migration; Piece A's, Piece B's, and Piece
C's own wrapper migrations (`20260806180000_P11bPieceASchemaCompleteness.cs`,
`20260806190000_P11bPieceBRegistryFieldProvenance.cs`, `20260806200000_P11bPieceCGovernedCommands.cs`)
have **no** `.Designer.cs` companions at all. There is also exactly one shared
`SibylaDbContextModelSnapshot.cs`, common to the whole `DbContext`, not per-piece. So the open
sub-question is whether these exact two tracked, tool-maintained files — one `.Designer.cs`, one
shared model snapshot — should also be included in the byte-identity roster (content that could in
principle diverge across a `Down`/`Up` cycle, though nothing in the existing per-piece tests
currently checks them), not whether four `.Designer.cs` companions exist. Not proposed as part of
this item's committed test; flagged here so it is not silently assumed out of scope.

**Proposed resolution, distinguished from authorization:** adopt (i) — assert the correct
eight-file roster — and explicitly not decide the Designer/ModelSnapshot sub-question without
Miguel's input, since it was never part of any prior piece's checklist either.

### Gate statement — Miguel's decision is required before implementation; the checklist is exhaustive, so no partial start is available

**Medium correction applied to this gate statement.** The prior draft's gate statement included a
clause reading: "implementation may proceed only on items 1–4 and 6–8" while item 5 stayed open.
That clause is removed. It contradicted the go-ahead's own exhaustive, non-severable checklist: the
go-ahead issues one Piece D checklist, not eight independent authorizations, and this mapping is
Piece D's one test-plan gate for all eight items together. No partial-start reading survives this
correction.

- **Item 5 / Observation 1** — approve (a), approve (b), or direct a different resolution. Until
  decided, item 5 has no committed test and **this checklist cannot be closed in full**.
- **Item 1 / Observation 2** — approve treating "six" as a stale count and asserting the corrected
  eight-file roster (recommended), or direct otherwise, and decide whether the one Designer file
  (`20260805180000_P11aFdrSchema.Designer.cs`) and the one shared `SibylaDbContextModelSnapshot.cs`
  are in scope.
- **Items 2, 3, 4, 6, 7, 8** — approve the proposed test names, surfaces, and literal assertions
  above as written; no further ambiguity is reported for these six items.

**A generic instruction to execute this prompt is not mapping approval, per amendment 5's own
test-plan gate.** Approval must cover Observation 1 and Observation 2 explicitly, alongside the six
unblocked items, before any code, test, helper, migration, container, or database run of any kind
under this go-ahead.

**Because the checklist is exhaustive, any unresolved item or observation — including item 5
alone — blocks ALL Piece D implementation, on every item, not only the item it names.**
Implementation may not begin on items 1–4 or 6–8 while item 5 (or Observation 2) remains open, even
though those six items are individually unblocked in the sense that no further ambiguity is reported
for them. **Implementation becomes eligible only after Miguel explicitly amends or resolves item 5
(by choosing option (a), option (b), or directing a different resolution) and separately approves
the resulting complete mapping — Observation 2 included — as a whole.** Until both of those happen,
this records step authorizes no code, test, helper, migration, container, or database run of any
kind, on any item.

**Exact copyable approval sentences — pick exactly one, since Observation 1's two alternatives are
mutually exclusive. Each sentence is itself the explicit checklist/go-ahead amendment that resolves
item 5 and closes the gate in full; neither sentence leaves item 5, or any other item, open, and
neither authorizes a partial start:**

> *Option (b), the recommended path — this sentence amends the go-ahead's checklist to close item 5
> in full before implementation:* "Aprovo o mapping Piece D na íntegra: itens 1, 2, 3, 4, 6, 7 e 8
> como escritos; aprovo a Observação 2 — a lista correta é de oito ficheiros de migração, não seis,
> e a questão dos ficheiros Designer/ModelSnapshot fica fora do âmbito deste item; **decido e
> emendo o checklist do go-ahead pela Observação 1, opção (b): o item 5 fica formalmente fora do
> Accept do Piece D, a confirmação da população real das cinco baselines e das duas linhas Routine
> fica diferida para o Scope 1, e o checklist de oito itens fica assim integralmente fechado — só
> agora autorizo o início da implementação de todos os itens 1–4 e 6–8, e do item 5 conforme
> reformulado.**"

> *Option (a) instead — this sentence amends the go-ahead's checklist to close item 5 in full
> before implementation, narrowed to a mechanism proof:* "Aprovo o mapping Piece D na íntegra:
> itens 1, 2, 3, 4, 6, 7 e 8 como escritos; aprovo a Observação 2 — a lista correta é de oito
> ficheiros de migração, não seis, e a questão dos ficheiros Designer/ModelSnapshot fica fora do
> âmbito deste item; **decido e emendo o checklist do go-ahead pela Observação 1, opção (a): o item
> 5 é reformulado para provar apenas o mecanismo de contagem/validação, usando dados sintéticos
> autorados para igualar os cinco números e as duas linhas Routine num único run, sem alegar
> reconciliação com a população real importada, e o checklist de oito itens fica assim
> integralmente fechado — só agora autorizo o início da implementação de todos os itens 1–4 e 6–8,
> incluindo o item 5 reformulado.**"

### Test inventory this mapping commits to

**High correction applied to this inventory.** The prior draft's table implied a separate new test
method for item 4 (double-counting against item 3's shared run), undercounted item 6's existing
regressions at 4 instead of the exact 7 now named, and totalled verification commands as "~14"
though both contributing rows (6 + 8) are fully enumerated. All three are corrected below: exact
method counts, no double counting, and an exact total in place of an approximation.

**Further High correction applied to this inventory (second independent review).** The table below
had still counted item 8 as contributing 2 new tests — the owner-bypass Fact and a separate roster
Fact — before item 8's roster check was folded into item 3's shared method exactly as item 4's own
assertions already are. Corrected below: item 8 now contributes exactly 1 new test (the owner-bypass
Fact); the roster fold is credited under item 3/4's shared row, not counted again under item 8. The
new-method total drops from 7 to 6.

| Surface | New | Strengthened | Existing regression | Verification command | Blocked |
|---|---:|---:|---:|---:|---:|
| Item 1 | 1 test | 0 | 0 (the 6 preflight checks are reused verbatim; counted once, under Verification command) | 6 preflight checks | 0 |
| Item 2 | 1 test + 1 helper | 0 | 0 | 0 | 0 |
| Item 3 | 1 test (shared with item 4 and item 8's roster — see item 4 and item 8 rows) | 1 | 0 | 0 | 0 |
| Item 4 | 0 (assertions folded into item 3's own method; no separate method) | 1 | 0 (2 helpers reused unmodified inside item 3's method) | 0 | 0 |
| Item 5 | 0 | 0 | 0 | 0 | **all** |
| Item 6 | 2 | 0 | 7 (2 DOCEFL validator + 2 DOCFLG validator + 1 five-findings + 1 Piece C disposable unknown command + 1 Piece C contract unknown command) | 0 | 0 |
| Item 7 | 0 | 0 | 0 | 8 | 0 |
| Item 8 | 1 test (owner-bypass Fact only; roster assertions folded into item 3's method, credited there, not counted again here) | 0 | 0 (pattern reused, new assertions) | 0 | 0 |
| **Total proposed** | **6 new tests + 1 helper** (item1=1, item2=1, item3+4+item8-roster=1 shared, item6=2, item8-owner-bypass=1) | **2 strengthened** (items 3 and 4, sharing item 3's one new method — not double counted) | **7 existing regressions re-run** (all under item 6) | **14 verification commands** (6 + 8, both fully enumerated — exact, not approximate) | **item 5 entire** |

No final suite total (N/N) is projected anywhere in this mapping, per amendment 5's test-plan gate
and the instruction governing this step. **No implementation, test, helper, migration, container,
or database run of any kind has occurred to produce this mapping** — it is documentation only, and
implementation on any item remains unauthorized until Miguel's explicit approval covering both
observations by name.

## 2026-08-06 Piece C candidate `ce983b2…` — mandatory independent adversarial review recorded: Accept

The mandatory independent adversarial review (ordered instruction 4 of
`docs/AGENT-PROMPT-v5-P1-1b-piece-c-goahead.md`) has run, in a fresh independent Claude CLI session
with no reliance on the implementer's own summary, no resumption of a prior session, and no use of
Codex. **Verdict: Accept — 0 Critical, 0 High, 0 Medium, 0 Low.** Full record:
`docs/p1-1b-o10-independent-review.md`, "Piece C candidate review — Accept".

Independently reproduced this session: Git state (`HEAD` = `origin/feature/p1-1b` = `ce983b2…`,
clean, `0 0` ahead/behind); the amendment-4 reformulated preflight (pin resolves, prototype clone
clean and at the pin, check-6 non-divergence unchanged); build **0 Warnings/0 Errors**; ordinary
**646/646**; focused **6/6**; disposable PostgreSQL 17 suite **55/55** in a fresh container, **0**
residual `sibyla-p11*` containers after; all 6 accepted P1-1a/Piece A/Piece B migration files
byte-identical by `git hash-object`-versus-`git ls-tree` blob comparison; `RejectTerminalDOCFLGMutationFn`'s
`Down` text byte-for-byte identical to the accepted P1-1a source; `RequireActiveCompanyRegistryFn`
referenced nowhere in `Up` or `Down`. All 20 checklist items (as amended by Option-B) independently
traced to code and test: 20/20.

Eight original adversarial probes beyond the candidate's own suite: a hostile pre-existing-role
`Up` failing atomically with zero partial objects and the migration not recorded as applied; an
all-or-nothing company-authorization rollback proven to fail before any write when one of two
active affected companies lacks membership; a direct empirical exercise of
`RejectTerminalDOCFLGMutationFn`'s narrow-exception GUC mechanism (bypassing
`AppendDOCFLGResolutionEvidence` entirely via a forged `sibyla.docflg_evidence_append_id` plus a
raw `UPDATE`, confirming the mechanism is real but not independently exploitable today because no
role in the entire accepted schema history holds direct DML on `DOCFLG` other than the table
owner — recorded as a **non-binding observation for Piece D's own scope**, not a classified
finding, since it violates no checklist item as literally scoped); a `search_path`/ownership
review confirming the PostgreSQL-recommended safe pattern; a SQL-injection-surface review
confirming no dynamic SQL exists in either function; independent re-reading of both genuine
two-connection concurrency tests (real `FOR UPDATE` locks, PID-scoped `pg_stat_activity` polling,
not timing theatre); byte-for-byte `Down` restoration verification; and independent re-reading of
the inactive-affected-company skip proof (`T18`) confirming the Option-B contract exactly.

**Piece C now has an accepted implementation.** Per amendment 3, this Accept authorizes Piece D to
seek its own go-ahead from Miguel; Piece D's own go-ahead is not implied by this Accept. Piece D,
Scope 1, and O5-prep remain gated and unstarted. No baseline, O8/O9/O10 decision, or accepted
Piece A/B/C object is changed by this review; no fix was applied (none was needed).

## 2026-08-06 Piece C implementation — evidence map (candidate recreated from zero, from the Option-B amendment tip)

This is ordered instruction 3's implementation, TDD first, recreated entirely from zero from the
Option-B amendment tip `fd9dbd9ddcfa3aea6c6659916532a5e7a7cdc1ae` — no previously deleted file was
restored as authoritative; every path below is newly authored in this session. It applies the
corrected 20-item mapping and all six originally adopted resolutions, as narrowed by the Option-B
amendment for the inactive-affected-company sub-case, exactly.

### Amendment-4 preflight — re-run fresh, read-only, before any code

Against prototype clone `D:\fileStorage\repos\invoice-skill-build`, pin `b91768513fc638381fbde91f0b576b08220a98f6`,
using only `git status`, `git diff --quiet`, `git fetch`, `git cat-file -e`, `git ls-tree`, `git rev-parse`,
`git merge-base --is-ancestor`, `git log --oneline`:

1. Pin resolves locally (`git cat-file -e`, exit 0). **Pass.**
2. `git merge-base --is-ancestor b917685… origin/main` succeeds — the pin is an ancestor of live
   `origin/main` (`3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`). **Pass.**
3. Local clone `HEAD` equals the pin exactly; clean tree (`git status --short --branch`, `git diff
   --quiet`, `git diff --cached --quiet` all clean). **Pass.**
4. All **49/49** roster blobs (the O8 `entbnk.json`-substituted roster) resolved fresh, cell by
   cell, via `git rev-parse b917685…:<path>` for every recorded path against its recorded blob SHA.
   **49/49 resolved, 0 mismatches, 0 resolve failures.** **Pass.**
5. `git ls-tree b917685 -- Editor/Data/` re-counted fresh: **49** entries total, exactly **1** is the
   `Backups` subdirectory (excluded), leaving **48/48** blob files, 0 delta. **Pass.**
6. (Non-stop finding, reproduced identically.) Live tip remains `3dd4150…`; `git log --oneline
   b917685..origin/main` lists exactly the same two post-pin commits `1e841a4` and `3dd4150` already
   on record. No new divergence. No post-pin content was read or adopted — only commit hashes,
   subjects, and tree listings were inspected.

### Exact changed/new paths — this candidate commit

| Path | Change |
|---|---|
| `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceCSchemaSql.cs` | New — the migration `Up`/`Down` SQL |
| `src/Sibyla.Infrastructure/Persistence/Migrations/20260806200000_P11bPieceCGovernedCommands.cs` | New — the EF `Migration` class |
| `tests/Sibyla.Tests/Persistence/P11bPieceCContractTests.cs` | New — 6 offline SQL-text contract tests |
| `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` | Modified — 21 new `Piece_c_*` disposable tests, 1 pre-existing test (`Piece_b_waivedocflg_and_reject_terminal_mutation_function_bodies_are_unchanged`) re-pinned to the Piece B tip instead of "latest" (see below) |

No importer, Piece D, Scope 1, O5-prep, live/shared database, or prototype-write path exists in any
of these four files. No accepted P1-1a, Piece A, or Piece B migration file is touched — confirmed
byte-identical below.

### The pre-existing Piece B test correction, explained

`Piece_b_waivedocflg_and_reject_terminal_mutation_function_bodies_are_unchanged` originally compared
`RejectTerminalDOCFLGMutationFn` from the Piece A tip to **latest**. Since Piece C's approved,
explicitly-waived exception now legitimately changes that function once Piece C is part of "latest,"
the test is re-pinned to compare Piece A tip to the **Piece B tip specifically** — what it actually
verifies (that Piece B itself never touched either function) still holds and still passes. Piece C's
own new test (`Piece_c_accepted_functions_are_byte_identical_except_the_one_approved_exception`)
proves the Piece-B-tip-to-latest comparison separately, asserting the one intentional difference.

### DDL / role / function / grant roster — exact, measured from the authored `Up`, not projected

- **1 role**, created fail-closed against a hostile pre-existing name: `sibyla_piece_c_executor`
  (`NOLOGIN NOSUPERUSER NOCREATEDB NOCREATEROLE NOINHERIT NOREPLICATION NOBYPASSRLS`, no password).
- **3 functions** touched by `CREATE OR REPLACE`, no others:
  - `RejectTerminalDOCFLGMutationFn()` — **the one approved exception** (Observation 1 option B):
    adds a narrow, GUC-gated, whole-row-compared branch permitting exactly one case (an imported
    terminal row's genuinely absent `ResolutionEvidence` being populated, with every other real
    column — the `STORED GENERATED` `ImportTargetTable` column excluded from the comparison since
    PostgreSQL has not recomputed it yet inside a `BEFORE UPDATE` trigger — provably unchanged);
    falls through to the unchanged unconditional block otherwise.
  - `AppendDOCFLGResolutionEvidence(varchar, text)` — new, `SECURITY DEFINER`.
  - `AssignDOCEFLItemClass(varchar, varchar)` — new, `SECURITY DEFINER`.
- **`RequireActiveCompanyRegistryFn` is never defined, replaced, or invoked anywhere in `Up` or
  `Down`** — confirmed both by contract-test string assertion and by live `pg_get_functiondef`
  byte-identical comparison before/after `Up` in the disposable suite (Option-B amendment).
- **2 grants**: `EXECUTE` on `AppendDOCFLGResolutionEvidence(varchar,text)` and
  `AssignDOCEFLItemClass(varchar,varchar)`, each to `sibyla_piece_c_executor` only, each preceded by
  `REVOKE ALL ... FROM PUBLIC` — the same pattern every accepted P1-1a governed command uses.
- **0 new tables, 0 new columns, 0 new triggers, 0 new constraints, 0 new indexes** on any accepted
  object. The only "table" surface in `Up` is two command-scoped `CREATE TEMP TABLE ... ON COMMIT
  DROP` working tables (`PieceCAffectedCompanies`, `PieceCCompletedSnapshots`), which never persist
  past the transaction and appear in no catalog snapshot.
- **`Down`**: drops both new functions, restores `RejectTerminalDOCFLGMutationFn`'s accepted
  definition exactly (verbatim source, byte-for-byte), drops the role. No `DROP OWNED`, no ownership
  change of any object this piece did not create.

### Checklist disposition — all 20 items, as amended by Option-B, each with its exact proof

| # | Item | Disposition and exact proof |
|---:|---|---|
| 1 | Preflight checks 1–5, check 6 non-adoption | **Pass.** Re-run fresh above. |
| 2 | Exact base-to-candidate surface; byte-identical accepted files/functions | **Pass.** `git diff --stat` against the 6 accepted P1-1a/Piece A/Piece B migration files shows zero changes (verified this session). `Piece_c_sql_is_command_and_role_surface_only_and_exactly_scoped` (contract) asserts exact role/function/grant surface and that `RequireActiveCompanyRegistryFn` is never defined/replaced. `Piece_c_accepted_functions_are_byte_identical_except_the_one_approved_exception` (disposable) proves live: `WaiveDOCFLG`, all 4 Piece B trigger functions, and **`RequireActiveCompanyRegistryFn`** byte-identical Piece-B-tip-to-latest; `RejectTerminalDOCFLGMutationFn` provably different, containing the approved GUC only after `Up`. |
| 3 | Minimal-surface discipline | **Pass.** Same contract test's negative assertions (no `ALTER`/`DROP` of any accepted table, no untouched trigger/function redefined). |
| 4 / 17 | Closed D8 vocabulary, closed twice | **Pass.** `Piece_c_assign_item_class_enforces_the_closed_d8_vocabulary_at_the_command_boundary` (contract) + `Piece_c_assign_item_class_rejects_unknown_item_class_literal` (disposable): command-boundary rejection with zero rows touched; the accepted `DOCEFL` `CHECK`/A-R1 validator gate remain the untouched second barrier. |
| 5 / 18 | Atomic `NULL`-only completion; non-null never modified | **Pass.** `Piece_c_assign_item_class_completes_null_snapshots_only_and_excludes_non_null_from_count`: two separate rules (the composite FK makes a same-rule non-null-different-value row structurally impossible to construct, so cross-rule isolation is the operative proof); the `NULL` row completes, the other rule's already-classified row and its provenance are provably byte-for-byte unchanged, audited count is exactly 1. |
| 6 | Provenance co-update; no delete/reinsert; no `SET CONSTRAINTS` | **Pass.** `Piece_c_assign_item_class_sql_contains_no_delete_reinsert_or_set_constraints` (contract, scoped precisely to `AssignDOCEFLItemClass`'s own body) + live hash assertion in item 5's test. |
| 7 | Audit states rule/value/actor/exact count; validator deltas exact | **Pass.** `Piece_c_assign_item_class_audit_states_rule_value_actor_and_exact_per_company_count` (one audit row per active affected company, exact per-company counts, context company's row carries the empty skip array, other companies' rows do not) and `Piece_c_assign_item_class_reduces_validator_findings_by_exact_audited_count` (raw `DOCEFL`/`DOCFLG` absent-`ItemClass` counts drop by exactly 1 and 2). |
| 8 | Evidence-append command | **Pass — now unblocked.** `Piece_c_evidence_append_completes_absent_evidence_only_on_imported_terminal_rows` and `Piece_c_evidence_append_never_overwrites_existing_evidence`: the approved narrow exception (Observation 1 option B) is implemented exactly as approved, with the generated-column comparison bug found and fixed this session (see below). |
| 9 / 19 | Server-side principal only; forged-GUC and non-owner-role denial, each command | **Pass.** `Piece_c_assign_item_class_ignores_forged_actor_and_authority_guc`, `Piece_c_evidence_append_ignores_forged_actor_and_authority_guc`, `Piece_c_assign_item_class_denied_to_non_owner_role`, `Piece_c_evidence_append_denied_to_non_owner_role` — 4 tests, all passing. |
| 10 | R1 fail-closed role provisioning | **Pass.** `Piece_c_up_fails_closed_when_expected_role_already_exists` (hostile pre-existing role, `MigrateAsync` throws, no partial state) and `Piece_c_up_creates_roles_fresh_on_normal_path` (fresh role, correct attributes). |
| 11 | R6 company scope — corrected (all-or-nothing, active only) and amended (Option-B inactive shape) | **Pass.** `Piece_c_assign_item_class_fails_closed_atomically_when_any_affected_company_is_unauthorized` (one unauthorized active company ⇒ zero changes anywhere, including the two authorized companies), `Piece_c_assign_item_class_authorized_for_every_affected_company_completes_all_atomically` (positive control, 3 active companies), `Piece_c_assign_item_class_inactive_affected_company_authorization` (inactive company's row provably unchanged, **zero** `P11aCommandAudit` rows for it, the active context company's own audit row carries the exact `skippedInactiveCompanies` evidence: `reason":"inactive"`, `completedCount:0`, exact `observedNullCount`). |
| 12 | R3 genuine concurrency, both orderings | **Pass.** `Piece_c_assignment_locks_parent_first_then_import_reads_the_assigned_value` and `Piece_c_import_locks_parent_first_then_assignment_completes_the_new_row`, both using a real parent-row `FOR UPDATE` lock and a deterministic, PID-scoped `pg_stat_activity.wait_event_type='Lock'` poll (`WaitForBackendBlockedOnLock`) — replacing the prior query-text-fragment matching, which was fragile because a governed-command call's `pg_stat_activity.query` shows the caller's outer submitted statement, not the function's inner blocked statement. |
| 13 | R7 — `ImportEvidenceRow` uniqueness untouched | **Pass.** `Piece_c_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_c_up`, reusing the existing helpers unmodified, re-run a third time. |
| 14 | Generated columns (A-R2 shape) | **Documentation obligation, satisfied vacuously.** `Up` adds no table or column (Observation 1 resolved to option B, not the evidence-log table). |
| 15 | R2 scoped `Down`; Up/Down/Up catalog stability | **Pass.** `Piece_c_down_is_exact_and_up_down_up_is_catalog_stable` — widened snapshot covering the role, its ACL, and the 4 relevant function bodies (including `RequireActiveCompanyRegistryFn`, for extra Up/Down/Up drift assurance beyond what was strictly required). |
| 16 | Closed vocabularies close twice, where they exist | **Documentation obligation.** No new closed vocabulary introduced beyond D8 (item 4). |
| 20 | Claims equal assertions | **Satisfied by this table itself** — every figure below is measured this session, not projected; the exact role/function/grant roster above was fixed when `Up` was authored and is reported item by item. |

### Prior-session TDD defects — fixed, not suppressed

- **Generated-column comparison bug** (item 8): `RejectTerminalDOCFLGMutationFn`'s narrow-exception
  whole-row comparison originally compared `NEW` against `OLD`-with-`ResolutionEvidence`-swapped
  directly, but PostgreSQL has not yet recomputed a `STORED GENERATED` column (`ImportTargetTable`)
  on `NEW` inside a `BEFORE UPDATE` trigger, so the comparison always mismatched. Root-caused this
  session via a temporary `RAISE NOTICE`-instrumented copy of the function run against a live
  disposable container (removed before any commit); fixed by excluding `ImportTargetTable` from the
  comparison, matching `NEW`'s actual (not-yet-generated) state on both sides.
- **Concurrency proof fragility** (item 12): replaced query-text-fragment matching (which cannot see
  inside a governed-command call's own blocked statement) with PID-scoped `pg_stat_activity` polling.
- **Fixture defects** (found and fixed this session, all confirmed via direct `psql` reproduction
  against a live disposable container before being fixed in the C# fixtures): the composite
  `DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey` requires a non-null `DOCFLG.ItemClass`
  to match its own `DOCEFL` parent's **current** `ItemClass` exactly, so every `DOCEFL` fixture row
  now carries matching `ReviewPriority`/`BlockingLevel` from creation, and item 5's "non-null, must
  not be touched" proof uses a second, already-classified rule rather than a same-rule row (which
  the FK makes impossible to construct); `DOCFLG`'s same-row `CHECK` (`Open`/`InReview` status
  requires `ItemClass='Decision'` or `NULL`) means every fixture assigning a non-`Decision` class now
  avoids leaving an `Open`-status row with a different class; `SourceTextHash` is now derived
  per-row from the flag ID (the accepted unique constraint collided when multiple rows shared
  `EFCode`/entity/`now()`); `ImportBatch.CompanyId` is now looked up from `CompanyRegistry` by
  `CompanyCode` rather than re-derived from a mismatched label.
- **Shared-database pollution of pre-existing full-down-migration tests**: three tests that migrate
  all the way down past Piece A (`Piece_a_down_is_exact_and_up_down_up_is_catalog_stable`,
  `Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up`,
  `Down_removes_only_owned_objects_restores_legacy_writes_and_up_reapplies`) require that **no**
  permanent `DOCFLG` row anywhere in the shared disposable database has a `NULL` `ItemClass` or a
  terminal status with blank `ResolutionEvidence`, because Piece A's `Down` restores the pre-Piece-A
  `NOT NULL`/`DOCFLG_check1` constraints. Every Piece C test that must, as its own core proof, leave
  such a row (the unauthorized-company negative controls; the inactive-company skip proof) now adds
  an explicit recovery/cleanup step **after** its real assertions — granting the missing membership
  and re-invoking the governed command for the authorization tests; reactivating the company and
  proving it usable again via a fresh rule, then a direct, explicitly-commented, non-product
  co-update of the one row whose "stays `NULL`" state is the test's own subject, for the
  inactive-company test — so no permanent incompatible row survives. Root-caused this session via a
  direct `psql` query against a live disposable container listing every such row after a full run
  (found exactly one: the inactive-company test's own subject row), not by guesswork.
- **Reader-scope bug**: one test (`Piece_c_assign_item_class_inactive_affected_company_authorization`)
  originally kept an `await using var reader` open at method scope while issuing further commands on
  the same connection during its recovery step, causing `NpgsqlOperationInProgressException`; fixed
  by scoping the `reader`/`command` to an explicit block that disposes before the recovery step.

### Measured verification — this session, reproduced twice for the disposable suite

| Verification | Result |
|---|---:|
| `dotnet build GOTT.Sibyla.slnx -c Release --no-incremental` | **0 Warnings, 0 Errors** |
| Ordinary `dotnet test` | **646/646** (640 accepted baseline + 6 new Piece C contract tests) |
| Focused (`P11bPieceCContractTests`) | **6/6** |
| Disposable PostgreSQL 17 suite (`Category=P11aDatabase`) | **55/55** (34 accepted baseline: 16 Piece A + 18 Piece B; 21 new Piece C), reproduced twice, same result both times |
| `git diff --check` | clean |
| Accepted P1-1a, Piece A, Piece B migration files (6 paths) | byte-identical — `git diff --stat` against each shows zero changes |
| `WaiveDOCFLG`, all 4 Piece B trigger functions, `RequireActiveCompanyRegistryFn` | byte-identical Piece-B-tip-to-latest, live `pg_get_functiondef` |
| `RejectTerminalDOCFLGMutationFn` | provably different (the one approved exception), live `pg_get_functiondef` |
| `ImportEvidenceRow` unique constraints and indexes | identical Piece-B-tip-to-latest |
| Up/Down/Up catalog stability (role, ACL, 4 function bodies) | proven stable |
| Diff-restricted scan of added lines for `CREATE ROLE`/`SECURITY DEFINER`/`GRANT`/`REVOKE`/`DROP OWNED`/secret-shaped strings | only the expected `sibyla_piece_c_executor` and the test-only `sibyla_piece_c_non_owner_probe`/hostile-role probe; nothing else |
| Residual `sibyla-p11*` containers | **0**, confirmed after every container this session |
| Prototype repository operations | **0** — read-only preflight only |

### What remains

Piece C now has an implementation candidate, not an accepted implementation. **The mandatory fresh
independent adversarial review (ordered instruction 4) has not begun** and must run in a separate
session before any Accept/Reject verdict exists. This session does not self-review, does not issue a
verdict, and does not start Piece D, Scope 1, or O5-prep.

## 2026-08-06 Piece C Option-B amendment — inactive-affected-company audit shape changed; `RequireActiveCompanyRegistryFn` remains untouched; implementation authorized to resume

This step performs the decision gate the stop record at `a8eff3d3b4355d38499c72187f4e6b1bbf315ce9`
requested: Miguel has chosen between the offered options for the `RequireActiveCompanyRegistryFn`
collision. It is a governed records commit, pushed before any code, per the amendment-5 rule.

### Miguel's exact words, and what they authorize

**Miguel's exact words in this conversation:** "Aprovo B — alterar o requisito de audit da empresa
inativa" — recorded verbatim, in full; no additional words are attributed to him and none are
fabricated.

**What this is, precisely.** This is approval of **Alternative B** from the stop record's proposed
resolutions: the inactive-affected-company **audit requirement is amended**. It is explicitly **not**
authorization for Option A or for any modification to `RequireActiveCompanyRegistryFn`. No waiver of
checklist item 2 or minimal-surface discipline is granted for that function, or for any function
beyond the one already-approved exception to `RejectTerminalDOCFLGMutationFn` (Observation 1 option
B, approved separately at `9a4a270…`). `RequireActiveCompanyRegistryFn` **remains byte-identical and
unmodified** — this is proven the same way every other "unchanged" claim in this piece is proven:
live `pg_get_functiondef` comparison, asserted in a disposable test, both before and after Piece C's
`Up`.

### The precise superseding contract — no hidden contradiction

This supersedes only the inactive-affected-company sub-case of checklist items 5, 7, 11, and 12, and
Observation 2b, as corrected below. Every other part of the corrected mapping (items 1–4, 6, 8–10,
13–20, and Observations 1, 2a, 3, 4, 5, 6) is unchanged and remains in force exactly as recorded in
the entry below this one.

1. **`RequireActiveCompanyRegistryFn` is out of scope, permanently, for this piece.** No `CREATE OR
   REPLACE`, no new exception, no waiver request. It is proven byte-identical before/after `Up`
   alongside `WaiveDOCFLG` and every Piece B trigger function, exactly as originally planned before
   the collision was discovered.
2. **An inactive affected company's `DOCFLG` rows are outside `AssignDOCEFLItemClass`'s mutable
   completion set.** They are never included in the `UPDATE` that completes `NULL` snapshots; they
   remain byte-identical, including `ItemClass IS NULL` where that was already their state. The
   command never attempts a `P11aCommandAudit` row under an inactive company's `CompanyCode` — not
   attempted-then-blocked (as in the discovered collision), but never attempted at all, by design.
3. **Skip evidence, not a separate audit row.** The calling **context** company's own
   `P11aCommandAudit` row (the row for `v_ctx.company_code` — always active, since
   `P11aCurrentActor` already requires that) carries a `"skippedInactiveCompanies"` array in its
   `Details`, fixed now as the exact shape: one element per skipped inactive affected company,
   `{"companyCode": <code>, "reason": "inactive", "completedCount": 0, "observedNullCount": <exact
   count of that company's still-`NULL` `DOCFLG` rows for this `EFCode`>}`. The array is always
   present (empty `[]` when no affected company is inactive), never omitted, so its absence never has
   to be interpreted. This is audit evidence that the skip happened and exactly what was skipped — it
   is **not** a claim that the inactive company received its own audit row, and no other company's
   audit row carries this field.
4. **The all-or-nothing authorization gate (Observation 2a) now applies only to active affected
   companies.** An inactive affected company is excluded from the "every affected company must have
   `RuntimePrincipalCompany` membership" requirement entirely — it is excluded **before** membership
   is even considered, because inactivity itself removes it from the set the command may write to,
   independent of who is asking. Ordinary membership in an inactive affected company is no longer
   meaningful and is not checked. For every **active** affected company, the prior contract is
   unchanged exactly as approved: authority for **all** active affected companies, or **zero**
   mutation and **zero** audit rows anywhere for the call; every eligible (active, `NULL`) snapshot
   completes atomically; one exact `P11aCommandAudit` row per active affected company; a non-null
   snapshot is never modified.
5. **Validator deltas and completion counts** (item 7) reduce by exactly the count of rows actually
   completed — active eligible rows only. A skipped inactive company's `NULL` snapshots remain
   visible as open findings (`DOCFLG snapshot ItemClass absent`) after the call; they are not, and
   must not be asserted as, part of the audited completed count.
6. **R3's "no unaudited `NULL` snapshot survives" assertion (item 12)** is scoped to active eligible
   companies. An inactive affected company's rows remaining `NULL` after the call is correct,
   by-design behaviour, not a survivor in the sense item 12 guards against; it is accounted for
   separately via the skip evidence in (3), not via the zero-`NULL`-survivor count. Item 12's two
   existing concurrency tests never involved an inactive company and are unaffected by this scoping
   clarification.
7. **Item 11's test mapping is corrected**, replacing the prior two-branch "(i) ordinary membership
   suffices / (ii) elevated authority required" framing (which depended on Observation 2b, now
   superseded) with the single fixed behaviour: `Piece_c_assign_item_class_inactive_affected_company_authorization`
   now asserts (a) the inactive company's `DOCFLG` row is unchanged, still `NULL`; (b) **no**
   `P11aCommandAudit` row exists with that inactive company's `CompanyCode`; (c) the context (active)
   company's own audit row's `Details` contains the `"skippedInactiveCompanies"` entry with
   `"reason":"inactive"`, `"completedCount":0`, and the exact `"observedNullCount"`. The existing
   active-company positive control
   (`Piece_c_assign_item_class_authorized_for_every_affected_company_completes_all_atomically`) and
   the existing unauthorized-active-company atomic negative
   (`Piece_c_assign_item_class_fails_closed_atomically_when_any_affected_company_is_unauthorized`)
   are unchanged by this amendment — neither test involves an inactive company.
8. **This amendment authorizes resuming implementation** (ordered instruction 3) from this pushed
   records tip, TDD first, recreating the candidate from zero rather than restoring any previously
   deleted file as authoritative. No independent review has begun and none begins here.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, role, grant, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `a8eff3d3b4355d38499c72187f4e6b1bbf315ce9`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it.

## 2026-08-06 Piece C implementation — stopped before a candidate exists: accepted `RequireActiveCompanyRegistryFn` blocks the approved inactive-company audit requirement

This step is a **stop-and-report**, not further implementation. TDD was started from the approval
tip `9a4a270caccf16ce04fa8d7d7cfa69c8fdf238f1` (ordered instruction 3). It is stopped here because a
governing collision with an accepted, untouchable P1-1a object was discovered that the approved
mapping and its six adopted resolutions did not anticipate and did not authorize a waiver for.
**No implementation candidate exists**: all uncommitted Piece C code/test files have been deleted
and the one modified tracked file has been restored byte-exactly to this approval tip; see the
cleanup section below. This records the blocker, the exact observed TDD evidence, a proposed (not
adopted) resolution, and the cleanup performed, and asks Miguel for an explicit decision before any
further implementation attempt.

### The blocker — confirmed against live evidence and the accepted schema, read-only

**Confirmed fact:** `"RequireActiveCompany_P11aCommandAudit" BEFORE INSERT OR UPDATE ON
"P11aCommandAudit" FOR EACH ROW EXECUTE FUNCTION "RequireActiveCompanyRegistryFn"('CompanyCode')`
(`P11aSchemaSql.cs:1539`, calling the accepted, untouched `RequireActiveCompanyRegistryFn` at
`P11aSchemaSql.cs:1527`) unconditionally rejects **any** `INSERT` into `P11aCommandAudit` whose
`CompanyCode` resolves to an inactive `CompanyRegistry` row. This is the same trigger family as
`"RequireActiveCompany_DOCFLG"` (already known to block writes to an inactive company's `DOCFLG`
rows) — it is not a new function, not created by Piece C, and not named by any part of the approved
mapping as available for modification.

**Live reproduction, this session, disposable PostgreSQL 17:** calling `AssignDOCEFLItemClass` for a
scenario with one active and one inactive affected company (per the approved item 11 / Observation
2b design: ordinary `RuntimePrincipalCompany` membership authorizes the inactive company, ordinary
membership was granted, the call attempted to record its own audit row for the inactive company)
raised:

```
Npgsql.PostgresException: 23503: active CompanyRegistry mapping is required for P11aCommandAudit
Where: PL/pgSQL function "RequireActiveCompanyRegistryFn"() line 7 at RAISE
SQL statement "INSERT INTO "P11aCommandAudit" ...
```

**Why this is a stop, not a test-only defect.** The approved mapping's item 11 requires the command
to "audit **every** affected company — including inactive ones — with exact per-company completion
counts," and Miguel's approval of Observation 2b adopted ordinary membership as sufficient authority
for an inactive affected company specifically so that it **would** be audited. The only waiver this
session's approval recorded was the exact, narrow `CREATE OR REPLACE` of `RejectTerminalDOCFLGMutationFn`
(Observation 1 option B) — nothing authorizes touching `RequireActiveCompanyRegistryFn` or any other
accepted P1-1a object, and minimal-surface discipline (item 3) makes an unnamed touch a stop-and-report
by its own terms. **The approved mapping therefore cannot be satisfied as written**: writing the
required audit row for an inactive affected company is exactly as structurally impossible under the
accepted schema as writing to its `DOCFLG` rows already was. This is a second, independent instance
of the same class of discovery, this time reaching `P11aCommandAudit` itself, not only `DOCFLG`.

**Not adopted, not worked around.** No fallback was implemented: the uncommitted candidate did not
silently record the inactive company's audit under the active context company, did not temporarily
reactivate the company, did not omit the audit row without reporting it, did not modify
`RequireActiveCompanyRegistryFn`, and did not invent a new table to hold the audit instead. All
uncommitted code implementing any of these has been deleted; see cleanup below.

### Observed TDD evidence — recorded exactly, not claimed fixed

The last disposable run before this stop (`scripts\run-p11a-disposable-tests.ps1`-equivalent,
disposable PostgreSQL 17): **47 passed, 8 failed, 55 total, 42s.** The log this was read from has
since been deleted per the cleanup mandate below; the following is transcribed from it before
deletion and is reported as exactly what was observed, not as a diagnosis of root cause beyond what
the error text itself states.

| Failed test | Exact observed error |
|---|---|
| `Piece_c_assign_item_class_inactive_affected_company_authorization` [400 ms] | `23503: active CompanyRegistry mapping is required for P11aCommandAudit` — the blocker above |
| `Piece_c_assign_item_class_fails_closed_atomically_when_any_affected_company_is_unauthorized` [808 ms] | `23503: insert or update on table "DOCFLG" violates foreign key constraint "DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey"` |
| `Piece_c_assign_item_class_completes_null_snapshots_only_and_excludes_non_null_from_count` [226 ms] | `23503: insert or update on table "DOCFLG" violates foreign key constraint "DOCFLG_EFCode_ItemClass_ReviewPriority_BlockingLevel_fkey"` |
| `Piece_c_evidence_append_completes_absent_evidence_only_on_imported_terminal_rows` [104 ms] | `23514: terminal DOCFLG rows are append-only` (raised by `RejectTerminalDOCFLGMutationFn`) |
| `Piece_c_import_locks_parent_first_then_assignment_completes_the_new_row` [10 s] | `System.Threading.Tasks.TaskCanceledException: A task was canceled.`, raised from the test's own `WaitForBackendBlockedOnDocflgParentLock` polling helper timing out |
| `Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up` [541 ms] | Not re-extracted from this exact run before the log was deleted. An earlier round in this same session observed `23502: column "ItemClass" of relation "DOCFLG" contains null values` for this test; consistent with residual `NULL` `DOCEFL`/`DOCFLG` rows left in the shared disposable database by other still-failing Piece C tests in the same run, but this specific run's exact text is not independently confirmed here |
| `Piece_a_down_is_exact_and_up_down_up_is_catalog_stable` [370 ms] | Same caveat as immediately above |
| `Down_removes_only_owned_objects_restores_legacy_writes_and_up_reapplies` [330 ms] | Same caveat as immediately above |

**No claim of fix.** These eight failures — the governing blocker aside — are recorded as observed
TDD-stage defects in the deleted, uncommitted candidate. None is claimed resolved. No code exists to
resolve them against, per the cleanup below; a future implementation attempt starts from the
approval tip and TDD again.

### Proposed resolution — offered for Miguel's decision, not adopted

**Option A (recommended for consideration, not authorized):** a narrow amendment permitting Piece
C's own migration to `CREATE OR REPLACE` `RequireActiveCompanyRegistryFn` with an additional,
command-scoped exception — structurally the same shape already approved for
`RejectTerminalDOCFLGMutationFn` (Observation 1 option B) — permitting exactly one case: a
`P11aCommandAudit` `INSERT` referencing an inactive company, gated by a transaction-local GUC that
`AssignDOCEFLItemClass` sets to the exact company code being audited immediately before that one
`INSERT`, checked against the row being inserted. Every other call path through
`RequireActiveCompanyRegistryFn` (every other trigger in the same family, on every other table)
keeps the unconditional active-company requirement unchanged. `Down` would restore the accepted
definition exactly, proven the same way `RejectTerminalDOCFLGMutationFn` is proven (live
`pg_get_functiondef` byte-identical before/after `Down`). Because command roles are never granted
direct `INSERT` on `P11aCommandAudit` (only `EXECUTE` on the two governed functions), a
forged-GUC-plus-direct-DML exploit would require a role with independent table-level `INSERT`
privilege on `P11aCommandAudit` in the first place — the same boundary condition already proven for
`RejectTerminalDOCFLGMutationFn`'s exception, provable the same way. This requires an **explicit
waiver of checklist item 2 and minimal-surface discipline for this one additional named function**,
on the same governed basis as Observation 1 — not implied by anything already approved.

**Alternative B:** amend item 11 / Observation 2b's audit shape instead of the trigger function —
e.g., accept that an inactive affected company is authorized and its `DOCFLG` write is skipped, but
its audit is recorded differently (a documentation-only note in the `Details` of the *context*
company's own audit row, naming the skipped inactive company and its zero count, rather than a
separate `P11aCommandAudit` row that the accepted schema cannot accept). This requires no additional
function waiver but changes what "audits every affected company" is read to mean.

**Alternative C:** any other resolution Miguel specifies, including deferring the inactive-company
sub-case entirely to a later piece.

**Neither A, B, nor C is adopted here.** This is a report of options with a recommendation clearly
labelled as such, per the same discipline every prior observation in this piece's mapping used.

### Cleanup performed

- **Process check:** one sleeping PowerShell process (`Start-Sleep -Seconds 480` then a
  docker/memory/external-endpoint check) was found running with a parent `claude.exe` process
  (PID 2404). This session's own PowerShell invocations run under a **different** parent `claude.exe`
  process (PID 11704). The sleeping process therefore belongs to a different session, not this one,
  and was **not** terminated.
- **Containers:** `docker ps -a --filter "name=sibyla-p11"` listed **12** residual containers, all
  `Exited`, none `Running`. All 12 were removed (`docker rm -f`); a repeat listing confirmed **0**
  residual `sibyla-p11*` containers, running or exited.
- **Working tree:** `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` (the only tracked
  file with uncommitted changes) was restored byte-exactly via `git restore` (not
  reset/revert/rebase/amend/force) to its content at `9a4a270`. The three untracked Piece C
  implementation/test files
  (`src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceCSchemaSql.cs`,
  `src/Sibyla.Infrastructure/Persistence/Migrations/20260806200000_P11bPieceCGovernedCommands.cs`,
  `tests/Sibyla.Tests/Persistence/P11bPieceCContractTests.cs`) and the three untracked temporary log
  files (`disposable-run.log`, `full-disposable-output.log`, `t09-debug.log`) were deleted. `git
  status` now reports a clean working tree with no changes relative to `9a4a270`, verified
  immediately before this records commit.

### State summary

**Approval commit `9a4a270caccf16ce04fa8d7d7cfa69c8fdf238f1` remains valid and recorded** — Miguel's
approval of the corrected mapping and all six adopted resolutions is not reopened or withdrawn by
this stop. **No Piece C implementation candidate exists, committed or uncommitted.** No independent
adversarial review (ordered instruction 4) has begun or could begin, because there is nothing to
review. Piece C implementation is blocked pending Miguel's explicit decision on the newly discovered
`RequireActiveCompanyRegistryFn` collision (option A, B, C above, or another Miguel specifies).

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, role, grant, constraint, trigger, fixture, or test paths changed | **0** (all Piece C candidate paths deleted, not committed) |
| `git diff --check` | clean |
| Working tree relative to approval tip `9a4a270`, immediately before staging this commit | clean, byte-identical |
| Residual `sibyla-p11*` containers | **0**, confirmed after removing 12 |
| Prototype repository operations | **0** |

No build or test figures are claimed as current for this stage: the last measured figures (47
passed / 8 failed / 55 total) are reported above as historical TDD evidence from the now-deleted
candidate, not as a state of any code that currently exists.

### Requested decision

**Miguel's explicit decision is requested** on the `RequireActiveCompanyRegistryFn` collision before
any further Piece C implementation attempt: approve option A (the narrow command-scoped exception,
with its own explicit item 2/minimal-surface waiver), approve option B (amend the audit shape
instead), specify option C, or return with corrections. No implementation, migration, model, test,
fixture, database, container, role, grant, or prototype work will resume until that decision is
recorded.

## 2026-08-06 Piece C test-plan mapping — Miguel's approval recorded; six adopted resolutions; implementation authorized

This step performs **ordered instruction 2's approval gate close-out** for
`docs/AGENT-PROMPT-v5-P1-1b-piece-c-goahead.md`: it records Miguel's approval of the corrected
mapping pushed at `c146e57fe4771fb769f9c7867559cfd4810d1ff5` and the six resolutions adopted under
it, and authorizes ordered instruction 3 (implementation, TDD first). It is a governed records
commit, pushed before any code, per the amendment-5 rule that a records commit touching
`p1-1b-status.md` updates `PROJECT-STATE.md` in the same commit.

### Miguel's exact words, and the interpretation recorded for this run

**Miguel's exact words in this conversation:** "aprovo mapping" — recorded verbatim, in full; no
additional words are attributed to him and none are fabricated.

**Why an interpretation is needed.** The orchestrator asked, before recording this approval, whether
"aprovo mapping" was intended to cover every one of the corrected mapping's currently recommended
resolutions across its six observations, or only the mapping's structure/checklist itself. The
clarification UI timed out before Miguel could answer that follow-up, and the orchestrator was
instructed to proceed on its own best judgement rather than block indefinitely.

**The authoritative interpretation adopted for this run**: "aprovo mapping" approves the corrected
mapping at `c146e57…` **in full**, including each of its currently recommended resolutions, exactly
as follows — this interpretation, not a longer quote, is what is acted on:

- **Observation 1 — option B adopted.** Piece C's migration may `CREATE OR REPLACE` the accepted
  `RejectTerminalDOCFLGMutationFn`, adding the exact narrow `sibyla.docflg_evidence_append_id`-gated
  exception described in the corrected mapping and nothing else. This is an **explicit waiver of
  checklist item 2's byte-identical-function requirement for this one named function only** — every
  other accepted function, and item 2's byte-identical requirement for every other named function
  and for the accepted P1-1a/Piece A/Piece B migration source files, remains in force unchanged. This
  waiver is also the **explicit item-3 authorization** naming this exact change, satisfying
  minimal-surface discipline's own escape clause. `Down` must restore
  `RejectTerminalDOCFLGMutationFn`'s accepted definition exactly (proven the same way Piece B proved
  `WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn` byte-identical: live `pg_get_functiondef` comparison
  against the pre-Piece-C definition). No other accepted function or object definition changes.
- **Observation 2a adopted.** `AssignDOCEFLItemClass` authorizes company writes by per-company
  `RuntimePrincipalCompany` membership for **every** affected company, checked before any write, with
  atomic all-or-nothing behaviour: any missing membership for any affected company means **zero**
  changes and **zero** audit rows anywhere for that call. No new "all-companies" authority literal is
  introduced.
- **Observation 2b adopted.** Ordinary, explicit `RuntimePrincipalCompany` membership remains valid
  authority to write an affected company's `DOCFLG` snapshots even when that company is itself
  inactive (`CompanyRegistry."Active"=false`). The calling actor still authenticates through its own
  active **context** company via `P11aCurrentActor`, unchanged; `CompanyRegistry."Active"` is **not**
  used as an authorization filter over the set of companies **affected by** the write.
- **Observation 3 adopted.** The evidence-append command's exact name and signature is
  `AppendDOCFLGResolutionEvidence(p_flag_instance_id varchar, p_evidence text)`.
- **Observation 4 adopted.** The role/ACL shape is approved now; the exact role name, attributes, and
  grant roster are fixed when `Up` is authored during TDD and reported item by item in the
  implementation's evidence map, exactly as Pieces A and B's own equivalent observations were
  approved and then closed.
- **Observation 6 adopted.** Both `AssignDOCEFLItemClass` and any future importer's contract use
  `SELECT 1 FROM "DOCEFL" WHERE "EFCode"=$1 FOR UPDATE` before reading `ItemClass` or writing any
  `DOCFLG` row for that `EFCode`, held until the transaction commits. This is the minimal shared
  parent-lock protocol the corrected item 12 concurrency tests are written against.

### What is now authorized

**Piece C implementation is now authorized** — ordered instruction 3, TDD first, from this pushed
approval tip, applying the corrected 20-item mapping and all six adopted resolutions above exactly,
no other content change; an apparent need beyond them is a stop-and-report, not an improvisation.
**The mandatory fresh independent adversarial review (ordered instruction 4) has not yet begun** and
will run in a separate session after implementation is committed and pushed.

Nothing here changes a decision or a baseline. The five expected completeness baselines remain
**119 / 119 / 52 / 221 / 2,787**, the two pinned `Routine` rows still import verbatim, and the
immutable source pin remains `b91768513fc638381fbde91f0b576b08220a98f6`.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, role, grant, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `c146e57fe4771fb769f9c7867559cfd4810d1ff5`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it.

## 2026-08-06 Piece C test-plan gate — checklist→test mapping, adversarial command proofs, and observations, corrected, awaiting Miguel's approval

This step performs **ordered instruction 2 of `docs/AGENT-PROMPT-v5-P1-1b-piece-c-goahead.md`
only**: it records the Piece C checklist→test mapping required by the test-plan gate. It does
**not** perform ordered instruction 3 (implementation) or ordered instruction 4 (the first
independent adversarial review of this piece), and it does not re-run the amendment-4 preflight,
which belongs to instruction 3. **Implementation remains unauthorized until Miguel explicitly
approves this mapping.** The instruction to record it is not approval of it.

**Correction, same-day follow-up, this normal additive commit.** After this mapping was first
recorded and pushed, an independent review found three internal contract/proof defects, corrected
below in place — git history is not rewritten; this is a new commit on top of the original, and all
other mapping content is unchanged: **(1)** Observation 1 understated the collision it found —
option A (a separate evidence-log table) does not literally satisfy checklist item 8 and may alter
O9-D5's own governed contract, and both options now require an explicit Miguel checklist/authority
amendment before item 8 can be implemented at all, not merely a recommendation between two
already-compliant designs. **(2)** Item 11's R6 mapping wrongly allowed the command to silently
complete an authorized subset of affected companies while skipping the rest — that is not
fail-closed and conflicts with items 5 and 7's own atomicity/exact-count requirements; corrected to
require all-or-nothing behaviour, with the inactive-affected-company authorization question now
surfaced as its own explicit decision rather than assumed. **(3)** Item 12's two concurrency tests
relied on a blind, uncoordinated second-connection `INSERT` that neither models nor proves the
required parent-lock serialization; corrected to a real shared parent-row-lock protocol with
deterministic (non-timing-based) blocking proof, and the importer's exact lock contract — previously
asserted as "resolved by necessity" — is corrected to an open decision reported to Miguel.

Nothing here changes a decision or a baseline. The five expected completeness baselines remain
**119 / 119 / 52 / 221 / 2,787**, the two pinned `Routine` rows still import verbatim, and the
immutable source pin remains `b91768513fc638381fbde91f0b576b08220a98f6`. The monolithic rejects
`b324a3e…`, `57f0f023…`, and `7ea6c0f…`, and rejected piece candidates `6f86023d…` and `b8fa033…`,
remain neutralized evidence only.

**Read-only inspection performed for this mapping** (no write of any kind; `Read`/`Grep` only):

- `P11aSchemaSql.cs` — `P11aCurrentActor(p_authority text)` (lines 78–100): derives `actor` from
  `RuntimePrincipal`/`RuntimePrincipalAuthority` rows keyed by `session_user`, never from any
  caller-set GUC; `RuntimePrincipal`/`RuntimePrincipalAuthority` are `REVOKE ALL ... FROM PUBLIC`.
  Every governed command (`AllocatePermanentCode` line 149, `ActivateDOCEFLRule` line 409,
  `WaiveDOCFLG` line 1495, etc.) opens with `SELECT * INTO v_ctx FROM "P11aCurrentActor"('<authority>')`
  and ends `REVOKE ALL ON FUNCTION ... FROM PUBLIC`. **No `CREATE ROLE` exists anywhere in
  `P11aSchemaSql.cs`, `P11bPieceASchemaSql.cs`, or `P11bPieceBSchemaSql.cs`** — every accepted
  `SECURITY DEFINER` function runs under ownership, not a granted application role; two existing
  contract tests (`P11bPieceAContractTests.cs:25`, `P11bPieceBContractTests.cs:86`)
  affirmatively assert **no** `CREATE ROLE` in Pieces A/B. R1's role surface is therefore wholly
  new territory for this piece, not an extension of an existing pattern.
- `P11aDisposableDatabaseTests.cs:650` (`Permanent_code_allocation_burns_rollback_crash_and_concurrency_loser_values`)
  and its private `Allocate` helper (line 2488): the exact forged-GUC pattern
  (`set_config('sibyla.actor','forged-allocation-actor',true)`,
  `set_config('sibyla.authorities','AllocatePermanentCode',true)`) this mapping's item 9 reuses.
  The same test is also the repository's one existing genuine two-real-connection concurrency
  proof (lines 700–711: an open, uncommitted transaction on connection #1 racing a real concurrent
  call on connection #2, synchronized by polling helper `WaitForSequenceHighWater`, lines
  2508–2536) — the pattern item 12 reuses.
- `P11aSchemaSql.cs:379` — `DOCEFL."ItemClass" varchar(16) NOT NULL CHECK ("ItemClass" IN
  ('Decision','Status','Annotation'))` (D8's closed vocabulary, already the accepted database
  barrier); `P11bPieceASchemaSql.cs:8–41` — Piece A's nullability relaxation and
  `CK_DOCFLG_TerminalResolutionEvidence`/`CK_DOCFLG_ProspectiveSnapshot` CHECKs. `DOCFLG."Company"`
  (not `CompanyId`) is the FK column to `CompanyRegistry."CompanyCode"` (`P11aSchemaSql.cs:598`).
- `P11aSchemaSql.cs:25–37` — `CompanyRegistry` (`Active boolean`, one-active-row-per-company partial
  unique index) and the `P11aCurrentActor` company check (lines 93–96): it validates **exactly one**
  `(company_id, company_code)` pair against `RuntimePrincipalCompany`, even though
  `RuntimePrincipalCompany`'s primary key already supports multiple rows per `SessionRole`
  (line 68). **No governed command today authorizes or audits across more than its one context
  company** — this is genuinely new surface, not an extension.
- `P11aSchemaSql.cs:535–548` (`ImportEvidenceRow`'s four accepted `UNIQUE` constraints) and the
  existing direct-comparison test re-run twice already:
  `P11aDisposableDatabaseTests.cs:531` (`Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up`)
  and `:2322` (`Piece_b_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_b_up`),
  both built on the same private `pg_get_constraintdef`/`pg_indexes` helpers (lines 557–575,
  577–592) — reused unmodified for item 13.
- `P11aSchemaSql.cs:50–55` — `P11aCommandAudit` columns
  `Id, CompanyId, CompanyCode, Actor, Action, TargetId, OccurredAt, CorrelationId, Details(jsonb)`;
  the FK to `CompanyRegistry(CompanyId,CompanyCode)` means **one audit row can carry exactly one
  company** — a multi-company assignment necessarily produces one audit row per affected company,
  directly implied by the existing schema shape, not an open question.
- `P11aSchemaSql.cs:1485–1511` — `RejectTerminalDOCFLGMutationFn` and `WaiveDOCFLG` read in full.
  `RejectTerminalDOCFLGMutationFn`'s **first** `IF` unconditionally rejects any `UPDATE`/`DELETE`
  once `OLD."Status" IN ('Resolved','Superseded','Waived')` — the `sibyla.docflg_waiver_id` GUC
  bypass in the **second** `IF` only exempts the one-time `Open`/`InReview`→`Waived` transition, and
  is never reached for an already-terminal row because the first `IF` fires first. **This is load-bearing for Observation 1 below.**
- `P11bPieceBSchemaSql.cs:6–21, 27–165` — `RegistryFieldProvenance`'s columns, the two
  `DEFERRABLE INITIALLY DEFERRED` `AFTER` trigger families (`RequireProvenanceAgreesWithTarget_*`,
  `RequireExactlyOneProvenance_*`) and the two immediate triggers (`RequireCompanyAgreement`,
  `RejectStaleProvenanceOnDocflgResolution`) — read to confirm Piece C's commands can perform a
  plain two-statement co-update relying on the accepted deferred timing, exactly as B-R1's
  accepted resolution requires.
- Test file conventions confirmed: `P11aDisposableDatabaseTests.cs` (`[Trait("Category","P11aDatabase")]`,
  `Piece_a_*`/`Piece_b_*`-prefixed methods in one shared file — Piece C's disposable tests are
  proposed as `Piece_c_*`-prefixed additions to the same file, not a new one, following the
  established convention) and `P11bPieceAContractTests.cs`/`P11bPieceBContractTests.cs` (offline
  SQL-text/EF-model assertions, no infrastructure) — Piece C's ordinary-suite tests are proposed as
  a new `P11bPieceCContractTests.cs`, mirroring the per-piece contract-file convention.

### The checklist being mapped

Per the go-ahead, **the Piece C checklist is exactly its own 20 numbered items** — preflight and
surface (1–3), O10-D2 command semantics (4–8), authorization/roles/concurrency (9–12), standing
guarantees carried into this piece (13–16), required rejection proofs (17–19), and proof honesty
(20) — and to nothing else. No other item exists; an apparent need for one is a stop-and-report.

### Legend — test surfaces and status labels

| Label | Meaning |
|---|---|
| **Contract (ordinary)** | Proposed new file `tests/Sibyla.Tests/Persistence/P11bPieceCContractTests.cs` — SQL-text and EF-model assertions, no infrastructure; runs in the ordinary suite, following `P11bPieceAContractTests.cs`/`P11bPieceBContractTests.cs`'s shape |
| **Disposable** | Proposed additions to `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs`, the same shared `[Trait("Category","P11aDatabase")]` class Pieces A and B added to; excluded from ordinary `dotnet test`, run only by `scripts\run-p11a-disposable-tests.ps1`. Method names prefixed `Piece_c_*` |
| **Verification command** | Non-test evidence (read-only Git or preflight commands); never described as a test |
| **New** | No Piece C code, migration, role, or test exists anywhere in history — nothing to remediate or regress from |
| **Existing regression** | An exact existing test, helper, or procedure (named and cited) re-run unmodified against Piece C's diff |
| **Strengthened** | An existing helper widened to cover Piece C's new surface (e.g. the catalog-snapshot helper gaining roles/ACLs) |
| **Documentation obligation** | A proof-honesty requirement satisfied by the status record's own wording, not by a test |

**Proposed command shapes — shape committed now, exact signature/DDL fixed at TDD (Observation 3
governs the evidence-append command's name specifically):**
`AssignDOCEFLItemClass(p_efcode varchar, p_item_class varchar)`, and the evidence-append command
provisionally named `AppendDOCFLGResolutionEvidence(p_flag_instance_id varchar, p_evidence text)`,
mirroring `WaiveDOCFLG`'s exact parameter shape. Proposed migration pair
`P11bPieceCSchemaSql.cs` / `20260806200000_P11bPieceCGovernedCommands.cs`, following the exact
naming convention of Pieces A and B — the literal timestamp and filename are fixed when authored.

### 1 · Amendment-4 reformulated preflight checks 1–5, check 6 non-adoption rule

**Verification command; not a test. Existing regression** — the identical six-check, read-only
procedure (`git fetch`, `git cat-file`, `git ls-tree`, `git rev-parse`, `git merge-base`, `git log`
only) Pieces A and B both used, re-run fresh at Piece C implementation start (ordered instruction
3) against pin `b917685…`. Checks 1–5 are a hard stop on failure; check 6 logs the live tip and
every post-pin commit by hash and subject only.

### 2 · Exact base-to-candidate surface and Piece C strict scope

**Verification command plus New Contract test plus New Disposable test.**
- Command: `git diff --name-status <Piece C base>..<Piece C implementation commit>`, restricted to
  `src/` and `tests/`, must list only the new Piece C migration pair, the new/expanded test files
  named in this mapping, and no Piece D, Scope 1, importer, or live-action path.
- New: `P11bPieceCContractTests.Piece_c_sql_is_command_and_role_surface_only_and_exactly_scoped`
  asserts, over the migration's `Up`/`Down` SQL text: `CREATE ROLE` appears only for the role(s)
  this piece itself creates (named at TDD); `GRANT`/`SECURITY DEFINER` appear only on the two new
  commands and their supporting roles; no `ALTER`/`DROP` of any `ENTMST`, `DOCEFL`, `DOCFLG`,
  `ImportEvidenceRow`, or `RegistryFieldProvenance` column or constraint; no redefinition of
  `WaiveDOCFLG`, `RejectTerminalDOCFLGMutationFn`, or any of Piece B's four trigger functions.
- Existing regression: byte-identical blob-ID assertion (`git hash-object` vs. `git ls-tree` at the
  records base) for the accepted P1-1a, Piece A, **and now Piece B** migration files
  (`20260805180000_P11aFdrSchema.cs`, `P11aSchemaSql.cs`,
  `20260806180000_P11bPieceASchemaCompleteness.cs`, `P11bPieceASchemaSql.cs`,
  `20260806190000_P11bPieceBRegistryFieldProvenance.cs`, `P11bPieceBSchemaSql.cs`) — the same
  check pattern Pieces A and B both used, extended to one more migration pair.
- Strengthened: New Disposable test
  `Piece_c_accepted_functions_are_byte_identical_before_and_after_piece_c_up` captures
  `pg_get_functiondef` for `WaiveDOCFLG`, `RejectTerminalDOCFLGMutationFn`, and all four Piece B
  trigger functions (`RequireCompanyAgreementFn`, `RequireProvenanceAgreesWithTargetFn`,
  `CheckRegistryFieldProvenanceCardinalityFn`, `RejectStaleProvenanceOnDocflgResolutionFn`) before
  and after Piece C's `Up`, asserting all six are unchanged — the same technique Piece B's own
  review used to independently confirm `WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn`, widened to
  cover Piece B's own function roster too.

### 3 · Minimal-surface discipline

**Same New Contract test as item 2** — its negative assertions are the minimal-surface proof; a
separate test would duplicate item 2's without adding coverage.

### 4 · `AssignDOCEFLItemClass` enforces the closed D8 vocabulary, closed twice

**New Disposable test** `Piece_c_assign_item_class_rejects_unknown_item_class_literal` — calling
the command with `p_item_class='Invented'` (and, separately, `NULL`) is rejected at the **command
boundary** (a first-statement `IF p_item_class NOT IN ('Annotation','Decision','Status') THEN RAISE
EXCEPTION` fail-closed check, before any row is touched — asserted by confirming no `DOCEFL`/
`DOCFLG`/`RegistryFieldProvenance` row changed after the failed call). The **second, independent**
barrier is the already-accepted `DOCEFL` `CHECK` (`P11aSchemaSql.cs:379`) plus A-R1's validator
identity-class gate (`RegistryValidationService`) — both regression-confirmed unbroken by item 2's
byte-identical checks and item 16 below, not re-derived here.

### 5 · Assignment atomically completes `NULL` snapshots only; non-null snapshot never modified

**New Disposable test** `Piece_c_assign_item_class_completes_null_snapshots_only_and_excludes_non_null_from_count` —
seeds one `DOCFLG` row with `ItemClass IS NULL` (imported) and one already-non-null (a different
governed value than the one being assigned) for the same `EFCode`; after the command commits, the
`NULL` row is completed to the assigned value and the non-null row is byte-for-byte unchanged; the
command's own audited completion count (item 7) is asserted to be **1**, excluding the untouched
row. (Item 11 extends this atomicity requirement across companies: a multi-company assignment must
be all-or-nothing, never partially applied.)

### 6 · Provenance moves with the value through Piece B's accepted invariant

**New Disposable test** `Piece_c_assign_item_class_co_updates_value_and_provenance_in_one_transaction` —
after commit, the `RegistryFieldProvenance` row for the completed `DOCFLG` target has
`Marker='authored'` and `ValueHash` equal to the governed hash of the assigned value (the same hash
convention already used for `SourceRowHash`/`SourceNaturalKeyHash` on `ImportEvidenceRow` — no new
algorithm introduced). **New Contract test**
`Piece_c_assign_item_class_sql_contains_no_delete_reinsert_or_set_constraints` — a direct string
assertion on the function body (the same string-level technique R1g used for Piece B) that the
target/provenance co-update is exactly two `UPDATE` statements, with no `DELETE`/`INSERT` on
`RegistryFieldProvenance` and no `SET CONSTRAINTS` anywhere in `Up`.

### 7 · The audit row states the rule, value, actor, and exact completion count; validator findings reduce by exactly that count

**New Disposable test**
`Piece_c_assign_item_class_audit_states_rule_value_actor_and_exact_per_company_count` — a
multi-company seed (3 `NULL` `DOCFLG` snapshots for the target `EFCode` split 2/1 across two
companies) produces one `P11aCommandAudit` row **per affected company** (the schema's single
`CompanyId`/`CompanyCode` FK columns admit no other shape — resolved by inspection, not an open
question), each `Action='AssignDOCEFLItemClass'`, `Actor` from `P11aCurrentActor`, and `Details`
carrying that company's exact completion count, summing to 3. **New Disposable test**
`Piece_c_assign_item_class_reduces_validator_findings_by_exact_audited_count` — reusing the
existing `PostgresRegistryValidationSnapshotSource` read pattern (the same source O9's NULL
round-trip test reads), measures the `DOCFLG snapshot ItemClass absent` finding count and the
`DOCEFL.ItemClass unassigned` finding count immediately before and after the same assignment in one
disposable run, asserting both drop by exactly the audited counts (3 and 1 respectively for this
seed). (This multi-company seed assumes authority for every affected company — item 11's positive
control; item 11's negative control proves the zero-change case when any company lacks authority.)

### 8 · The evidence-append command appends `ResolutionEvidence` under O9-D5's governed-append semantics

**Corrected: blocked pending Miguel's explicit checklist/authority amendment under Observation 1 —
as written, this item cannot be satisfied by either proposed option, so no test shape is committed
until Miguel decides which amendment to authorize.** If Miguel authorizes **option B** (a scoped,
GUC-gated exception to `RejectTerminalDOCFLGMutationFn`, explicitly waiving item 2 for that one named
function): a New Disposable test seeding a row with `ImportEvidenceRowId IS NOT NULL AND
"ResolutionEvidence" IS NULL`, calling the command, and asserting the value is populated and the
audit records the governed value/hash appended, plus a companion New Disposable test proving a row
whose `"ResolutionEvidence"` is already non-null is rejected or a provable no-op (never overwritten)
— this option's tests directly satisfy item 8's literal text. If Miguel authorizes **option A** (a
separate additive evidence-log table, amending item 8's own text to accept that substitution): the
equivalent proof targets that new table's rows instead — **this is not a test that
`DOCFLG."ResolutionEvidence"` itself was appended to**, since option A never touches that column; it
proves only the new table's own append-only semantics, and gets the full A-R2 three-test shape under
item 14. Either way, the append-only/never-overwrite-non-absent proof itself is required and is fixed
at TDD only once Miguel's amendment is recorded — see the corrected Observation 1 below.

### 9 · Server-side principal only — forged-GUC and non-owner-role denial, for each command

**New Disposable tests, four total.** Two reuse the exact forged-GUC pattern from `Allocate`
(`P11aDisposableDatabaseTests.cs:2488`, `set_config('sibyla.actor', ...)` /
`set_config('sibyla.authorities', ...)`, both ignored because `P11aCurrentActor` never reads them):
`Piece_c_assign_item_class_ignores_forged_actor_and_authority_guc` and
`Piece_c_evidence_append_ignores_forged_actor_and_authority_guc` — each proves the forged GUCs grant
nothing (the call still fails/succeeds solely on the real `session_user`-derived context). Two are
genuinely new to this repository — **no non-owner-role execution test exists for any P1-1a/Piece
A/B command today**, because no non-owner role has ever been created: `Piece_c_assign_item_class_denied_to_non_owner_role`
and `Piece_c_evidence_append_denied_to_non_owner_role` each create a fresh low-privilege `LOGIN`
role in the test (not one of Piece C's own granted roles), connect as it, and assert
`insufficient_privilege` on `EXECUTE`, proving the `REVOKE ALL ... FROM PUBLIC` boundary holds for
these two new functions exactly as it does for every accepted one.

### 10 · R1, fail-closed role provisioning

**New Disposable test** `Piece_c_up_fails_closed_when_expected_role_already_exists` — before
running `context.Database.MigrateAsync()` for Piece C's migration, a raw `CREATE ROLE <expected
name>` pre-seeds a hostile pre-existing role under the exact name Piece C's `Up` will use (fixed at
TDD); asserts `MigrateAsync` throws with a clear error and no partial `Up` state is left applied.
**New Disposable test** `Piece_c_up_creates_roles_fresh_on_normal_path` — the ordinary migration path
(no pre-existing role) succeeds and `pg_roles` confirms the role(s) exist with the attributes fixed
at TDD. This is genuinely new proof for this repository — no prior piece created a role at all, so
there is no existing pattern to reuse, only the requirement text itself
(`docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-2.md:42`, restated verbatim in the go-ahead's item 10).

### 11 · R6, accurate and complete company scope

**Corrected: subset completion is not an option.** Items 5 and 7 already require the assignment to
be atomic (item 5: "atomically completes `NULL` snapshots only") and to audit an exact, well-defined
completed set (item 7: "the audit row states … the exact completion count"). A command that
completes some authorized companies while silently skipping others is neither atomic nor exactly
auditable as one well-defined operation, and is not fail-closed. **The required behaviour is
therefore all-or-nothing:** if the calling principal lacks authority (however R6's authority shape is
finally decided — Observation 2) for **any** company with an affected `NULL` `DOCFLG` snapshot for
the target `EFCode`, the entire call fails and makes **no** change at all — no `DOCEFL` write, no
`DOCFLG` write, no `RegistryFieldProvenance` write, and no `P11aCommandAudit` row, for **any**
company, including the ones the principal was authorized for. The command only ever completes when
authority is proven for every affected company, and then it completes and audits all of them.

**New Disposable test**
`Piece_c_assign_item_class_fails_closed_atomically_when_any_affected_company_is_unauthorized` — seeds
`NULL` `DOCFLG` snapshots for the target `EFCode` across three companies (A, B, C); the calling
principal holds authority (per Observation 2's eventual shape) for A and B only, not C; calls the
command and asserts it fails (raises/returns failure); then independently re-queries the database and
asserts **all three** companies' `DOCFLG.ItemClass` are still `NULL`, the `DOCEFL.ItemClass` for the
rule is still unassigned, **no** `RegistryFieldProvenance` row was inserted or changed for any of the
three targets, and **zero** `P11aCommandAudit` rows exist for this call — proving genuine
all-or-nothing atomicity (no partial completion of A/B merely because C was unauthorized), not just
that the command returned an error.

**New Disposable test**
`Piece_c_assign_item_class_authorized_for_every_affected_company_completes_all_atomically` — the
required positive control: the same three-company seed, but the principal holds authority for **all
three**; the call succeeds, all three `DOCFLG` rows complete, `DOCEFL.ItemClass` is assigned, and
exactly three `P11aCommandAudit` rows exist (one per company, item 7), each with its own exact
per-company count. This replaces the prior "two of three authorized, two complete" framing, which
described silent subset completion and is corrected here per proof-pattern rule 2.

**New Disposable test (inactive-affected-company sub-decision, shape conditional on Observation 2's
resolution)** `Piece_c_assign_item_class_inactive_affected_company_authorization` — one of the
affected companies (say C) has `CompanyRegistry."Active" = false`, and the principal holds an
**ordinary** `RuntimePrincipalCompany` row for C (no elevated authority). This is deliberately
distinct from `P11aCurrentActor`'s own requirement that the caller's single **context** company (the
one passed via `sibyla.company_id`/`sibyla.company_code`) be active (`P11aSchemaSql.cs:93–96`) — that
check never runs against C, which is merely one of potentially several companies **affected by** the
write, not the calling context. Whether ordinary membership in an inactive affected company suffices,
or whether it requires the same elevated authority R6 defines for cross-company writes generally, is
not decided by any accepted text and is Observation 2's second sub-question (2b) below — it is not
silently assumed either way. The test's two branches are described so implementation can proceed
immediately once Miguel decides: **(i)** if ordinary membership suffices, the call with only ordinary
membership for C still completes all companies including C, with C's own audit row recorded; **(ii)**
if elevated authority is required, the call with only ordinary membership for C fails closed
atomically (per the correction above, with zero changes anywhere), and a companion assertion proves
the call succeeds once the principal additionally holds whatever elevated-authority mechanism
Observation 2 establishes.

### 12 · R3, genuine concurrency, both orderings

**Corrected: a blind second-connection `INSERT` does not model the required protocol and does not
prove the required invariant.** The original tests had connection #2 insert a `NULL`-snapshot
`DOCFLG` row with no interaction with the row lock the assignment command takes on the parent
`DOCEFL` row — that proves nothing about ordering, cannot show "no unaudited `NULL` snapshot
survives" as anything but an accident of timing, and does not model the shared-lock protocol item 12
itself names ("the assignment command and the importer serialize on the parent DOCEFL rule — row
lock on `EFCode` or equivalent"). Both tests below are corrected so **both** sides genuinely acquire
the same parent-row lock (`SELECT ... FROM "DOCEFL" WHERE "EFCode"=$1 FOR UPDATE`, or the schema's
equivalent locking primitive — exact choice fixed at TDD) before reading `ItemClass` or writing
anything, so the two connections genuinely serialize through real PostgreSQL lock-wait behaviour,
proven deterministically — not by sleep/timeout-based racing — via a proposed new polling helper
analogous to the existing `WaitForSequenceHighWater` (`P11aDisposableDatabaseTests.cs:2508–2536`),
but polling `pg_stat_activity`/`pg_locks` for the second backend's real `wait_event_type='Lock'`
state rather than a sequence value — proposed name `WaitForBackendBlockedOnDocflgParentLock`. The
exact lock protocol these tests assume is not yet authorized — see the corrected Observation 6 below.

- **New Disposable test**
  `Piece_c_assignment_locks_parent_first_then_import_reads_the_assigned_value` — connection #1 opens
  a transaction, takes the parent-row lock, runs `AssignDOCEFLItemClass` to completion (completing
  every `NULL` snapshot then visible), and **holds the transaction open** before committing.
  Connection #2, in a real second transaction, attempts the same parent-row lock as the first step of
  the simulated import protocol; the test asserts via `WaitForBackendBlockedOnDocflgParentLock` that
  connection #2 is genuinely blocked (observed waiting on the lock connection #1 holds, not merely
  "hasn't run yet"). Connection #1 then commits, releasing the lock; the test asserts connection #2's
  blocked call unblocks and completes. Connection #2, now holding the lock, re-reads the
  (now-committed) assigned `ItemClass` under the lock and inserts its new `DOCFLG` snapshot row
  **already carrying that value**, not `NULL` — modelling the future importer reading current state
  under the shared lock rather than blindly inserting `NULL`. Final assertions: **zero** `NULL`
  `DOCFLG` snapshots remain for the `EFCode` (the new row was never `NULL` to begin with), and the
  assignment's own audited completion count (item 7) covers exactly the rows that existed and were
  `NULL` at the moment connection #1's lock was acquired — correctly excluding the row connection #2
  inserted afterward, since it did not exist yet.
- **New Disposable test**
  `Piece_c_import_locks_parent_first_then_assignment_completes_the_new_row` — the reverse ordering:
  connection #1 takes the parent-row lock first, inserts a new `DOCFLG` row with `ItemClass IS NULL`
  (modelling an import landing before any assignment exists), and holds the transaction open before
  committing. Connection #2 attempts `AssignDOCEFLItemClass`, which must take the same parent-row
  lock as its own first step; the test asserts via the same polling helper that connection #2 is
  genuinely blocked. Connection #1 commits, releasing the lock; connection #2's call unblocks, and —
  because its own `NULL`-snapshot scan happens **after** acquiring the lock, not before — it now sees
  and completes the row connection #1 just committed. Final assertions: **zero** `NULL` `DOCFLG`
  snapshots remain for the `EFCode`, and the assignment's audited completion count (item 7)
  **includes** the row connection #1 inserted, proving the command does not miss a row that landed
  immediately before it acquired the lock.

**Design note, unchanged by this correction:** "the importer" in both tests is a real second
connection issuing real SQL shaped like the future import protocol, not the real Scope 1 importer,
which remains unbuilt and explicitly out of this piece's scope. This mirrors how `Allocate`'s own
concurrency test already simulates a second caller without a full application layer, and is required
precisely because building or running the real importer is forbidden to this piece.

### 13 · R7 direct assertion — accepted `ImportEvidenceRow` uniqueness untouched

**Existing regression** — `P11aDisposableDatabaseTests.cs:531`/`:2322`'s exact private
`pg_get_constraintdef`/`pg_indexes` comparison helpers (lines 557–575, 577–592), re-run a third time
as New Disposable test
`Piece_c_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_c_up`. Per this
item's own text, this is re-verified again end-to-end in Piece D; that is Piece D's own gate, not
this one's.

### 14 · Generated columns exactly as generated, store type included, for every column Piece C adds

**Documentation obligation unless Piece C's `Up` adds a table/column.** The two governed commands
are function/role/grant surface with no new table currently designed, **unless Observation 1
resolves to a separate additive evidence-log table**, in which case every column that table adds
gets the full A-R2 three-test shape already established (contract `GetColumnType()`,
snapshot-versus-runtime-model, disposable EF-versus-`information_schema.columns`). If `Up` adds no
column, the record states that explicitly per proof-pattern rule 1, mirroring Piece B's own item-10
discipline.

### 15 · R2, scoped `Down`; Up/Down/Up catalog stability

**Strengthened** — New Disposable test `Piece_c_down_is_exact_and_up_down_up_is_catalog_stable`
widens the existing catalog-snapshot helper (the same shape Pieces A and B's own item-12/-20 tests
used) to include roles and ACLs in addition to columns/constraints/indexes/triggers/functions;
asserts `Down` performs no `DROP OWNED`, drops exactly and only the roles/functions/grants this
piece's `Up` created, changes no ownership of `WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn`/any
Piece B function (cross-referenced with item 2's byte-identical test), and restores the accepted
P1-1a-plus-Piece-A-plus-Piece-B catalog exactly; `Up` again reproduces the first `Up`.

### 16 · Closed vocabularies close twice wherever they exist on this surface

**Documentation obligation.** The D8 vocabulary already closes twice per item 4. Piece C introduces
no new closed vocabulary of its own (no new marker/status literal set) — stated explicitly here per
proof-pattern rule 5 and mirroring Piece B's own item-11 discipline for surfaces that don't apply,
rather than leaving the point implicit.

### 17 · An assignment naming an unknown or non-D8 literal is rejected

**Same test as item 4.**

### 18 · An assignment attempting to modify a non-null snapshot is rejected or a provable no-op

**Same test as item 5** — the non-null row's exclusion from the audited count is the "provable
no-op" half of this item.

### 19 · An unauthorized-company write and a forged-GUC invocation are each rejected fail-closed

**Same tests as items 9 and 11.**

### 20 · Claims equal assertions

**Documentation obligation, not a test.** The Piece C implementation's own status record will state
exactly the surface its tests assert — the exact role/function/grant roster and command return
shape authored during TDD, no projected suite counts, no overstated catalog surface — mirroring the
discipline Pieces A and B's own mappings used as the model.

---

## Observations — reported, not resolved silently

### Observation 1 — corrected: as written, checklist item 8 is impossible; both options require an explicit Miguel amendment, not just a recommendation between two compliant designs

**Correction to the original text.** The original Observation 1 recommended option A without stating
plainly that option A does **not** literally satisfy item 8, and did not enumerate the exact
amendment each option would need. Restated precisely:

`RejectTerminalDOCFLGMutationFn`'s body (`P11aSchemaSql.cs:1485–1494`, read in full) rejects **any**
`UPDATE`/`DELETE` unconditionally once `OLD."Status" IN ('Resolved','Superseded','Waived')` — the
`sibyla.docflg_waiver_id` bypass only ever exempts the one-time `Open`/`InReview`→`Waived` transition
and is never reached for a row that is already terminal. Item 8 requires the evidence-append command
to append `ResolutionEvidence` **to imported terminal `DOCFLG` rows** — rows that are, by
`CK_DOCFLG_TerminalResolutionEvidence`'s own definition (`P11bPieceASchemaSql.cs:34–41`), already
terminal. **As written, checklist item 8 cannot be satisfied at all without an explicit amendment**,
because:

- **Option A (a separate, additive, append-only evidence-log table) does not literally satisfy item
  8.** Item 8's text is "appends `ResolutionEvidence`" — the `DOCFLG."ResolutionEvidence"` column
  itself. A separate table records evidence **somewhere else**; it never touches
  `DOCFLG."ResolutionEvidence"`, so the historical gap that column represents (the O9-P/O9-D5
  "terminal DOCFLG rows without `ResolutionEvidence`" finding, baseline 221) is **not** closed by
  this design — it would remain open, or a new, different finding would need to be defined against
  the new table instead. This is a change to **what "the evidence" means**, i.e. to O9-D5's own
  governed contract, not merely an implementation choice within it. **Option A therefore needs an
  explicit Miguel amendment to checklist item 8's text (and arguably to O9-D5 itself)** stating that
  appending to a new, separate table satisfies "appends `ResolutionEvidence`," and a decision on
  whether the 221 baseline is considered closed, left open, or replaced by a new finding.
- **Option B (a scoped, GUC-gated exception added to `RejectTerminalDOCFLGMutationFn`)** directly
  satisfies item 8's literal text, but **violates checklist item 2 as written** (which names
  `RejectTerminalDOCFLGMutationFn` explicitly as required byte-identical before/after this piece's
  `Up`) **and minimal-surface discipline (item 3)**, since no checklist item currently names this
  exact change as authorized. **Option B therefore needs an explicit Miguel waiver of item 2 for this
  one named function**, plus an explicit item-3-compliant authorization naming exactly this change
  (the narrow GUC-gated exception described below) so it is not an unnamed touch to an accepted
  object.

Neither option is currently authorized by any accepted text; **implementation of item 8 cannot
proceed on either path without Miguel first recording one of these two amendments** (or a third
option Miguel may prefer instead). This is a stop-and-report under minimal-surface discipline and a
direct collision between checklist items 2 and 8, not a mere design choice between two
already-compliant designs.

**Recommendation, clearly distinguished from authorization:** of the two, this record recommends
Miguel authorize **option B** — the scoped `sibyla.docflg_evidence_append_id`-gated exception
described below — because it is the only one of the two that actually closes the substantive
historical gap (the 221-row finding) the command exists to address, and because its shape is narrow,
single-purpose, and directly mirrors the existing, already-accepted
`WaiveDOCFLG`/`sibyla.docflg_waiver_id` pattern, making it auditable by the same convention already
in the codebase. Option A is offered as the more conservative alternative if Miguel judges that
touching `RejectTerminalDOCFLGMutationFn` at all — even narrowly — is unacceptable regardless of the
cost to item 8's literal intent. **This is a recommendation only; no option is authorized until
Miguel records an explicit decision, and no code implements either yet.**

**Option B's exact proposed shape**, for concreteness: a second GUC
(`sibyla.docflg_evidence_append_id`) checked in a new `IF`, reached only when the row is already
terminal, permitting exactly one additional case: `OLD."Status" IN
('Resolved','Superseded','Waived') AND OLD."ImportEvidenceRowId" IS NOT NULL AND
OLD."ResolutionEvidence" IS NULL AND
coalesce(current_setting('sibyla.docflg_evidence_append_id',true),'')=NEW."FlagInstanceID"` — every
other column on the row must be asserted unchanged by the same test that proves this path.

### Observation 2 — R6's authority shape, corrected and split into two explicit sub-decisions

**Correction.** The original text conflated "how authority for a company is established" with
"whether the command may partially complete an unauthorized subset" — the latter is no longer an
open question (see item 11's correction above: partial completion is never permitted; the command is
all-or-nothing). What remains genuinely open is authority **shape**, now split into two
sub-questions, 2a (the originally requested observation (a)) and 2b (newly surfaced by this
correction).

**2a — the exact elevated multi-company authority shape.** Proposed: a per-company set, not a new
authority literal. `RuntimePrincipalCompany` already supports multiple `(SessionRole, CompanyId,
CompanyCode)` rows per role (its primary key, `P11aSchemaSql.cs:68`) — the schema shape already
anticipates a role authorized for more than one company; no new table or column is needed.
`AssignDOCEFLItemClass` would enumerate every company with an affected `NULL` `DOCFLG` snapshot for
the target `EFCode`, and require a matching `RuntimePrincipalCompany` row for the calling role for
**every** one of them (generalizing `P11aCurrentActor`'s existing single-company check,
`P11aSchemaSql.cs:93–96`, to a loop); per item 11's correction, if even one is missing, the **entire
call** fails closed with zero changes anywhere. **Justification:** this is the conservative,
fail-closed reading consistent with every other authorization boundary in the accepted catalog (R1,
B-R1, the company-agreement trigger) — it never grants a role reach into a company it was never
explicitly enrolled in, and it reuses an existing table shape rather than inventing a new "trusted
for everything" authority literal, which would be a strictly broader, harder-to-audit grant.
**Fallback alternative:** a new elevated authority literal (e.g.
`'AssignDOCEFLItemClass:AllCompanies'`, recorded the same way any other `RuntimePrincipalAuthority`
row is) for operator/administrative roles that must write broadly without per-company enrollment —
offered only if Miguel judges per-company enrollment operationally too heavy for this command's real
usage pattern. Submitted for Miguel's explicit decision, exactly as the go-ahead's own instruction 2
names it; no code implements either option yet.

**2b — does ordinary `RuntimePrincipalCompany` membership authorize a write to an affected company
that is itself inactive, or does it require the same elevated authority as 2a? (newly surfaced by
this correction — not previously asked, and not decided by any accepted text).**
`P11aCurrentActor`'s own active-company check (`P11aSchemaSql.cs:93–96`) only ever validates the
caller's single **context** company — it says nothing about companies merely **affected by** a
multi-company write, which is exactly what item 11's "an inactive affected company still receives
its audit row" requirement concerns. **This record does not silently treat inactive membership as
sufficient.** **Proposed (weakly held):** ordinary membership remains valid authorization regardless
of the affected company's current active state — nothing in the accepted schema ties a
`RuntimePrincipalCompany` enrollment to `CompanyRegistry."Active"`, a principal was legitimately
enrolled at some point, and completing historical `NULL` snapshots for a since-retired company is
exactly the kind of housekeeping this command exists to do; treating inactive companies as requiring
**more** authority than active ones would be a new, unstated asymmetry. **Alternative:** require the
same elevated authority as 2a for any inactive affected company specifically, on the theory that
writing into a retired company's data is inherently more sensitive than ordinary enrollment was
meant to cover. Submitted as an explicit, separate decision for Miguel alongside 2a; item 11's third
test is written with both branches ready so implementation can proceed immediately once Miguel
decides.

### Observation 3 — proposed resolution for expected observation (b): the evidence-append command's precise name and argument shape

**Proposed:** `AppendDOCFLGResolutionEvidence(p_flag_instance_id varchar, p_evidence text)`,
mirroring `WaiveDOCFLG(p_flag_instance_id varchar, p_evidence text)`'s exact parameter shape and
naming convention (verb + target + noun), since both commands write evidence onto one identified
`DOCFLG` row for one caller-supplied text. **This proposal is downstream of Observation 1**: if
Observation 1 resolves to option A (a separate evidence-log table), the same name is proposed for a
command that inserts into that new table instead of updating `DOCFLG` directly, with an unchanged
argument shape; if option B, the same name and arguments apply to the direct-update path. Submitted
for Miguel's explicit decision alongside Observation 1, per the go-ahead's own instruction 2.

### Observation 4 — role/ACL roster shape (R1) has no precedent in this repository; shape committed now, exact roster fixed at TDD

No prior piece created a PostgreSQL role. The exact number of roles (one shared role for both
commands, or one per command), their names, and their exact `GRANT` surface are fixed when Piece
C's `Up` is authored during TDD and reported item by item in the implementation's own evidence map
— the same discipline Piece A's item 20 and Piece B's items 10/12 already used for undetermined
DDL. **Proposed resolution:** approve the mapping on this basis; no additional authorization is
requested beyond confirming this reading, consistent with the precedent both prior pieces' test-plan
gates already established.

### Observation 5 — `P11aCommandAudit`'s single-company-per-row shape (resolved by inspection, not an open question)

`P11aCommandAudit`'s `CompanyId`/`CompanyCode` columns are singular `NOT NULL` with a composite FK
to `CompanyRegistry` — the schema itself, unmodified, already dictates that a multi-company
assignment produces **one audit row per affected company**. This is stated here for completeness
under item 7/11's mapping; it is not submitted as a decision for Miguel because the existing,
unmodifiable schema shape leaves no alternative to evaluate.

### Observation 6 — corrected: the future importer's parent-lock protocol is not decided/authorized, and a blind insert is not sufficient proof

**Correction.** The original text called this "resolved by necessity, not an open question" — that
was wrong, and is what item 12's original blind-`INSERT` tests rested on. Item 12 requires the
assignment command and **the importer** to "serialize on the parent DOCEFL rule (row lock on
`EFCode` or equivalent)," but the importer itself is out of this piece's scope to build or run ("No
importer, no Scope 1" — the go-ahead's own Scope section and "What this go-ahead does not
authorize"). That means the **locking contract** a future importer will need to honour — not just
its existence, but which exact statement/lock mode it must issue, and at which point in its own
transaction — is not decided or authorized by any accepted text either, even though Piece C's own
concurrency tests (item 12, corrected above) must simulate that exact contract to be meaningful. A
blind, uncoordinated `INSERT` (the original test design) is not sufficient proof of anything, which
is exactly why item 12 was corrected above.

**Proposed minimal shared parent-lock protocol**, submitted for Miguel's confirmation now, ahead of
the importer's own eventual design: any writer of a `DOCFLG` row referencing a given
`DOCEFL."EFCode"` — `AssignDOCEFLItemClass` and, later, the importer — must first acquire `SELECT 1
FROM "DOCEFL" WHERE "EFCode"=$1 FOR UPDATE` (or the schema's equivalent row-lock primitive) in its
own transaction, before reading `DOCEFL."ItemClass"` or inserting/updating any `DOCFLG` row for that
`EFCode`, and must hold that lock until its transaction commits. This is the minimal protocol that
makes item 12's own two orderings well-defined and provable, and item 12's corrected tests are
written against exactly this protocol. **This is reported as an observation, not assumed settled**:
the importer does not exist, so this protocol cannot be verified against real importer code in this
piece, only asserted as the contract Piece C's own side must honour and future import work must be
held to. Submitted for Miguel's explicit confirmation alongside Observations 1 and 2.

### Test inventory this mapping commits to

| Surface | New | Existing regression | Strengthened | Documentation-only |
|---|---:|---:|---:|---:|
| Contract (ordinary), proposed `P11bPieceCContractTests.cs` | 2 methods (items 2/3, 6) | 0 | 0 | — |
| Disposable, proposed additions to `P11aDisposableDatabaseTests.cs` | 16–18 methods (items 4, 5, 6, 7×2, 8×0–2 pending Miguel's amendment under Observation 1, 9×4, 10×2, **11×3 corrected**, 12×2) | 1 (item 13) | 2 (items 2, 15) | — |
| Verification command | 0 | 1 (item 1) | 0 | plus item 2's diff-path command |
| Documentation obligation | — | — | — | items 14 (conditional), 16, 20 |

Item 11's count is corrected from the original mapping's 2 methods to 3 (the all-or-nothing negative
test, the full-authorization positive control, and the inactive-affected-company sub-decision test),
per the correction above. Item 8's exact test count is still not committed — now pending Miguel's
explicit checklist/authority amendment under Observation 1, not merely a decision between two
already-compliant designs — per proof-pattern rule 1, no projected count is claimed for it here.

**No suite-count projection is recorded**, per proof-pattern rule 1 and the discipline Pieces A and
B's mappings both adopted: the exact count is fixed only once Piece C's `Up` is authored and
Observations 1–3 are decided.

### What this test-plan step did not do

No implementation, migration, model, role, grant, constraint, trigger, validator, fixture, test,
importer, or Scope 1 work: not one line of code was written. `WaiveDOCFLG`, `RejectTerminalDOCFLGMutationFn`,
the four Piece B trigger functions, the validator source, and the migration history were inspected
**read-only** exactly as authorized. No amendment-4 prototype preflight was run and no post-pin
prototype content was read. No prototype read, write, fetch, or checkout of content; no database,
container, service, deployment, or live-data action, disposable or otherwise; no history rewrite.
Piece C implementation, Piece D, and Scope 1 remain gated and unstarted.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, role, grant, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Candidate/history access mode | read-only `Read`/`Grep`/`git log` only — no candidate exists to diff |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it.

### Gate statement — Miguel's decision is required before implementation

This corrected mapping is submitted under the go-ahead's test-plan gate. **Piece C implementation
remains unauthorized until Miguel records an explicit approval of this mapping**; the instruction to
record it is not approval of it. Requested decision: **approve**, **reject**, or **return with
corrections** — in particular on:

- **Observation 1** — which of the two amendments to authorize before item 8 can be implemented at
  all: option B (recommended — a scoped `sibyla.docflg_evidence_append_id`-gated exception to
  `RejectTerminalDOCFLGMutationFn`, waiving checklist item 2 for that one function) versus option A
  (a separate append-only evidence-log table, which requires amending item 8's own text and deciding
  the fate of the 221-row baseline finding, since it does not touch `DOCFLG."ResolutionEvidence"`
  itself) — or a third option Miguel may prefer.
- **Observation 2a** — R6's exact elevated multi-company authority shape: the recommended per-company
  `RuntimePrincipalCompany` enumeration (all-or-nothing per item 11's correction) versus a new
  elevated authority literal.
- **Observation 2b** — whether ordinary `RuntimePrincipalCompany` membership authorizes a write to an
  inactive affected company, or whether that requires the same elevated authority as 2a.
- **Observation 3** — the evidence-append command's proposed name and argument shape, downstream of
  Observation 1.
- **Observation 4** — committing the role/ACL roster to shape now, exact names fixed during TDD.
- **Observation 6** — confirmation of the proposed minimal shared parent-lock protocol (`SELECT 1
  FROM "DOCEFL" WHERE "EFCode"=$1 FOR UPDATE` before any read/write of that `EFCode`'s `DOCFLG` rows)
  that both `AssignDOCEFLItemClass` and any future importer must honour, since item 12's corrected
  concurrency tests are written against exactly this contract.

## 2026-08-06 Piece C go-ahead — acceptance recorded

This step performs **ordered instruction 1 of `docs/AGENT-PROMPT-v5-P1-1b-piece-c-goahead.md`**:
the governed records commit acknowledging Piece C's go-ahead, pushed before any code. The go-ahead
prompt itself is already tracked and pushed at `6880bbf8dc2f44a3f97f217e653c6400fb9c98b5`; it is
not duplicated or rewritten merely to force an unchanged path into this commit.

Live Git state was verified fresh rather than trusted: local `HEAD` = `origin/feature/p1-1b` =
`6880bbf8dc2f44a3f97f217e653c6400fb9c98b5`, clean tree, `0 0` divergence against origin. That
commit added the go-ahead prompt file (181 insertions) and an unrelated `docs/project-evolution.html`
rendering update (11 insertions, 10 deletions); it touched neither `docs/p1-1b-status.md` nor
`docs/PROJECT-STATE.md`, so both remained accurate as of Piece B's Accept and are updated here for
the first time to reflect the go-ahead.

**Authority and content, restated from the go-ahead.** Piece B has a recorded Accept (its
remediation `7059809…`, reviewed and accepted at `256da9c…`,
`docs/p1-1b-o10-independent-review.md`, "Piece B B-R1 remediation review — Accept": 0 Critical / 0
High / 0 Medium / 0 Low). Per amendment 3, Piece B's Accept authorizes Piece C to seek its own
go-ahead; `docs/AGENT-PROMPT-v5-P1-1b-piece-c-goahead.md` is that go-ahead — its content was
pre-authorized by amendment 3, this document starts it. It reopens no decision. The five baselines
remain 119 / 119 / 52 / 221 / **2,787**; the two `Routine` rows still import verbatim; the pin
remains `b91768513fc638381fbde91f0b576b08220a98f6`. Monolithic rejects `b324a3e…`, `57f0f023…`,
`7ea6c0f…` and piece candidates `6f86023d…` (Piece A Reject #1) and `b8fa033…` (Piece B Reject #1)
remain neutralized evidence only, never resurrected — the accepted implementations are Piece A
`f6f297b…` and Piece B `7059809…` alone.

**O5-prep note, restated.** The parallel O5-prep green-light remains deferred by Miguel's decision;
the implementer works solely on Piece C.

**Scope, restated.** `AssignDOCEFLItemClass` (O10-D2's atomic snapshot-completion command) and the
evidence-append command, plus whatever roles and `SECURITY DEFINER` surface they need — and nothing
else. Additive base: the accepted P1-1a catalog plus accepted Piece A (`f6f297b…`) plus accepted
Piece B (`7059809…`). No importer, no Scope 1, no prototype access beyond the amendment-4 preflight.
This piece must not touch `WaiveDOCFLG` at all, nor any Piece A/B object: the commands *use* Piece
B's provenance invariant, they do not modify it. Per B-R1's accepted resolution, the value/provenance
co-update is a plain two-statement co-update in one transaction relying on the accepted
`DEFERRABLE INITIALLY DEFERRED` triggers at `COMMIT` — no delete-update-insert sequence, no
`SET CONSTRAINTS ... IMMEDIATE`.

**The Piece C consolidated checklist** is exactly the go-ahead's 20 numbered items — preflight and
surface (1–3), O10-D2 command semantics (4–8), authorization/roles/concurrency — R1 · R6 · R3 ·
round-1 principal boundary (9–12), standing guarantees carried into this piece (13–16), required
rejection proofs (17–19), and proof honesty (20) — and to nothing else. The implementer's evidence
map and the reviewer's disposition key to this list only.

**Ordered execution ahead, restated:** (1) this records commit; (2) the test-plan gate — record the
checklist→test mapping and stop for Miguel's explicit approval, reporting ambiguities as
observations with a proposed resolution rather than resolving them silently (at minimum: R6's exact
elevated multi-company authority shape, and the evidence-append command's precise name and argument
shape); (3) implement, TDD first, from the pushed tip after approval; (4) full independent
adversarial review, the first attempt of this piece.

**What this step did and did not do.** Documentation only. No implementation, migration, model,
constraint, trigger, role, grant, test, fixture, importer, prototype, database, container, service,
deployment, or live-data work occurred. Piece C implementation remains unauthorized pending the
test-plan gate and Miguel's explicit approval of it — the go-ahead itself is not approval of
implementation. Piece D and Scope 1 remain gated and unstarted. O5 remains the project's only other
open item.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, constraint, trigger, role, grant, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `6880bbf8dc2f44a3f97f217e653c6400fb9c98b5`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. The last independently reproduced
figures remain those of the Piece B B-R1 remediation Accept record below.

## 2026-08-06 Piece B B-R1 remediation — mandatory fresh independent adversarial review recorded: Accept

This step performs **ordered instruction 4 of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-remediation-approval.md`**
— **the second and final Piece B attempt before escalation to Miguel** — run in a fresh, independent
Claude CLI session per that instruction's requirement, with no reliance on the implementer's own
summary and no use of Codex. The full verdict, findings, item-by-item confirmation, and independent
verification evidence are recorded in `docs/p1-1b-o10-independent-review.md` under **"Piece B B-R1
remediation review — Accept"**. Summary:

- **Verdict: Accept — 0 Critical, 0 High, 0 Medium, 0 Low.** Live Git state was verified fresh
  (local `HEAD` = `origin/feature/p1-1b` = `7059809424e066aee7ef07f5e068dd5a550402aa`, clean tree,
  `0 0` divergence against the records/approval base `1627dd6ea84b4a7310c8d5ebdadd714aada94cec`)
  rather than trusted from this file.
- The amendment-4 reformulated preflight was independently re-run fresh, read-only, against the
  prototype clone: checks 1–5 passed (pin reachable and ancestral, local clone anchored, a fresh
  cell-by-cell 49/49 roster-blob measurement with 0 mismatches, 48/48 direct `Editor/Data` surface
  with 0 delta); check 6 reproduced the same live-tip divergence (`3dd4150…`, commits
  `1e841a4`/`3dd4150`) already on record, with no post-pin content read or adopted.
- The exact base-to-candidate diff was independently confirmed to touch exactly the same 8 paths
  the evidence map claims (2 records files, 3 new and 3 modified code/test paths); no Piece C/D,
  role, ACL, `SECURITY DEFINER`, governed-command, or importer path appears anywhere in the diff.
  Both accepted P1-1a and Piece A migration files were independently confirmed byte-identical to
  the pre-implementation base by `git hash-object`/`git ls-tree` blob-ID comparison.
- **B-R1 was independently confirmed genuinely fixed**, not merely test-shaped: the redesigned
  `RequireProvenanceAgreesWithTargetFn` and its three `DEFERRABLE INITIALLY DEFERRED` constraint
  triggers were read in full and their deferred/immediate timing was independently measured
  live against a fresh disposable PostgreSQL 17 container's `pg_trigger` catalog (not assumed from
  the SQL text); the candidate's own R1a–R1g proofs and the reshaped item-16 test were read
  line-by-line; and six original adversarial probe transactions — not derived from the candidate's
  test suite — independently reproduced both statement orderings succeeding, a duplicate-firing
  toggle succeeding with consistent final state, the previously-exploited no-provenance window now
  failing closed, the full delete-update-insert sequence remaining incidentally valid but unneeded,
  company agreement firing genuinely immediately (demonstrated without a `DO`/`EXCEPTION` block),
  and a combined move-plus-value-change scenario failing closed. All six probes passed on first run
  and were fully removed before the verdict was recorded. Every Reject #1 Pass row was independently
  confirmed to still hold on the new diff.
- Build, focused, ordinary, and disposable PostgreSQL suites were independently rerun fresh and
  reproduced the implementer's own measured counts exactly (0 warnings/0 errors; 3/3; 640/640;
  34/34); `git diff --check` clean; both accepted migration-family blob IDs unchanged; live catalog
  measurement of `RegistryFieldProvenance` (9 columns / 11 constraints / 2 indexes) and the touched
  tables (8 triggers / 4 functions total) matched the evidence map exactly; `WaiveDOCFLG`'s and
  `RejectTerminalDOCFLGMutationFn`'s source was independently confirmed to contain no reference to
  `RegistryFieldProvenance`; 0 residual `sibyla-p11*`/`sibyla-review-probe*`/`sibyla-review-catalog*`
  containers after every container and after the final run; 0 matches on a diff-restricted
  secret/role/`SECURITY DEFINER`/`DROP OWNED` scan.

**Piece B now has an accepted implementation.** Per amendment 3, Piece B's Accept authorizes Piece C
to seek its own go-ahead; Piece C, Piece D, and Scope 1 remain gated and unstarted pending each
predecessor's own recorded Accept. No neutralization was authorized or performed. O8/O9/O10
decisions, the five baselines 119 / 119 / 52 / 221 / 2,787, and the two verbatim `Routine` rows are
unchanged. O5 remains the project's only other open item.

## 2026-08-06 Piece B B-R1 remediation implementation — evidence map

This step performs **ordered instruction 3** of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-remediation-approval.md`:
implement the Piece B remediation as a **remediation of candidate `b8fa0333035c59e8b154554aa984d038853ab069`**
under the amendment-4 reformulated preflight, TDD first, from the pushed approval tip
`1627dd6ea84b4a7310c8d5ebdadd714aada94cec` — applying exactly the approved redesign (the item 5/7
split, three `DEFERRABLE INITIALLY DEFERRED` `AFTER` constraint triggers, R1a–R1g, the item-20
design-note correction, and the item 2/12 roster widenings) and **no other content change**. It does
**not** perform ordered instruction 4 (the fresh independent adversarial review of this remediation),
which runs in a fresh, independent session after this candidate publishes.

### Reformulated preflight — re-run fresh at remediation start

Read-only against prototype clone `D:\fileStorage\repos\invoice-skill-build`, using only
`git status`, `git fetch`, `git cat-file`, `git ls-tree`, `git rev-parse`, and `git merge-base`:

1. Pin `b91768513fc638381fbde91f0b576b08220a98f6` resolves locally (`git cat-file -e`). **Pass.**
2. `git merge-base --is-ancestor` confirms the pin is an ancestor of live `origin/main`
   (`3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`). **Pass.**
3. Local clone `HEAD` equals the pin exactly (branch `c8-entbnk-five-pair-merge`, clean working
   tree — `git status --short --branch` reported no changed or untracked paths; `git diff --quiet`
   and `git diff --cached --quiet` both succeeded). **Pass.**
4. All **49/49** roster blobs (the complete 49-entry roster with the O8 `entbnk.json`
   substitution) were re-measured fresh, cell by cell, via `git rev-parse
   b91768513fc638381fbde91f0b576b08220a98f6:<path>` for every recorded path against its recorded
   blob SHA. **49/49 resolved, 0 mismatches, 0 resolve failures.** **Pass.**
5. `git ls-tree b917685 -- Editor/Data/` independently counted: **49** entries total, exactly **1**
   is the `Backups` subdirectory tree entry (excluded), leaving **48/48** blob files, 0 delta —
   every filename and blob matches the recorded roster exactly, including the substituted
   `entbnk.json` blob `70d418f6023bff68f0d642b4aff26c1ead1298be`. **Pass.**
6. (Non-stop finding, reproduced identically.) Live tip remains
   `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`; `git log --oneline
   b91768513fc638381fbde91f0b576b08220a98f6..origin/main` lists exactly the same two post-pin
   commits already on record, `1e841a4` (*Complete Stage 10 Round 8 reconciliation and mapping
   updates*) and `3dd4150` (*Apply Stage 10 Round 8 revenue review updates*) — no new divergence.
   No post-pin content was read or adopted — only commit hashes, subjects, and tree listings were
   inspected.

### Root cause and remediation design — restated exactly as approved, no content change

PostgreSQL defers trigger evaluation to `COMMIT` only for `AFTER` constraint triggers; the rejected
candidate mixed an immediate `AFTER` trigger on `DOCEFL`/`DOCFLG` with an immediate `BEFORE`
trigger on `RegistryFieldProvenance`, so each validated the other side's stale state regardless of
statement order. The remediation splits `RequireProvenanceAgreesWithTargetFn`'s two
responsibilities exactly along the checklist's item 5/item 7 boundary:

- **Item 5 (company agreement), unchanged in substance.** A new, dedicated `RequireCompanyAgreementFn`
  keeps an immediate `BEFORE INSERT OR UPDATE` attachment on `RegistryFieldProvenance` alone,
  validating a `DOCFLG`-targeted provenance row's `Company` against the target's live `Company`
  (`DOCEFL`-targeted rows are company-agnostic by `CK_RegistryFieldProvenance_CompanyScope`).
  Company never changes as part of a `NULL`→value `ItemClass` transition, so immediacy remains
  safe.
- **Item 7 (absent/value agreement), re-implemented as three `DEFERRABLE INITIALLY DEFERRED`
  `AFTER` constraint triggers**, all sharing one redesigned `RequireProvenanceAgreesWithTargetFn`:
  `RegistryFieldProvenance` (`AFTER INSERT OR UPDATE` — moved from `BEFORE` to make deferral
  possible), `DOCEFL` (`AFTER UPDATE OF "ItemClass"`, now deferrable), `DOCFLG`
  (`AFTER UPDATE OF "ItemClass"`, now deferrable). Each firing re-queries the **live** current
  state of both the governed value and the current provenance row by fresh `SELECT`, never trusting
  the firing statement's own captured `OLD`/`NEW` for the counterpart side — the same live-lookup
  discipline the accepted `CheckRegistryFieldProvenanceCardinalityFn` (item 6) already uses. Because
  every one of the three fires only at `COMMIT`, after every statement in the transaction has
  already applied, both natural orderings of a two-statement co-update see the identical final
  state and are validated identically. If, at `COMMIT`, no provenance row exists for a target at
  all, the trigger has nothing to compare and performs no check for that reason — this is **not**
  the rejected candidate's gap, because item 6's own independent deferred cardinality trigger
  separately and unconditionally guarantees exactly one provenance row exists per governed member
  at commit; existence is item 6's invariant, agreement is item 7's, and both are enforced
  independently and unconditionally at commit.

This changes only Piece B's own never-accepted objects; no accepted P1-1a or Piece A object, role,
ACL, or `WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn` surface is touched.

### Finalized DDL/catalog roster — items 2 and 12, measured against the migrated disposable catalog

Measured directly against a fresh disposable PostgreSQL 17 container migrated through this exact
candidate's `Up` (`information_schema.columns`, `pg_constraint`, `pg_indexes`, `pg_trigger`,
`pg_proc`), not projected:

**9 columns on `RegistryFieldProvenance`** — unchanged from the rejected candidate, the remediation
adds/removes none: `Id` (`uuid`, PK), `TargetTable` (`character varying(16)`, NOT NULL),
`TargetCode` (`character varying(32)`, NOT NULL), `Company` (`character varying(128)`, nullable),
`DOCEFLCode` (`character varying(32)`, `GENERATED ALWAYS ... STORED`, nullable),
`DOCFLGFlagInstanceID` (`character varying(32)`, `GENERATED ALWAYS ... STORED`, nullable), `Marker`
(`character varying(16)`, NOT NULL), `ValueHash` (`character varying(64)`, nullable), `RecordedAt`
(`timestamp with time zone`, NOT NULL).

**9 "real" constraint-class objects on `RegistryFieldProvenance`** (measured via `pg_constraint`,
excluding the 2 self-attached deferred-constraint-trigger rows counted separately below):
`RegistryFieldProvenance_pkey` (PK on `Id`), `UQ_RegistryFieldProvenance_Target` (`UNIQUE
("TargetTable","TargetCode")`), `FK_RegistryFieldProvenance_DOCEFL` (`FOREIGN KEY ("DOCEFLCode")
REFERENCES "DOCEFL"("EFCode") ON DELETE RESTRICT`), `FK_RegistryFieldProvenance_DOCFLG` (`FOREIGN
KEY ("DOCFLGFlagInstanceID") REFERENCES "DOCFLG"("FlagInstanceID") ON DELETE RESTRICT`),
`RegistryFieldProvenance_Company_fkey` (auto-named inline FK, `FOREIGN KEY ("Company") REFERENCES
"CompanyRegistry"("CompanyCode") ON DELETE RESTRICT`), `CK_RegistryFieldProvenance_CompanyScope`,
`CK_RegistryFieldProvenance_AbsentHash`, `RegistryFieldProvenance_TargetTable_check` (auto-named),
`RegistryFieldProvenance_Marker_check` (auto-named) — all unchanged from the rejected candidate.
The two additional `pg_constraint` rows Postgres auto-registers for the table's own deferred
constraint triggers (`RequireExactlyOneProvenance_RegistryFieldProvenance`,
`RequireProvenanceAgreesWithTarget_RegistryFieldProvenance` — the latter is **new**, a direct
consequence of item 7 moving from `BEFORE` to a deferred `AFTER` constraint trigger) bring the
measured `pg_constraint` row count for this table to **11**.

**2 indexes on `RegistryFieldProvenance`** (both constraint-backed, unchanged): `RegistryFieldProvenance_pkey`,
`UQ_RegistryFieldProvenance_Target`.

**8 triggers total (widened from the rejected candidate's 7), by table, measured via
`pg_trigger`/`pg_get_triggerdef`:**
`DOCEFL` — `RequireExactlyOneProvenance_DOCEFL` (unchanged, item 6) and
`RequireProvenanceAgreesWithTarget_DOCEFL` (**redesigned**: `AFTER UPDATE OF "ItemClass"
DEFERRABLE INITIALLY DEFERRED`, was immediate);
`DOCFLG` — `RequireExactlyOneProvenance_DOCFLG` (unchanged, item 6),
`RequireProvenanceAgreesWithTarget_DOCFLG` (**redesigned**, same timing change), and
`RejectStaleProvenanceOnDocflgResolution` (unchanged, item 8/19);
`RegistryFieldProvenance` — `RequireExactlyOneProvenance_RegistryFieldProvenance` (unchanged, item
6), `RequireCompanyAgreement` (**new**, `BEFORE INSERT OR UPDATE`, item 5), and
`RequireProvenanceAgreesWithTarget_RegistryFieldProvenance` (**redesigned**: moved from `BEFORE
INSERT OR UPDATE` immediate to `AFTER INSERT OR UPDATE DEFERRABLE INITIALLY DEFERRED`, item 7). No
trigger is attached to any other accepted table.

**4 trigger functions (widened from the rejected candidate's 3):** `RequireCompanyAgreementFn`
(**new**, item 5), `RequireProvenanceAgreesWithTargetFn` (**redesigned body and timing**, item 7),
`CheckRegistryFieldProvenanceCardinalityFn` (unchanged, item 6),
`RejectStaleProvenanceOnDocflgResolutionFn` (unchanged, item 8/19). No other function is added, and
`WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn` are not redefined — proven directly (item 2 below) by
comparing `pg_get_functiondef` before and after this candidate's `Up`.

No role, ACL, `SECURITY DEFINER` function, or governed command is added. No accepted `ENTMST`,
`DOCEFL`, `DOCFLG`, or `ImportEvidenceRow` column or constraint is altered or dropped.

### Item-by-item remediation checklist evidence

**Items 1–4, 6, 8–15, 17–19 — Reject #1 Pass rows, regression-confirmed unchanged.**

1. **Amendment-4 reformulated preflight checks 1–5, check 6 non-adoption rule** — Pass, re-proven
   fresh above.
2. **Exact base-to-candidate surface and Piece B strict scope** — `git diff --name-status` against
   the pushed approval tip lists exactly 6 code/test paths: 3 new
   (`20260806190000_P11bPieceBRegistryFieldProvenance.cs`, `P11bPieceBSchemaSql.cs`,
   `tests/Sibyla.Tests/Persistence/P11bPieceBContractTests.cs`) and 3 modified
   (`P11aRegistryModelConfiguration.cs`, `SibylaDbContextModelSnapshot.cs`,
   `P11aDisposableDatabaseTests.cs`), plus this status file and `PROJECT-STATE.md`. No Piece C/D,
   role, ACL, `SECURITY DEFINER`, governed-command, or importer path.
   `P11bPieceBContractTests.Piece_b_sql_is_schema_only_and_exactly_scoped` passes, asserting no
   `CREATE ROLE`/`SECURITY DEFINER`/`GRANT`/`REVOKE`, no `ALTER TABLE` on any of
   `ENTMST`/`DOCEFL`/`DOCFLG`/`ImportEvidenceRow`, no redefinition of `WaiveDOCFLG` or
   `RejectTerminalDOCFLGMutationFn`, and the widened exact enumerated trigger/function roster (8
   triggers, 4 functions) above. Both accepted P1-1a and Piece A migration files
   (`20260805180000_P11aFdrSchema.cs`, `P11aSchemaSql.cs`,
   `20260806180000_P11bPieceASchemaCompleteness.cs`, `P11bPieceASchemaSql.cs`) are byte-identical
   to pre-implementation `HEAD` — verified directly by `git hash-object` matching the blob IDs
   `git ls-tree HEAD` records for those four paths.
3. **Minimal-surface discipline** — Pass, same contract test as item 2; no accepted object is
   altered by the redesign. The two pre-existing `P11aDisposableDatabaseTests.cs` fixtures
   extended with matching `authored` provenance rows by the original candidate are untouched by
   this remediation.
4. **Every provenance row has an FK to its target row; orphan provenance is impossible** — Pass,
   unchanged. `Piece_b_provenance_row_referencing_a_nonexistent_target_is_rejected` reproduced
   green.
6. **Exact cardinality on every path** — Pass, unchanged.
   `Piece_b_docefl_insertion_without_a_matching_provenance_row_is_rejected`,
   `Piece_b_deleting_the_only_provenance_row_for_a_target_is_rejected`,
   `Piece_b_moving_a_provenance_row_to_a_new_target_rechecks_the_old_target` reproduced green;
   `CheckRegistryFieldProvenanceCardinalityFn` is byte-for-byte untouched by this remediation.
8. **The accepted terminal command and the invariant agree on every path — `WaiveDOCFLG`** — Pass,
   unchanged; proven by item 19 below, a distinct mechanism from item 7's re-check.
9. **R7 direct assertion — accepted `ImportEvidenceRow` uniqueness untouched** — Pass, unchanged.
   `Piece_b_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_b_up`
   reproduced green (4/4 accepted unique constraints, identical indexes, before vs. after this
   candidate's `Up`).
10. **Generated columns exactly as generated, store type included** — Pass, unchanged; no column is
    added, removed, or retyped by this remediation.
    `Piece_b_ef_store_types_match_the_disposable_catalog_for_every_touched_column` reproduced green
    for all 9 columns.
11. **Closed vocabularies close twice** — Pass, unchanged. The `Marker` CHECK domain
    (`extracted|authored|absent`) is untouched; `RegistryValidationService.cs` and
    `PostgresRegistryValidationSnapshotSource.cs` still have zero references to any provenance
    surface, so closure remains at the database `CHECK` alone, stated explicitly.
13. **A missing provenance row is rejected** — Pass, proven by item 6's tests, unchanged.
14. **An orphan provenance row is rejected** — Pass, proven by item 4's test, unchanged.
15. **A wrong-company provenance row is rejected, same-company positive control** — Pass, mechanism
    now traced to the new dedicated `RequireCompanyAgreementFn` (still immediate); test shape
    unchanged. `Piece_b_wrong_company_provenance_row_is_rejected` reproduced green.
17. **A delete that would break cardinality is rejected** — Pass, proven by item 6's delete test,
    unchanged.
18. **A move that leaves the old target inconsistent is rejected** — Pass, proven by item 6's move
    test, unchanged.
19. **`WaiveDOCFLG` cannot leave stale `absent` provenance with a NULL hash** — Pass, unchanged;
    `Piece_b_waivedocflg_cannot_leave_stale_absent_provenance_with_a_null_hash` and the byte-identity
    test (item 2 below reference) reproduced green on the accepted command's real path.

**Item 2 (continued) — byte-identity of `WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn`:**
`Piece_b_waivedocflg_and_reject_terminal_mutation_function_bodies_are_unchanged` compares live
`pg_get_functiondef` output before vs. after this candidate's `Up` and passes — both definitions
byte-identical.

**Item 5 — Company agreement, mechanism traced to `RequireCompanyAgreementFn`, still immediate,
shape unchanged (Observation R-2).** Pass. Same test as item 15.

**Item 7 — `absent` agrees with the value, re-checked on target update, both orderings now succeed
(B-R1 fix).** Pass, on both `DOCEFL` and `DOCFLG`, both orderings:
- `Piece_b_r1_docefl_null_to_value_coupdate_succeeds_value_then_provenance` (R1a) and
  `Piece_b_r1_docefl_null_to_value_coupdate_succeeds_provenance_then_value` (R1b) each prove a
  `DOCEFL` row transitions honest `NULL`/`absent` to a real value with `authored` provenance, via
  exactly two `UPDATE` statements in the stated order, commit succeeds, final state read back and
  asserted consistent.
- `Piece_b_r1_docflg_null_to_value_coupdate_succeeds_value_then_provenance` (R1c) and
  `Piece_b_r1_docflg_null_to_value_coupdate_succeeds_provenance_then_value` (R1d) prove the same
  transition on `DOCFLG`, both orderings, with the `DOCEFL` parent pre-set to an already-agreeing
  non-`NULL` `ItemClass` so the O10-D1 composite `MATCH SIMPLE` FK does not itself block the
  `DOCFLG`-side transition under test.
- `Piece_b_r1_unaccompanied_value_change_alone_still_fails_closed_at_commit` (R1e) and
  `Piece_b_r1_unaccompanied_provenance_change_alone_still_fails_closed_at_commit` (R1f) prove a
  single-statement, one-sided change (target alone, or provenance alone) still fails — now
  asserted as a `COMMIT`-time failure per Observation R-1/R-2, not a statement-time failure —
  target value and provenance row both confirmed unchanged after the failed commit.
- `Piece_b_r1_legitimate_coupdate_is_proven_directly_not_via_delete_then_insert` (R1g) directly
  asserts, over the exact SQL text constants R1a–R1d execute, that each co-update is exactly two
  `UPDATE` statements — no `DELETE`, no `INSERT` — a direct, non-database assertion that the proof
  does not depend on the rejected candidate's undocumented delete-update-insert gap. This test
  needs no disposable connection and does not open one — an honest scope note, not a claim that a
  database was exercised for it.

**Item 16 — value/provenance-contradiction rejected, reshaped per Observation R-2.** Pass.
`Piece_b_absent_and_hash_agree_with_the_governed_value` now proves: the same-row CHECK sub-case
(an unknown marker literal) remains immediate/statement-time, unaffected; the three cross-table
sub-cases (`absent` for a non-null value, non-`absent` for a `NULL` value, a mismatched hash) each
now succeed at the offending `INSERT` statement itself and fail only at `COMMIT`
(`PostgresErrorCodes.CheckViolation`), with the provenance row confirmed absent afterward in each
case — the required outcome (rejection) is unchanged; only the point in the transaction at which it
is observed changed, exactly as approved.

**Item 20 — Claims equal assertions, design-note correction.** Pass. This evidence map claims
exactly what R1a–R1g and the reshaped item-16 test assert: both natural statement orderings of a
legitimate `NULL`→value co-update succeed at `COMMIT` for both `DOCEFL` and `DOCFLG`; an
unaccompanied one-sided change fails closed at `COMMIT`; the proof uses exactly two `UPDATE`
statements per co-update, never the rejected candidate's delete-update-insert sequence, which is
not part of this design and is exercised by no test in the suite. No projected counts: the 9-column,
11-`pg_constraint`-row, 2-index, 8-trigger, 4-function roster above is measured from the live
migrated catalog, not assumed from the mapping's shape-level commitment.

### Regression fixture hygiene — one honest observation

R1c and R1d each commit a real, permanent `DOCFLG` row (`FLPB0110`, `FLPB0111`) and its full
company/entity/import-evidence fixture chain. `DOCFLG` is accepted-schema append-only
(`RejectTerminalDOCFLGMutationFn` rejects every `DELETE`, not only terminal-status ones), so these
rows — and everything they hold an `ON DELETE RESTRICT` reference to — cannot be cleaned up after
the test, exactly like the pre-existing accepted Piece A tests that also commit real `DOCFLG` rows
(e.g. `FLPA0001`). Both fixtures use concrete non-null `ENTMST.DirectDebit`/`TaxIdVerificationStatus`
values (not the honest `NULL` other Piece B fixtures use) specifically so no later Down-migration
test that restores the pre-Piece-A `NOT NULL` constraints on those columns is broken by a
permanently-committed `NULL`. `DOCFLG.ItemClass` itself is the one column intentionally `NULL` at
setup and is transitioned to a real value by each test's own successful co-update, so it is never
left `NULL` at commit either.

### Measured verification (this remediation implementation)

| Verification | Result |
|---|---:|
| Build | **0 warnings, 0 errors** (`dotnet build GOTT.Sibyla.slnx -c Release --no-incremental`) |
| Ordinary suite | **640/640** (637 base + 3 focused contract tests, same as before — no ordinary-suite count changes) |
| Focused suite (`P11bPieceBContractTests`) | **3/3** |
| Disposable PostgreSQL 17 suite (`Category=P11aDatabase`) | **34/34** — 16 Piece A + 18 Piece B (11 base-shape + 7 new `Piece_b_r1_*`/R1g) |
| `git diff --check` | clean |
| Risk/secret/role/`SECURITY DEFINER`/`DROP OWNED` scan (added lines only) | 0 matches |
| Accepted P1-1a migration files (`20260805180000_P11aFdrSchema.cs`, `P11aSchemaSql.cs`) | byte-identical to pre-implementation `HEAD` |
| Accepted Piece A migration files (`20260806180000_P11bPieceASchemaCompleteness.cs`, `P11bPieceASchemaSql.cs`) | byte-identical to pre-implementation `HEAD` |
| `WaiveDOCFLG` / `RejectTerminalDOCFLGMutationFn` (live `pg_get_functiondef`) | byte-identical before/after `Up` |
| Up/Down/Up catalog stability (`Piece_b_down_is_exact_and_up_down_up_is_catalog_stable`) | Pass — additive base = post-`Down`; first `Up` = second `Up` |
| Residual `sibyla-p11*` containers | **0** |

### What this step did and did not do

Implemented the Piece B B-R1 remediation as a remediation of candidate `b8fa033…`, TDD first, from
the pushed approval tip. Reapplied the candidate's 19-Pass foundation unchanged plus exactly the
approved remediation (item 5/7 split, three deferred constraint triggers, R1a–R1g, item-20
correction, item 2/12 roster widenings). No other content change. Piece C, Piece D, and Scope 1
remain gated and unstarted. Baselines 119 / 119 / 52 / 221 / 2,787, the two verbatim `Routine` rows,
pin `b917685…`, and every O8/O9/O10 decision are unchanged; O5-prep remains deferred; O5 remains the
only other open item. **Piece B still has no accepted implementation** until the fresh independent
adversarial review (ordered instruction 4) runs in a fresh session and records an explicit verdict.

### Verification of this implementation stage

| Verification | Result |
|---|---:|
| Changed code/test paths | exactly **6** — 3 new, 3 modified |
| Records paths changed in the same commit | `docs/p1-1b-status.md`, `docs/PROJECT-STATE.md` |
| Candidate/history access mode | read-only `git show`/`git diff` against `b8fa033…` for remediation planning; no path restored, cherry-picked, or force-copied — every file was authored fresh against the approved design |
| Prototype repository operations | preflight only (read-only, see above) |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `1627dd6ea84b4a7310c8d5ebdadd714aada94cec`, clean tree, `0 0` divergence |

## 2026-08-06 Piece B B-R1 remediation test-plan gate — Miguel's approval recorded

This step records the gate decision required by the go-ahead's standing test-plan gate and
amendment 5's remediation basis, for the B-R1 remediation checklist→test mapping recorded
immediately below in this file (section "2026-08-06 Piece B remediation test-plan gate — B-R1
checklist→test mapping, regression plan, design observations, awaiting Miguel's approval"). The
decision is recorded in `docs/AGENT-PROMPT-v5-P1-1b-piece-b-remediation-approval.md`, tracked and
pushed at `2d09612a68786bb22178ef4d6bb6fcc978b89fa4`. This step performs no implementation,
migration, model, constraint, trigger, validator, fixture, test, prototype, database, or container
work of any kind.

### Decision: Approved, with both observations decided in the plan's favor

The B-R1 remediation checklist→test mapping — the Reject #1 disposition table with its 19 Pass
rows carried forward as regression requirements, plus B-R1's correction to items **7** and **20**
exactly, mapped to R1a–R1g and the item-20 design-note correction — is **approved as the binding
Piece B remediation test plan**. The root-cause analysis (PostgreSQL can defer only `AFTER`
constraint triggers; the rejected candidate mixed an immediate `AFTER` target-side trigger with an
immediate `BEFORE` provenance-side trigger, so no single-sided adjustment closes both orderings)
and the item 5/item 7 split along the checklist's own boundary are confirmed as the narrowest shape
consistent with amendment 3's "closed by construction, not patched".

1. **Observation R-1 — resolved as option (b), both orderings.** The remediation must support
   **both natural statement orderings** of a legitimate value/provenance co-update: item 7 is
   re-implemented as `DEFERRABLE INITIALLY DEFERRED` `AFTER` constraint triggers at the three
   attachment points (`RegistryFieldProvenance` insert/update, `DOCEFL` and `DOCFLG`
   `AFTER UPDATE OF "ItemClass"`), each re-querying **live** state at `COMMIT`, so both orderings
   see the identical final state and an unaccompanied one-sided change still fails closed at
   `COMMIT`. Option (a) — deferring only one side — is rejected: it would silently couple Piece
   C's future O10-D2 `AssignDOCEFLItemClass` command to a fixed statement order and reintroduce
   B-R1's failure mode invisibly on any reordering. Item 5 (company agreement) keeps its own
   dedicated, still-immediate `BEFORE INSERT OR UPDATE` function (`RequireCompanyAgreementFn`) on
   `RegistryFieldProvenance` alone.
2. **Observation R-2 — accepted as a necessary consequence of R-1.** The proof-mechanism shape
   changes to already-Pass items 5/15/16 are approved: 5/15 trace to the new dedicated immediate
   function with unchanged test shape; 16's cross-table sub-case moves from statement-time to
   commit-time rejection (same-row CHECK sub-cases untouched), mirroring the shape item 6's
   deferred cardinality tests already use. The required outcome — rejection — changes in neither
   case; only the point in the transaction at which it is observed changes.

### Confirmed scope notes

The "no provenance row at commit" branch of item 7's redesigned trigger is accepted **only**
because item 6's independent deferred cardinality trigger unconditionally forecloses that state
first; no test may construct a row-less-at-commit transaction to obtain a passing item-7 outcome,
and R1g's direct two-`UPDATE`-only assertion plus the explicit no-reliance statement on the
rejected candidate's delete-update-insert gap are part of the approved plan. The trigger/function
roster growing to a proposed **8 triggers / 4 functions** is approved as **shape**, with the exact
DDL and catalog roster fixed when `Up` is authored during remediation TDD and reported item by item
in the remediation's own evidence map. Items 2 and 12's widened roster assertions are part of the
regression plan.

### What is now authorized

Ordered instruction 3 of the go-ahead, on the remediation basis amendment 5 established for piece
candidates: implement the Piece B remediation as a **remediation of candidate `b8fa033…`** under
the amendment-4 reformulated preflight (checks 1–5 re-run fresh and passing; check-6 divergence
logged without reading or adopting post-pin content), TDD first from this pushed approval tip —
applying exactly the approved redesign (the item 5/7 split, the three deferred constraint
triggers, R1a–R1g, the item-20 design-note correction, and the item 2/12 roster widenings) and
**no other content change**; full ordinary, focused, and disposable suites green; build 0
warnings; 0 residual containers; both accepted P1-1a and Piece A migration files byte-identical;
`WaiveDOCFLG` and `RejectTerminalDOCFLGMutationFn` proven byte-identical; the status evidence map
keyed to the 20-item remediation checklist item by item, with measured counts only; commit and
push. Then ordered instruction 4: the fresh independent adversarial review in an independent
session, verdict recorded. On Accept, stop and report. On Reject, neutralize per amendment 3, stop,
and escalate to Miguel: **this is the second and final Piece B attempt before escalation.**

### What this approval does not authorize

Starting Piece C or D, or any Scope 1 work. Any content change beyond the approved remediation
diff. Resurrecting any part of the three monolithic rejects or rejected Piece A candidate
`6f86023d…` (Piece B candidate `b8fa033…` is remediated under this approval, never merged as-is).
Relying on, testing through, or documenting the delete-update-insert gap as a supported path. Any
prototype write or post-pin read. Reopening any closed decision or changing any baseline. Any
shared/live database write. Production go-live (O5 remains the only other open item; O5-prep
remains deferred by decision). History rewrite in either repository.

Baselines 119 / 119 / 52 / 221 / 2,787, the two verbatim `Routine` rows, pin `b917685…`, and every
O8/O9/O10 decision are unchanged. This records step performs no implementation, migration, model,
constraint, trigger, test, fixture, prototype, database, container, service, deployment, or
live-data work; Piece B remediation implementation has not started as of this commit.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `2d09612a68786bb22178ef4d6bb6fcc978b89fa4`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it.

## 2026-08-06 Piece B remediation test-plan gate — B-R1 checklist→test mapping, regression plan, design observations, awaiting Miguel's approval

This step performs the amendment-5 remediation test-plan gate required after Piece B candidate
`b8fa0333035c59e8b154554aa984d038853ab069`'s Reject #1 — binding finding **B-R1**
(`docs/p1-1b-o10-independent-review.md`, "Piece B candidate review — Reject #1"). Per amendment 5's
remediation basis (0 Critical, an enumerated disposition table), the reattempt, when authorized, is
a **remediation of the rejected candidate**, not a rewrite. This step records only the
checklist→test mapping and design observations required by the go-ahead's own instruction 4 and
amendment 5's test-plan-gate rule. **It performs no implementation, migration, model, constraint,
trigger, validator, fixture, test, database, or container work of any kind, and no code, migration,
model, or test path is touched. Implementation remains unauthorized until Miguel explicitly approves
this mapping** — exactly as it did for the original Piece B mapping and for Piece A's own
remediation cycle.

### Live Git state verified fresh

Local `HEAD` = `origin/feature/p1-1b` = `b0d7445c5885f4d1b43e6f933403c8200649b18a`, clean working
tree, `git rev-list --left-right --count origin/feature/p1-1b...feature/p1-1b` = `0 0`. This matches
the expected tip recorded at the close of the prior records step and was verified fresh in this
step, not trusted from a prior record.

### Read-only inspection performed for this mapping

`docs/p1-1b-o10-independent-review.md`'s "Piece B candidate review — Reject #1" section was read in
full: the central finding, the empirical two-ordering probe table and its exact error codes/messages,
the requirement-by-requirement disposition of all 20 checklist items, the missing-coverage note, and
the positive confirmations. The prior Piece B mapping and evidence-map sections in this file were
re-read for the accepted design description (trigger/function roster, attachment points) and the
exact test method names already in evidence. Rejected candidate `b8fa033…` was inspected **read-only
through Git history only** (`git show`, `git log`) — no path was restored, cherry-picked, or
modified, and no implementation path exists in the working tree to inspect directly (all 6 are
neutralized to records base `87499a1…`, as verified by the unchanged `git status`/`git diff --check`
clean tree above). No prototype access occurred in this step.

### The remediation checklist

Per amendment 5's remediation basis and the go-ahead's own instruction 4: the remediation checklist
is the Reject #1 disposition table — **all 20 items, with the dispositions the review recorded** —
applied as a correction to items **7** (Partial/Fail) and **20** (Fail) exactly. No other checklist
item, decision, or baseline is reopened. The **19** items the review disposed **Pass** — 1, 2, 3, 4,
5, 6, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, plus the positive confirmations — are carried
forward unchanged as regression requirements for the reattempt, per this task's own instruction and
the identical precedent Piece A's own A-R1…A-R4 remediation cycle set.

### B-R1, restated exactly as reviewed — binding, not reopened

The `RequireProvenanceAgreesWithTarget_DOCEFL`/`_DOCFLG` (`AFTER UPDATE OF "ItemClass"`) triggers and
`RequireProvenanceAgreesWithTargetFn`'s `BEFORE INSERT OR UPDATE` path on `RegistryFieldProvenance`
are **both immediate (non-deferrable)**. The review **empirically proved**, against a live disposable
PostgreSQL 17 database, that **neither statement ordering** of a plain two-statement transaction
(update the governed value then its provenance row, or the reverse) can legitimately transition a
governed `DOCEFL`/`DOCFLG` `ItemClass` value from `NULL` to a real value while keeping
`RegistryFieldProvenance` in agreement:

- Value-then-provenance fails: `RequireProvenanceAgreesWithTarget_DOCEFL`/`_DOCFLG` fires immediately
  after the value `UPDATE`, before the provenance `UPDATE` runs, and rejects against the **stale**
  provenance row (`23514 stale absent provenance for DOCEFL … after the governed value changed to
  non-NULL`).
- Provenance-then-value fails: `RequireProvenanceAgreesWithTargetFn`'s `BEFORE` path fires
  immediately on the provenance `UPDATE`, before the value `UPDATE` runs, and rejects against the
  **stale** target value (`23514 non-absent provenance recorded for DOCEFL … but the governed value
  is NULL`).

The only sequence that succeeds — `DELETE` the stale provenance row, `UPDATE` the target value,
`INSERT` a fresh provenance row — exploits an undocumented, untested validation gap
(`RequireProvenanceAgreesWithTargetFn`'s `AFTER UPDATE` path silently no-ops when no provenance row
currently exists) rather than exercising the "re-check" checklist item 7 and the candidate's own
design note both describe. **This gap is not accepted proof and this mapping does not rely on it in
any form.** Item 7 is disposed **Partial/Fail**; item 20 is disposed **Fail** because the design
note's claim overstates what was demonstrated. No other item is affected — the deferred cardinality
trigger and the immediate insert-time checks together still prevent any permanently-inconsistent
committed state.

### Root cause and the narrowest remediation design consistent with R4 closed-by-construction

PostgreSQL can only defer trigger evaluation to `COMMIT` (or an explicit `SET CONSTRAINTS`
checkpoint) for **constraint triggers**, and a constraint trigger must be declared `AFTER` — a
`BEFORE` trigger can never be deferred. The rejected candidate's design mixes an immediate `AFTER`
trigger on `DOCEFL`/`DOCFLG` with an immediate `BEFORE` trigger on `RegistryFieldProvenance`; each
validates the *other* table's state as of the moment it fires, which is necessarily stale for
whichever statement of a two-statement co-update runs second. No adjustment to only one side closes
both orderings: probed algebraically against the same two triggers —
  - deferring only the `DOCEFL`/`DOCFLG`-side trigger still leaves the immediate `RegistryFieldProvenance`-side
    `BEFORE` trigger checking a stale target value on the provenance-then-value ordering, so
    value-then-provenance would newly succeed but provenance-then-value would still fail;
  - deferring only the `RegistryFieldProvenance`-side trigger (moved to `AFTER`, deferred) still
    leaves the immediate `DOCEFL`/`DOCFLG`-side trigger checking a stale provenance row on the
    value-then-provenance ordering, so provenance-then-value would newly succeed but
    value-then-provenance would still fail.

**Proposed remediation (narrowest shape that reaches both orderings):** split
`RequireProvenanceAgreesWithTargetFn`'s two responsibilities exactly along the checklist's own item
5/item 7 boundary, and change only the item 7 half's timing:

- **Item 5 (company agreement) is unchanged in substance.** A new, dedicated trigger function
  (proposed name `RequireCompanyAgreementFn`) keeps the existing immediate `BEFORE INSERT OR UPDATE`
  attachment on `RegistryFieldProvenance` alone, validating the new/updated provenance row's
  `Company` against the target's live `Company`. Company does not change as part of a
  `NULL`→value `ItemClass` transition, so this half never needs to observe a co-update's other
  statement, and immediacy remains safe.
- **Item 7 (absent/value agreement, the re-check on target update) is re-implemented as
  `DEFERRABLE INITIALLY DEFERRED` constraint triggers**, attached at three points, all `AFTER`:
  `RegistryFieldProvenance` (`AFTER INSERT OR UPDATE` — moved from `BEFORE` to make deferral
  possible at all), `DOCEFL` (`AFTER UPDATE OF "ItemClass"`, now deferrable), `DOCFLG`
  (`AFTER UPDATE OF "ItemClass"`, now deferrable). Each firing re-queries the **live** current state
  of both sides — the governed value and the current provenance row — the same live-lookup pattern
  the accepted `CheckRegistryFieldProvenanceCardinalityFn` (item 6) already uses, rather than relying
  on the captured `OLD`/`NEW` of its own firing statement. Because execution is deferred to
  `COMMIT`, by the time any of the three fires, every statement in the transaction has already
  applied; both natural orderings of a two-statement co-update therefore see the identical final
  state at commit and are validated identically, regardless of which statement ran first.
- If, at commit, no provenance row exists for a target at all, item 7's trigger has nothing to
  compare and performs no check for that reason — this is **not** a re-introduction of the rejected
  candidate's gap, because item 6's own independent deferred cardinality trigger separately and
  unconditionally guarantees exactly one provenance row exists per governed member at commit;
  existence is item 6's invariant, agreement is item 7's, and both are enforced independently and
  unconditionally at commit. No test relies on a transaction that leaves a target with zero
  provenance rows at commit to reach a passing outcome for item 7 — item 6 rejects that transaction
  first, on its own terms, exactly as the accepted regression already proves.

This changes only Piece B's own never-accepted objects; no accepted P1-1a or Piece A object, role,
ACL, or `WaiveDOCFLG`/`RejectTerminalDOCFLGMutationFn` surface is touched, so item 3 (minimal-surface
discipline) is unaffected. The trigger/function roster grows from 7 triggers / 3 functions (the
rejected candidate) to a proposed **8 triggers / 4 functions** — the exact DDL, like items 10/12 in
the original mapping, is fixed when `Up` is authored during remediation TDD and reported item by item
in the remediation's own evidence map; this mapping commits to the **shape**, consistent with the
same convention Observation 2 already established and Miguel already approved for this piece.

### Observation R-1 — intended transactional semantics: both orderings, not one — reported for Miguel's explicit confirmation

Checklist item 7's own text requires "the trigger re-checks... against the new governed values"
without stating whether one or both natural statement orderings must succeed; B-R1 found **neither**
works today. Two resolutions were considered:

- **(a) Defer only one side**, supporting exactly one ordering. Narrower diff, but it silently
  couples Piece B's fix to a statement order Piece C's future O10-D2 `AssignDOCEFLItemClass` command
  would then be forced to use — a command that does not exist yet and whose own checklist has not
  been written. Any accidental reordering inside that future command would reintroduce exactly
  B-R1's failure mode without a further Piece B change ever being visible to Piece B's own tests.
- **(b) Defer both sides** (proposed above), supporting both orderings symmetrically because deferred
  constraint-trigger evaluation is order-independent once every statement in the transaction has run.
  This is the option proposed above.

**Proposed resolution: (b).** Nothing in the go-ahead or the checklist restricts Piece B's invariant
to a single statement order, and amendment 3 requires R4 to be "closed by construction, not patched"
— a fix that only works for one accidental ordering is closer to a patch than a construction. This is
submitted for Miguel's explicit confirmation, exactly as the go-ahead's own scope note required for
the original `WaiveDOCFLG` question; it is not adopted silently.

### Observation R-2 — proof-mechanism shape change for two already-Pass items — reported for Miguel's explicit confirmation

Splitting company agreement from absent/value agreement, and deferring the latter, changes the
**proof mechanism** (not the required outcome) of two items the review already disposed Pass:

- **Item 5** keeps its own dedicated immediate trigger function; the existing proof shape
  (`Piece_b_wrong_company_provenance_row_is_rejected`, rejection on the offending statement itself)
  needs no change.
- **Item 16**'s cross-table sub-case (a provenance row's `Marker`/`ValueHash` disagreeing with the
  target's **live** `ItemClass` value, as opposed to the same-row `Marker`-vs-`ValueHash`
  self-consistency already enforced by the unaffected `CK_RegistryFieldProvenance_AbsentHash` CHECK,
  and the unaffected unknown-marker-literal CHECK) moves from immediate rejection to commit-time
  rejection, mirroring the shape item 6's own deferred cardinality tests already use. The existing
  test `Piece_b_absent_and_hash_agree_with_the_governed_value`'s cross-table assertions need
  reshaping from "the `INSERT`/`UPDATE` statement itself raises" to "the transaction succeeds until
  `COMMIT`, then `COMMIT` raises"; its same-row CHECK-level assertions are untouched.

**Proposed resolution:** accept both shape changes as a necessary consequence of Observation R-1's
resolution; the required behaviour (rejection) is preserved in both cases, only the point in the
transaction at which it is observed changes. Reported here, not adopted silently, alongside R-1.

### B-R1 → test-plan mapping

| # | Proposed test (New) | Surface | Proves |
|---:|---|---|---|
| R1a | `Piece_b_r1_docefl_null_to_value_coupdate_succeeds_value_then_provenance` | Disposable | A `DOCEFL` row with `ItemClass` honestly `NULL` and `absent` provenance transitions to a real value with `authored` provenance in one committed transaction: `UPDATE "DOCEFL"` then `UPDATE "RegistryFieldProvenance"`, both statements, commit succeeds, final state read back and asserted consistent. |
| R1b | `Piece_b_r1_docefl_null_to_value_coupdate_succeeds_provenance_then_value` | Disposable | The same transition, reverse statement order: `UPDATE "RegistryFieldProvenance"` then `UPDATE "DOCEFL"`, commit succeeds, same final-state assertion. |
| R1c | `Piece_b_r1_docflg_null_to_value_coupdate_succeeds_value_then_provenance` | Disposable | The same transition on `DOCFLG`, value-then-provenance ordering; fixture pre-sets the row's `DOCEFL` parent to an already-agreeing non-`NULL` `ItemClass` so the O10-D1 composite `MATCH SIMPLE` FK does not itself block the `DOCFLG`-side transition being tested. |
| R1d | `Piece_b_r1_docflg_null_to_value_coupdate_succeeds_provenance_then_value` | Disposable | The same `DOCFLG` transition, reverse order. |
| R1e | `Piece_b_r1_unaccompanied_value_change_alone_still_fails_closed_at_commit` | Disposable | Reshape of the existing re-check sub-case in `Piece_b_absent_and_hash_agree_with_the_governed_value`: a single-statement transaction that updates only `DOCEFL`/`DOCFLG` `ItemClass` (no accompanying provenance statement) still fails — now asserted as a `COMMIT`-time failure per Observation R-1/R-2, not a statement-time failure; target value and provenance row both confirmed unchanged after rollback. |
| R1f | `Piece_b_r1_unaccompanied_provenance_change_alone_still_fails_closed_at_commit` | Disposable | New negative, symmetric to R1e: a single-statement transaction that updates only `RegistryFieldProvenance` (`Marker`/`ValueHash` to agree with a value the target does not yet have; no accompanying target statement) still fails at `COMMIT`; target value and provenance row both confirmed unchanged after rollback. |
| R1g | `Piece_b_r1_legitimate_coupdate_is_proven_directly_not_via_delete_then_insert` | Disposable + documentation obligation | R1a–R1d's transactions are asserted to contain **exactly two** `UPDATE` statements each (no `DELETE`, no `INSERT`) — a direct assertion that the proof does not depend on the rejected candidate's undocumented gap. The remediation's own status evidence map states explicitly that the `DELETE`-then-`UPDATE`-then-`INSERT` sequence is not part of the design and is exercised by no test in the suite, mirroring proof-pattern rule 1 ("claims equal assertions"). |
| — | Design-note correction (item 20) | Documentation obligation | The status record's design-note language is corrected to claim exactly what R1a–R1f prove — both orderings succeed for a legitimate co-update, commit-time (not statement-time) fail-closed for an unaccompanied change — replacing the rejected candidate's overstated "re-validat[es]... against the new value" claim that item 20 found unproven. |

### Regression plan — the 19 Pass rows

| # | Item | Mechanism affected by the R-1/R-2 redesign? | Regression requirement |
|---:|---|---|---|
| 1 | Preflight checks 1–5, check-6 non-adoption | No | Re-run fresh at remediation start, identical shape to every prior attempt. |
| 2 | Exact base-to-candidate surface, strict scope | Trigger/function count changes (7→8, 3→4) | `Piece_b_sql_is_schema_only_and_exactly_scoped`'s enumerated trigger allow-list is updated to the new 8-trigger roster; its negative assertions (no role/ACL/`SECURITY DEFINER`/accepted-object alteration) are otherwise unchanged. |
| 3 | Minimal-surface discipline | No | Same contract test as item 2; no accepted object is altered by the redesign. |
| 4 | Orphan FK impossible | No | `Piece_b_provenance_row_referencing_a_nonexistent_target_is_rejected` unchanged. |
| 5 | Company agreement schema-enforced | Mechanism only (Observation R-2) | `Piece_b_wrong_company_provenance_row_is_rejected` unchanged in shape; now traced to the new dedicated `RequireCompanyAgreementFn`, still immediate. |
| 6 | Exact cardinality, every path | No | `Piece_b_docefl_insertion_without_a_matching_provenance_row_is_rejected`, `Piece_b_deleting_the_only_provenance_row_for_a_target_is_rejected`, `Piece_b_moving_a_provenance_row_to_a_new_target_rechecks_the_old_target` unchanged; `CheckRegistryFieldProvenanceCardinalityFn` is not touched by this remediation. |
| 8 | `WaiveDOCFLG` agreement | No | `RejectStaleProvenanceOnDocflgResolutionFn` and its trigger are a distinct mechanism from item 7's, untouched by this remediation. |
| 9 | `ImportEvidenceRow` uniqueness untouched | No | `Piece_b_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_b_up` unchanged. |
| 10 | Generated columns exactly as generated | No | The three A-R2-shaped tests unchanged; no column is added, removed, or retyped by this remediation. |
| 11 | Closed vocabularies close twice | No | Marker-vocabulary CHECK and validator non-observation statement unchanged. |
| 12 | Exact `Down`; Up/Down/Up stability | Trigger/function count changes | `Piece_b_down_is_exact_and_up_down_up_is_catalog_stable` widened to snapshot the new 8-trigger/4-function roster; the equality assertions themselves (accepted base = post-`Down`; first `Up` = second `Up`) are unchanged in kind. |
| 13 | Missing provenance row rejected | No | Proven by item 6's tests, unchanged. |
| 14 | Orphan provenance row rejected | No | Proven by item 4's test, unchanged. |
| 15 | Wrong-company provenance row rejected | Mechanism only (Observation R-2) | Same as item 5 above. |
| 16 | Value/provenance-contradiction rejected | Mechanism + shape (Observation R-2) | Same-row CHECK sub-cases (absent-vs-null-hash self-consistency, unknown marker literal) unchanged; cross-table sub-case reshaped per R1e above and Observation R-2. |
| 17 | Delete breaking cardinality rejected | No | Proven by item 6's delete test, unchanged. |
| 18 | Move leaving old target inconsistent rejected | No | Proven by item 6's move test, unchanged. |
| 19 | `WaiveDOCFLG` real-path proof | No | `Piece_b_waivedocflg_cannot_leave_stale_absent_provenance_with_a_null_hash` and the byte-identity test unchanged; both independently confirmed unaffected by the central finding in the review itself. |

All 19 Pass rows are retained as regression requirements; only items 5, 15, and 16 change proof
**mechanism** (traced to a different, still-immediate function for 5/15; reshaped to commit-time for
16's cross-table sub-case), and only items 2 and 12 change **surface size** (trigger/function count),
none change **required outcome**.

### No silent reliance on the delete-update-insert gap — explicit statement

The proposed redesign does not use, depend on, or pass through the rejected candidate's
`DELETE`-then-`UPDATE`-then-`INSERT` sequence at any point: R1a–R1d prove the legitimate transition
via exactly two `UPDATE` statements in either order, and R1g directly asserts no `DELETE`/`INSERT`
appears in those transactions. The "no provenance row exists at commit" branch of item 7's redesigned
trigger is not exercised as a passing path by any test in this mapping — it exists only because item
6 independently forecloses that state before item 7 could ever observe it, and no test is proposed
that constructs a transaction leaving a target row-less at commit to obtain a passing item-7 outcome.

### Claims equal assertions (item 20, applied to this mapping itself)

This mapping proposes test method names, surfaces, and the exact behaviour each must assert; it
claims no suite-count projection, no measured figures, and no DDL beyond the shape described above.
The exact trigger/function DDL, the final trigger/function counts, and the exact catalog roster are
fixed only when remediation `Up` is authored during TDD (if and when authorized) and reported item by
item in the remediation's own evidence map — the same discipline the original mapping's Observation 2
already established for items 10/12 and that Miguel already approved for this piece.

### What this step did and did not do

Recorded the B-R1 remediation checklist→test mapping, the regression plan for all 19 Pass rows, and
two design observations (R-1, R-2) for Miguel's explicit approval. Inspected the rejected candidate
and the independent review **read-only through Git history only** — no path was restored,
cherry-picked, or modified; no implementation, migration, model, constraint, trigger, validator,
fixture, test, prototype, database, container, service, deployment, or live-data work occurred.
Piece C, Piece D, and Scope 1 remain gated and unstarted. Baselines 119 / 119 / 52 / 221 / 2,787, the
two verbatim `Routine` rows, pin `b917685…`, and every O8/O9/O10 decision are unchanged; O5-prep
remains deferred; O5 remains the only other open item.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Candidate/history access mode | read-only `git show`/`git log` only — no candidate path restored, cherry-picked, or modified |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `b0d7445c5885f4d1b43e6f933403c8200649b18a`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it.

### Gate statement — Miguel's decision is required before remediation implementation

This mapping is submitted under the go-ahead's standing test-plan gate, per amendment 5's remediation
basis. **Piece B remediation implementation remains unauthorized until Miguel records an explicit
approval of this mapping**; the instruction to record it is not approval of it. Requested decision:
**approve**, **reject**, or **return with corrections** — in particular on **Observation R-1**
(whether the remediation must support both natural statement orderings, as proposed, or only one) and
**Observation R-2** (whether the proof-mechanism shape changes to already-Pass items 5/15/16 are an
acceptable consequence of R-1's resolution).

## 2026-08-06 Piece B independent review — Reject #1, neutralized

Ordered instruction 4 of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-goahead.md` — the first independent
adversarial review of Piece B — ran fresh in an independent session against candidate
`b8fa0333035c59e8b154554aa984d038853ab069` (records/approval base `87499a15fd8fa9e4b32ce9d1d4c47bb805abf1d7`).
Full verdict, disposition, and empirical proof are recorded in
`docs/p1-1b-o10-independent-review.md` ("Piece B candidate review — Reject #1"). **Verdict: Reject
— 0 Critical, 1 High, 0 Medium, 0 Low.**

### Binding finding B-R1 (High)

The `RequireProvenanceAgreesWithTarget_DOCEFL`/`_DOCFLG` (`AFTER UPDATE OF "ItemClass"`) trigger and
`RequireProvenanceAgreesWithTargetFn`'s `BEFORE INSERT OR UPDATE` path on `RegistryFieldProvenance`
are both immediate (non-deferrable). The review independently proved, empirically against a live
disposable PostgreSQL 17 database, that **neither statement ordering** of a plain two-statement
transaction (update the governed value then its provenance row, or the reverse) can legitimately
transition a governed `DOCEFL`/`DOCFLG` `ItemClass` value from `NULL` to a real value while keeping
`RegistryFieldProvenance` in agreement — each ordering is rejected by the *other* trigger validating
against the counterpart's not-yet-updated state. The only sequence that succeeds
(`DELETE` the stale provenance row, `UPDATE` the target value, `INSERT` a fresh provenance row)
exploits an undocumented, untested validation gap (`RequireProvenanceAgreesWithTargetFn`'s `AFTER
UPDATE` path silently no-ops when no provenance row currently exists) rather than exercising the
"re-check" checklist item 7 and the candidate's own design note both describe. No test in the
candidate proves any legitimate co-update succeeds. Because this is exactly the transition Piece
C's O10-D2 `AssignDOCEFLItemClass` command must perform, Piece C cannot be built against these
triggers as designed without either depending on the undocumented workaround or altering Piece B's
accepted trigger definitions — forbidden without a future piece's checklist naming that exact
change. Full proof, the exact error codes/messages from both failing orderings, and the working
workaround are recorded in the review.

**This finding is binding for any future Piece B remediation attempt.** It is not fixed here. No
remediation test-plan mapping has been recorded, and no remediation code has been written; per the
go-ahead's ordered instruction 4 and amendment 5's test-plan-gate rule, a remediation test-plan
mapping B-R1 to its exact proof must be recorded and approved by Miguel before any remediation
code, exactly as Piece A's own remediation cycle required after its Reject #1.

### Neutralization performed in this same records step

Per amendment 3's per-piece rule ("A piece that is Rejected is neutralized exactly as before — a
normal branch-tip stop commit restoring that piece's changed paths byte-for-byte to its own
starting point") — and because Piece B was implemented from zero with no prior candidate, its "own
starting point" is the pre-implementation records/approval base `87499a1…` — all 6
implementation/test paths changed by candidate `b8fa033…` are restored byte-for-byte to their exact
`87499a1…` content in the same commit as this review record:

| Path | Action |
|---|---|
| `src/Sibyla.Infrastructure/Persistence/Migrations/20260806190000_P11bPieceBRegistryFieldProvenance.cs` | Removed (did not exist at `87499a1…`) |
| `src/Sibyla.Infrastructure/Persistence/Migrations/P11bPieceBSchemaSql.cs` | Removed (did not exist at `87499a1…`) |
| `tests/Sibyla.Tests/Persistence/P11bPieceBContractTests.cs` | Removed (did not exist at `87499a1…`) |
| `src/Sibyla.Infrastructure/Persistence/Migrations/SibylaDbContextModelSnapshot.cs` | Restored to `87499a1…` content exactly |
| `src/Sibyla.Infrastructure/Persistence/P11aRegistryModelConfiguration.cs` | Restored to `87499a1…` content exactly |
| `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs` | Restored to `87499a1…` content exactly |

No other path is touched by the neutralization. The governed records — this file, the review
record, and `docs/PROJECT-STATE.md` — are preserved and updated, not reverted. Accepted Piece A
(`f6f297b…`) and the accepted P1-1a base are untouched by both the candidate and the neutralization.
No prototype write, no shared/live database action, and no history rewrite (no amend, reset,
rebase, revert, or force push) — the neutralization is a normal additive commit.

### What this step does not authorize

Any remediation code for B-R1. Starting Piece C, Piece D, or Scope 1. Reopening Piece A's Accept or
any O8/O9/O10 decision or baseline. Any content change beyond restoring the 6 paths and recording
the review/findings. Baselines 119 / 119 / 52 / 221 / 2,787, pin `b917685…`, and every O8/O9/O10
decision are unchanged; O5 remains the only other open item.

## 2026-08-06 Piece B implementation — evidence map (candidate `b8fa033…`, rejected — see review above)

This step performs **ordered instruction 3 of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-goahead.md`**,
under the approval recorded below (Miguel's verbatim "Aprovo o mapping de Piece B e ambas as
resoluções propostas"). Piece B is implemented **from zero** — there is no rejected candidate to
remediate — TDD first, against the approved 20-item checklist and mapping. It does **not** perform
ordered instruction 4 (the first independent adversarial review of this piece), which per the
go-ahead runs in a fresh, independent session after this candidate publishes.

### Reformulated preflight — re-run fresh at implementation start

Read-only against prototype clone `D:\fileStorage\repos\invoice-skill-build`, using only
`git status`, `git fetch`, `git cat-file`, `git ls-tree`, `git rev-parse`, and `git merge-base`:

1. Pin `b91768513fc638381fbde91f0b576b08220a98f6` resolved locally before the fetch and in the
   fetched remote after `git fetch --prune origin`. **Pass.**
2. `git merge-base --is-ancestor` confirms the pin remains an ancestor of live `origin/main`. **Pass.**
3. Local prototype `HEAD` still equals the pin (on branch `c8-entbnk-five-pair-merge`, pinned at
   that commit; clean working tree, `git diff --quiet` and `git diff --cached --quiet` both
   succeed). **Pass.**
4. All **49/49** roster blobs (the complete 49-entry roster with the O8 `entbnk.json` substitution)
   resolved at the pin with **0** hash mismatches. **Pass.**
5. The pinned direct `Editor/Data` surface contains exactly **48** blob (file) tree entries, all
   rostered, with **0** delta; the one `Editor/Data/Backups` tree entry present is a subdirectory,
   not a file, and is correctly excluded from the 48-file surface count. **Pass.**
6. (Non-stop finding.) Live tip remains `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`, with the same
   two already-recorded post-pin commits `1e841a4` (*Complete Stage 10 Round 8 reconciliation and
   mapping updates*) and `3dd4150` (*Apply Stage 10 Round 8 revenue review updates*) — no new
   divergence since the last preflight run. No post-pin content was read or adopted.

### Schema design — `RegistryFieldProvenance`, decided during TDD per Observation 2

`RegistryFieldProvenance` tracks provenance for the one governed nullable field the accepted
schema's historical-honesty relaxations created on both governed catalogs — `DOCEFL.ItemClass` and
`DOCFLG.ItemClass` — one provenance row per governed member (a `DOCEFL` rule row or a `DOCFLG`
snapshot row), keyed by a `TargetTable`/`TargetCode` pair. Orphan prevention (item 4) uses two real
foreign keys against two `STORED GENERATED` discriminator columns (`DOCEFLCode`,
`DOCFLGFlagInstanceID` — the exact shape amendment 3 itself named as an example), rather than a
single polymorphic column, because PostgreSQL foreign keys cannot reference one of two tables
conditionally; `MATCH SIMPLE` semantics mean only the generated column matching the row's own
`TargetTable` is ever non-null, so exactly one of the two FKs is ever live per row. Company
agreement (item 5) and absent/value agreement (item 7) are enforced by a shared trigger function
(`RequireProvenanceAgreesWithTargetFn`) attached both to `RegistryFieldProvenance` itself (BEFORE
INSERT OR UPDATE, validating a written provenance row against its target's *current* state) and,
for item 7's explicit "on target updates the trigger re-checks" requirement, to `DOCEFL` and
`DOCFLG` (AFTER UPDATE OF `"ItemClass"`, re-validating the *existing* provenance row against the
*new* value). Exact cardinality (item 6) uses a second shared trigger function
(`CheckRegistryFieldProvenanceCardinalityFn`) attached as `DEFERRABLE INITIALLY DEFERRED`
constraint triggers at three points — `DOCEFL` AFTER INSERT, `DOCFLG` AFTER INSERT, and
`RegistryFieldProvenance` AFTER DELETE OR UPDATE (rechecking the *old* target on delete/move,
never returning early) — so that a governed row and its provenance row, inserted in the same
transaction as two separate statements, are only ever checked together at commit. **This refines
the test-plan mapping's tentative sketch** ("the `DOCFLG` side is exercised through the ordinary
cardinality trigger on `RegistryFieldProvenance` itself") once TDD showed that sketch could not
actually catch a `DOCFLG` row inserted with zero `RegistryFieldProvenance` DML in the same
transaction: a trigger only fires on DML against the table it is attached to, so `DOCFLG` needed
its **own** dedicated deferred trigger, exactly mirroring item 6's own `DOCEFL` precedent — this is
the literal DDL Observation 2 committed to finalizing during TDD, not a scope change. The
`WaiveDOCFLG` closure (item 8/19, Observation 1) is a third, independent trigger
(`RejectStaleProvenanceOnDocflgResolutionFn`, BEFORE UPDATE ON `DOCFLG`) that fires on any
Open/InReview→terminal transition and blocks it while any `absent`-marked provenance row survives
for that `DOCFLG` row — `WaiveDOCFLG`'s only write to `DOCFLG` is the `UPDATE` this transition
performs, so the trigger intercepts it without any change to `WaiveDOCFLG` itself.

### Finalized DDL/catalog roster — items 10 and 12, measured against the migrated disposable catalog

**9 columns on `RegistryFieldProvenance`:** `Id` (`uuid`, PK), `TargetTable`
(`character varying(16)`, NOT NULL), `TargetCode` (`character varying(32)`, NOT NULL), `Company`
(`character varying(128)`, nullable), `DOCEFLCode` (`character varying(32)`, `GENERATED ALWAYS ...
STORED`, nullable), `DOCFLGFlagInstanceID` (`character varying(32)`, `GENERATED ALWAYS ... STORED`,
nullable), `Marker` (`character varying(16)`, NOT NULL), `ValueHash` (`character varying(64)`,
nullable), `RecordedAt` (`timestamp with time zone`, NOT NULL).

**10 constraint-class objects on `RegistryFieldProvenance`** (measured via `pg_constraint`):
`RegistryFieldProvenance_pkey` (PK on `Id`), `UQ_RegistryFieldProvenance_Target` (`UNIQUE
("TargetTable","TargetCode")`), `FK_RegistryFieldProvenance_DOCEFL` (`FOREIGN KEY ("DOCEFLCode")
REFERENCES "DOCEFL"("EFCode") ON DELETE RESTRICT`), `FK_RegistryFieldProvenance_DOCFLG` (`FOREIGN
KEY ("DOCFLGFlagInstanceID") REFERENCES "DOCFLG"("FlagInstanceID") ON DELETE RESTRICT`),
`RegistryFieldProvenance_Company_fkey` (`FOREIGN KEY ("Company") REFERENCES
"CompanyRegistry"("CompanyCode") ON DELETE RESTRICT`, Postgres-auto-named from the inline column
FK), `CK_RegistryFieldProvenance_CompanyScope` (`CHECK ((("TargetTable"='DOCEFL') =
("Company" IS NULL)))`), `CK_RegistryFieldProvenance_AbsentHash` (`CHECK ((("Marker"='absent') =
("ValueHash" IS NULL)))`), `RegistryFieldProvenance_TargetTable_check` (`CHECK ("TargetTable" IN
('DOCEFL','DOCFLG'))`, auto-named), `RegistryFieldProvenance_Marker_check` (`CHECK ("Marker" IN
('extracted','authored','absent'))`, auto-named), and
`RequireExactlyOneProvenance_RegistryFieldProvenance` (the deferred constraint trigger itself,
which registers as a `pg_constraint` row of type `t`).

**2 indexes on `RegistryFieldProvenance`** (both constraint-backed, no separately-declared
`CREATE INDEX`): `RegistryFieldProvenance_pkey`, `UQ_RegistryFieldProvenance_Target`.

**7 new triggers total**, by table: `DOCEFL` gets `RequireExactlyOneProvenance_DOCEFL` (deferred
constraint trigger, item 6) and `RequireProvenanceAgreesWithTarget_DOCEFL` (item 7 re-check);
`DOCFLG` gets `RequireExactlyOneProvenance_DOCFLG` (deferred constraint trigger, item 6),
`RequireProvenanceAgreesWithTarget_DOCFLG` (item 7 re-check), and
`RejectStaleProvenanceOnDocflgResolution` (item 8/19 closure); `RegistryFieldProvenance` gets
`RequireProvenanceAgreesWithTarget_RegistryFieldProvenance` (items 5/7, immediate) and
`RequireExactlyOneProvenance_RegistryFieldProvenance` (item 6, deferred). No trigger is attached to
any other accepted table.

**3 new trigger functions:** `RequireProvenanceAgreesWithTargetFn`,
`CheckRegistryFieldProvenanceCardinalityFn`, `RejectStaleProvenanceOnDocflgResolutionFn`. No other
function is added, and `WaiveDOCFLG` and `RejectTerminalDOCFLGMutationFn` are not redefined —
proven directly (item below) by comparing `pg_get_functiondef` before and after Piece B's `Up`.

No role, ACL, `SECURITY DEFINER` function, or governed command is added. No accepted `ENTMST`,
`DOCEFL`, `DOCFLG`, or `ImportEvidenceRow` column or constraint is altered or dropped.

### Item-by-item checklist evidence

1. **Amendment-4 reformulated preflight checks 1–5, check 6 non-adoption rule** — Pass, re-proven
   fresh above; no post-pin content read or adopted.
2. **Exact base-to-candidate surface and Piece B strict scope** — `git diff --name-status` against
   the pushed approval tip lists exactly 6 paths: 3 new (`20260806190000_P11bPieceBRegistryFieldProvenance.cs`,
   `P11bPieceBSchemaSql.cs`, `tests/Sibyla.Tests/Persistence/P11bPieceBContractTests.cs`) and 3
   modified (`P11aRegistryModelConfiguration.cs`, `SibylaDbContextModelSnapshot.cs`,
   `P11aDisposableDatabaseTests.cs` — the last gaining only new `Piece_b_*` test methods and two
   pre-existing fixture inserts extended with matching `RegistryFieldProvenance` rows, described
   under item 3), plus this status file and `PROJECT-STATE.md`. No Piece C/D, role, ACL,
   `SECURITY DEFINER`, governed-command, or importer path. `P11bPieceBContractTests.Piece_b_sql_is_
   schema_only_and_exactly_scoped` passes, asserting no `CREATE ROLE`/`SECURITY DEFINER`/
   `GRANT`/`REVOKE`, no `ALTER TABLE` on any of `ENTMST`/`DOCEFL`/`DOCFLG`/`ImportEvidenceRow`, no
   redefinition of `WaiveDOCFLG` or `RejectTerminalDOCFLGMutationFn`, and an exact enumerated
   trigger allow-list (7 triggers: the 5 attached to `DOCEFL`/`DOCFLG` named above plus the 2
   attached only to `RegistryFieldProvenance`). Both accepted P1-1a and Piece A migration files
   (`20260805180000_P11aFdrSchema.cs`, `P11aSchemaSql.cs`, `20260806180000_P11bPieceASchemaCompleteness.cs`,
   `P11bPieceASchemaSql.cs`) are byte-identical to pre-implementation `HEAD` — verified directly by
   `git hash-object` matching the blob IDs `git ls-tree HEAD` records for those four paths.
3. **Minimal-surface discipline** — Pass, proven by the same contract test as item 2. The two
   pre-existing `P11aDisposableDatabaseTests.cs` fixtures that insert native `DOCEFL` rows without
   rollback (`Database_backed_registry_validation_is_clean_and_exercises_query_sensitive_semantics`,
   which seeds 52 rows via `generate_series`, and `Migration_applies_and_core_database_postconditions_
   hold`, which seeds `EF0000000`/`EF0000053`) now also insert matching `authored` provenance rows in
   the same committed batch — a necessary, additive extension of existing fixture data caused
   directly by Piece B's own new invariant applying universally, not a change to either test's
   original assertions, both of which still pass unchanged. No other existing test needed
   modification: every other `DOCEFL`/`DOCFLG`-inserting test in the suite runs inside a transaction
   that ends in `RollbackAsync()`, so `DEFERRABLE INITIALLY DEFERRED` triggers — which fire only at
   commit — never observe them.
4. **Every provenance row has an FK to its target row; orphan provenance is impossible** — Pass.
   `Piece_b_provenance_row_referencing_a_nonexistent_target_is_rejected` proves both the `DOCEFL`
   and `DOCFLG` orphan cases raise `foreign_key_violation`, via the real `FK_RegistryFieldProvenance_
   DOCEFL`/`FK_RegistryFieldProvenance_DOCFLG` constraints on the generated discriminator columns.
   Every other disposable test's setup is itself a positive control (a provenance row against a real
   target, exercised before its specific scenario).
5. **Company agreement is schema-enforced** — Pass.
   `Piece_b_wrong_company_provenance_row_is_rejected` proves a `DOCFLG`-targeted provenance row
   asserting the wrong company raises `foreign_key_violation` (ERRCODE `23503`, matching the A-R3
   trigger-based convention) inside a rolled-back transaction, with a same-company positive control
   that succeeds. Enforced by `RequireProvenanceAgreesWithTargetFn`'s immediate `BEFORE INSERT OR
   UPDATE` check against the live `DOCFLG."Company"` value (`DOCEFL` provenance is company-agnostic
   by construction — `CK_RegistryFieldProvenance_CompanyScope` requires `Company IS NULL` there).
6. **Exact cardinality on every path (INSERT/UPDATE/DELETE/move), DOCEFL gets its own trigger** —
   Pass, on all four paths.
   `Piece_b_docefl_insertion_without_a_matching_provenance_row_is_rejected` proves both `DOCEFL` and
   `DOCFLG` insertion without a matching provenance row fails at `COMMIT` (`check_violation`, via the
   two dedicated deferred constraint triggers), with a positive control inserting the governed row
   and its provenance together in one transaction succeeding.
   `Piece_b_deleting_the_only_provenance_row_for_a_target_is_rejected` proves `DELETE` (item 17) —
   the trigger does not return early on delete — with a replacement-row positive control.
   `Piece_b_moving_a_provenance_row_to_a_new_target_rechecks_the_old_target` proves move (item 18) —
   the deferred recheck on the **old** target rejects a move that would leave it empty even though
   the new target's own cardinality would be satisfied, with a replacement-row positive control.
7. **`absent` agrees with the value, re-checked on target update** — Pass.
   `Piece_b_absent_and_hash_agree_with_the_governed_value` proves, inside one rolled-back
   transaction: `absent` against a non-null value rejected; non-`absent` against a null value
   rejected; a mismatched hash rejected; an unknown marker literal rejected (folds in item 11's
   fourth-literal proof); and — the re-check half — updating a target's `ItemClass` after a
   consistent provenance row already exists is rejected (`check_violation`) because the existing
   `authored` marker's hash would no longer match the new value, with the target's original value
   and the provenance row both confirmed unchanged by the failed attempt.
8. **The accepted terminal command and the invariant agree on every path — `WaiveDOCFLG`** — Pass,
   proven by item 19 below and by the design note above (closure by construction, no `WaiveDOCFLG`
   change).
9. **R7 direct assertion — accepted `ImportEvidenceRow` uniqueness untouched** — Pass.
   `Piece_b_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_b_up` captures
   all four accepted `UNIQUE` constraint definitions (confirmed count = 4) and every index
   definition immediately before Piece B's `Up`, runs `Up`, and asserts both sets are identical.
10. **Generated columns exactly as generated, store type included** — Pass. `DOCEFLCode` and
    `DOCFLGFlagInstanceID` are the exact two generated columns named as an example in amendment 3.
    Full A-R2 three-test shape: `P11bPieceBContractTests.Piece_b_nullable_and_generated_columns_are_
    modelled_truthfully` asserts `GetColumnType()`, `GetComputedColumnSql()`, and `GetIsStored()` for
    both plus the seven non-generated columns;
    `Piece_b_model_snapshot_matches_the_runtime_model_for_added_columns` compares
    `SibylaDbContextModelSnapshot` against the runtime model for all nine added columns;
    `Piece_b_ef_store_types_match_the_disposable_catalog_for_every_touched_column` compares the
    runtime model against `information_schema.columns` in the migrated disposable catalog for all
    nine, store type and generation flag both. The exact roster is the one recorded above.
11. **Closed vocabularies close twice, where they exist on this surface** — Resolved as the mapping
    proposed: the marker vocabulary closes at the database `CHECK`
    (`RegistryFieldProvenance_Marker_check`) alone, proven by
    `Piece_b_sql_is_schema_only_and_exactly_scoped`'s SQL-text assertion and by the fourth-literal
    rejection folded into item 7's disposable test; `RegistryValidationService.cs` and
    `PostgresRegistryValidationSnapshotSource.cs` were re-confirmed to have zero references to any
    provenance surface, so no validator test is claimed — stated explicitly, not silently assumed.
12. **Exact `Down`; Up/Down/Up catalog stability** — Pass.
    `Piece_b_down_is_exact_and_up_down_up_is_catalog_stable` migrates to the accepted-plus-Piece-A
    tip (`20260806180000_P11bPieceASchemaCompleteness`), snapshots columns/constraints/indexes on
    `RegistryFieldProvenance` and the 7 named triggers on `DOCEFL`/`DOCFLG`/`RegistryFieldProvenance`
    via a new `PieceBCatalogSnapshot` helper, runs `Up`, snapshots again, `Down`, asserts the
    additive base equals post-`Down` exactly, `Up` again, asserts first `Up` equals second `Up`.
    `Down` in `P11bPieceBSchemaSql.cs` is the exact statement-for-statement mirror of `Up` in reverse
    order; it performs no `DROP OWNED` and changes no ownership of any object it did not create.
13. **A missing provenance row is rejected** — Pass, proven by item 6's tests (both the `DOCEFL` and
    `DOCFLG` insertion halves, the latter exercised through `DOCFLG`'s own dedicated deferred
    trigger rather than only through `RegistryFieldProvenance`'s, per the design-note refinement
    above).
14. **An orphan provenance row is rejected** — Pass, proven by item 4's test.
15. **A wrong-company provenance row is rejected, with a same-company positive control** — Pass,
    proven by item 5's test.
16. **A value/provenance-contradiction row is rejected** — Pass, proven by item 7's test.
17. **A delete that would break cardinality is rejected** — Pass, proven by item 6's delete test.
18. **A move that leaves the old target inconsistent is rejected** — Pass, proven by item 6's move
    test.
19. **`WaiveDOCFLG` cannot leave stale `absent` provenance with a NULL hash** — Pass, proven on the
    real accepted function's path, not by inspection.
    `Piece_b_waivedocflg_cannot_leave_stale_absent_provenance_with_a_null_hash` calls the real,
    unmodified `WaiveDOCFLG('FLPB0040', ...)` against a native `RuntimePrincipal`/`RuntimePrincipalCompany`/
    `RuntimePrincipalAuthority`-authenticated session and an imported `DOCFLG` row whose sole
    governed field (`ItemClass`) is honestly `NULL` with `absent` provenance, and asserts the call
    raises `check_violation` with `DOCFLG."Status"`/`"ResolutionEvidence"` unchanged; a companion
    positive control against a second imported row with consistent `extracted` provenance calls
    `WaiveDOCFLG` and asserts it succeeds, `"Status"='Waived'`, and `"ResolutionEvidence"` is
    populated. `Piece_b_waivedocflg_and_reject_terminal_mutation_function_bodies_are_unchanged`
    additionally proves `pg_get_functiondef` for both `WaiveDOCFLG` and
    `RejectTerminalDOCFLGMutationFn` is byte-identical immediately before and after Piece B's `Up`.
20. **Claims equal assertions** — This section states exactly the tests that exist and exactly the
    surface they assert; the DDL roster above is measured from the live migrated catalog, not
    projected. No suite-count projection was made in advance of implementation.

### Measured verification (this implementation)

| Verification | Measured result |
|---|---:|
| `dotnet build GOTT.Sibyla.slnx --no-incremental` | 0 warnings, 0 errors |
| Focused (new Piece B contract tests) | **3** passed, 0 failed, 0 skipped |
| Ordinary `dotnet test --no-build` | **640** passed, 0 failed, 0 skipped (637 + 3 new) |
| Disposable PostgreSQL 17 suite (`scripts\run-p11a-disposable-tests.ps1`) | **27** passed, 0 failed, 0 skipped (16 + 11 new) |
| `git diff --check` | clean |
| Accepted migration blob IDs (`20260805180000_P11aFdrSchema.cs`, `P11aSchemaSql.cs`,
  `20260806180000_P11bPieceASchemaCompleteness.cs`, `P11bPieceASchemaSql.cs`) | unchanged — `git hash-object` matches `git ls-tree HEAD` exactly for all four |
| Diff-restricted secret/role/`SECURITY DEFINER`/`DROP OWNED` scan | 0 matches |
| Residual `sibyla-p11*` containers | **0** |

No suite-count projection was made in advance; these are measured totals only, per proof-pattern
rule 1.

### What this step did and did not do

Implemented `RegistryFieldProvenance` from zero — no rejected candidate exists to remediate,
consistent with the mapping's own "no candidate" framing. Added exactly 6 code/test paths (3 new,
3 modified) as enumerated in item 2. No accepted P1-1a or Piece A object was altered, dropped,
re-owned, or replaced; both migrations remain byte-identical. No role, ACL, `SECURITY DEFINER`
function, or governed command was added. No prototype write or post-pin read. No shared/live
database, service, deployment, or production action; every disposable container used in this step
was removed, with 0 residual `sibyla-p11*` containers confirmed after the final run. Ordered
instruction 4 — the first full independent adversarial review of this piece — has not run; per the
go-ahead it must run in a fresh, independent session.

### Verification of this implementation stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **8** — 6 code/test paths (item 2) plus `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| `git diff --check` | clean |
| Prototype repository operations | read-only preflight only — **0** writes |
| Disposable database and container operations | multiple disposable PostgreSQL 17 containers created and removed during TDD; **0** residual after the final run |
| Shared or live database operations | **0** |

## 2026-08-06 Piece B test-plan gate — Miguel's approval recorded

This step records the gate decision required by the go-ahead's ordered instruction 2 (test-plan
gate): Miguel's explicit approval of the 20-item checklist→test mapping recorded immediately below
in this file (section "2026-08-06 Piece B test-plan gate — checklist→test mapping and `WaiveDOCFLG`
closure analysis") and of both reported observations. Miguel's approval, verbatim: **"Aprovo o
mapping de Piece B e ambas as resoluções propostas."** ("I approve the Piece B mapping and both
proposed resolutions.")

### Decision: Approved in full — the mapping and both proposed resolutions

The 20-item checklist→test mapping recorded below is **approved as the binding Piece B test
plan**, exactly as submitted, with no correction. Both reported observations are decided in the
plan's own favor, as proposed:

1. **Observation 1 — the `WaiveDOCFLG` closure mechanism.** Miguel's approval **authorizes the
   proposed new, additive `BEFORE UPDATE` trigger and trigger function on the accepted `"DOCFLG"`
   table** (created by Piece B's `Up`, alongside `RegistryFieldProvenance`, its own triggers, and
   the item-6 `DOCEFL` insertion trigger) as the closure-by-construction mechanism for checklist
   item 8/19. This is the intended reading of the go-ahead's scope note "constraints and triggers
   on Piece B's own objects": a new trigger Piece B's own migration additively creates and attaches
   to `DOCFLG`, exactly as item 6 already required for `DOCEFL`. The approval is explicit that this
   mechanism must leave **`WaiveDOCFLG`'s accepted function definition, and the existing accepted
   `RejectTerminalDOCFLGMutation` trigger/function, byte-identical** — no line of either is added,
   removed, or reordered; the new trigger fires automatically on `WaiveDOCFLG`'s existing `UPDATE`
   of `"DOCFLG"` without any change to `WaiveDOCFLG`'s SQL text, `pg_get_functiondef` output, or
   blob ID. Piece B's implementation must prove this identity directly (checklist item 2's SQL-text
   scope test) and prove the closure fires on `WaiveDOCFLG`'s real path (item 19's disposable test),
   not merely by inspection.
2. **Observation 2 — items 10/12 as shape, not enumeration.** Miguel's approval **confirms that
   committing items 10 and 12 to the required test shape and location now — with the literal
   column, constraint, and index roster necessarily fixed only once `RegistryFieldProvenance`'s own
   `Up` is authored during TDD — is an acceptable reading of the test-plan gate** for a piece with
   no existing rejected candidate to enumerate against, on the same basis Piece A's own test-plan
   gate accepted shape-level commitments it had not yet measured. The exact roster is **not**
   invented now; it is fixed during implementation (ordered instruction 3) and recorded item by
   item, by exact name and definition, in the implementation's own evidence map against items 10
   and 12 — measured, not projected, per proof-pattern rule 1.

No other content change is authorized beyond what the mapping and these two observations already
state; an apparent need for one remains a stop-and-report.

### What is now authorized

Ordered instruction 3 of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-goahead.md`: **implement Piece B,
TDD first**, from this pushed approval tip — disposable suite green including every rejection proof
in the checklist (items 13–19); ordinary and focused suites green; build 0 warnings; 0 residual
containers; status evidence map keyed to the checklist item by item, measured counts only; commit
and push. Ordered instruction 4 (the first full independent adversarial review of this piece) is
**not** authorized by this step; it runs in a fresh, independent session after implementation
publishes.

### What this approval does not authorize

Piece C, Piece D, or Scope 1. Roles, `SECURITY DEFINER` functions, or governed commands (Piece C's
surface). Any content change to the approved mapping beyond what it and the two observations
already state. Any prototype write or post-pin read. Reopening any closed decision or changing any
baseline. Resurrecting any part of the three named monolithic rejects or rejected Piece A candidate
`6f86023d…`. Any shared/live database write. Production go-live (O5 remains the only other open
item). History rewrite in either repository. Starting or resuming O5-prep, which remains deferred
by Miguel's decision in the go-ahead.

Baselines 119 / 119 / 52 / 221 / 2,787, the two verbatim `Routine` rows, pin `b917685…`, and every
O8/O9/O10 decision are unchanged. This records step performs no implementation, migration, model,
constraint, trigger, test, fixture, prototype, database, container, service, deployment, or
live-data work; Piece B implementation has not started as of this commit.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `0465f0501855870f315b3187a772bf4777cf3b22`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. The last independently reproduced
figures remain those of the Piece A attempt #2 Accept record below.

## 2026-08-06 Piece B test-plan gate — checklist→test mapping and `WaiveDOCFLG` closure analysis, awaiting Miguel's approval

This step performs **ordered instruction 2 of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-goahead.md`
only**: it records the Piece B checklist→test mapping required by the test-plan gate, and resolves
the `WaiveDOCFLG` closure-by-construction scope note as that instruction requires. It does **not**
perform ordered instruction 3 (implementation) or ordered instruction 4 (the first independent
adversarial review of this piece), and it does not re-run the amendment-4 preflight, which belongs
to instruction 3. **Implementation remains unauthorized until Miguel explicitly approves this
mapping.** The instruction to record it is not approval of it.

Nothing here changes a decision or a baseline. The five expected completeness baselines remain
**119 / 119 / 52 / 221 / 2,787**, the two pinned `Routine` rows still import verbatim, and the
immutable source pin remains `b91768513fc638381fbde91f0b576b08220a98f6`. The monolithic rejects
`b324a3e…`, `57f0f023…`, and `7ea6c0f…` remain neutralized evidence only.

**Read-only inspection performed for this mapping:** `RegistryFieldProvenance` does not exist
anywhere in the repository outside documentation — it is absent from every migration
(`P11aSchemaSql.cs`, `P11bPieceASchemaSql.cs`) and from every test file. `WaiveDOCFLG`'s accepted
definition (`P11aSchemaSql.cs` lines 1495–1511) was read in full: its body touches only `"DOCFLG"`
(one `UPDATE` setting `"Status"`, `"ResolutionEvidence"`, `"ResolvedBy"`, `"ResolvedAt"`) and
`"P11aCommandAudit"` (one `INSERT`); it performs no read or write of any provenance surface, because
none yet exists. `RegistryValidationService.cs` and `PostgresRegistryValidationSnapshotSource.cs`
were searched for `Provenance` (case-insensitive): **zero matches in either file.** Unlike Piece A's
attempt-#2 mapping, there is no existing rejected candidate to diff against — Piece B starts from
zero, so this mapping is a genuine test plan (proposed method names, surfaces, and required
behaviour) rather than a diff against written code. Exact column/constraint enumeration for items
that depend on `RegistryFieldProvenance`'s own DDL (10, 12) is necessarily finalized when `Up` is
authored during TDD and reported in the implementation's own evidence map — this mapping commits to
the required shape and test location now, which is what the checklist items themselves specify (at
the requirement level, not the DDL level), and is reported as observation 2 below rather than
assumed silently.

### The checklist being mapped

Per the go-ahead, **the Piece B checklist is exactly its own 20 numbered items** — preflight and
surface (1–3), R4 closed by construction (4–8), standing guarantees carried into this piece (9–12),
required schema-level rejection proofs (13–19), and proof honesty (20) — and to nothing else. No
other item exists, and no other content change is authorized; an apparent need for one is a
stop-and-report.

### Legend — test surfaces and status labels

| Label | Meaning |
|---|---|
| **Contract (ordinary)** | Proposed new file `tests/Sibyla.Tests/Persistence/P11bPieceBContractTests.cs` — SQL-text and EF-model assertions, no infrastructure; runs in the ordinary suite, following the shape of `P11bPieceAContractTests.cs` |
| **Disposable** | Proposed additions to the existing `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs`, class-level `[Trait("Category","P11aDatabase")]` — the same shared disposable class Piece A's own new disposable tests were added to rather than a new per-piece file; excluded from ordinary `dotnet test` and run only by `scripts\run-p11a-disposable-tests.ps1` against a disposable PostgreSQL 17 container. Method names are prefixed `Piece_b_*` to mirror the existing `Piece_a_*` convention |
| **Verification command** | Non-test evidence (read-only Git or preflight commands). Recorded as a command because no test can assert it; never described as a test |
| **New** | Every item here, because no Piece B code, migration, or test exists at any point in history to restore or regress from — there is no candidate to remediate |
| **Documentation obligation** | A proof-honesty requirement satisfied by the status record's own wording, not by a test |

Every surface below is **New**; the "Existing regression" and "Strengthened" labels used by the
Piece A mapping do not apply here because Piece B has no prior candidate.

### 1 · Amendment-4 reformulated preflight checks 1–5, check 6 non-adoption rule

**Verification command; not a test.** Re-run at Piece B implementation start (ordered instruction
3), the identical six-check procedure used by Piece A attempt #2: read-only `git fetch`,
`git cat-file`, `git ls-tree`, `git rev-parse`, `git merge-base`, `git log` only, against pin
`b917685…`. Checks 1–5 (pin resolves and is an ancestor of live `main`; local prototype `HEAD`
equals the pin; 49/49 roster blobs; 48/48 direct `Editor/Data` surface) are a hard stop on failure.
Check 6 logs the live tip and every post-pin commit by hash and subject only; no post-pin content is
read or adopted.

### 2 · Exact base-to-candidate surface and Piece B strict scope

**Verification command plus New Contract test.**
- Command: `git diff --name-status <Piece B base>..<Piece B implementation commit>`, restricted to
  `src/` and `tests/`, must list only the new Piece B migration pair, the new/expanded test files
  named in this mapping, and no Piece C/D role, ACL, `SECURITY DEFINER` function, governed command,
  importer, or live-action path.
- New: `P11bPieceBContractTests.Piece_b_sql_is_schema_only_and_exactly_scoped` asserts, over the
  migration's `Up`/`Down` SQL text: no `CREATE ROLE`, no `SECURITY DEFINER`, no `GRANT`/`REVOKE`
  beyond ordinary DDL on Piece B's own new table; no `ALTER`/`DROP` of any existing `ENTMST`,
  `DOCEFL`, `DOCFLG`, or `ImportEvidenceRow` column or constraint that Piece A did not already
  alter; no change to `WaiveDOCFLG`'s or `RejectTerminalDOCFLGMutationFn`'s function bodies (their
  `pg_get_functiondef` text is unchanged before/after, asserted as a command in item 8); any new
  trigger the migration adds is attached only to `RegistryFieldProvenance` and — where item 6 or 8
  names that exact change — to `DOCEFL` or `DOCFLG`, and to no other accepted table.

### 3 · Minimal-surface discipline

**Same New Contract test as item 2** — its negative assertions (no accepted object altered, dropped,
re-owned, or replaced beyond what items 6 and 8 name) are the minimal-surface proof. No separate
test is proposed; a distinct assertion here would duplicate item 2's without adding coverage.

### 4 · Every provenance row has an FK to its target row; orphan provenance is impossible

**Proven by item 14's rejection test** (an orphan provenance row is rejected) plus the positive
control implicit in every other disposable test in this mapping, each of which first inserts a
provenance row against a real target row and only then exercises its specific scenario. The exact
FK/trigger mechanism (a foreign key on the target reference, a trigger, or both) is an
implementation decision made during TDD; this item and its proof test assert the **behaviour**
required — an orphan cannot be inserted — regardless of the mechanism chosen.

### 5 · Company agreement between every provenance row and its target is schema-enforced

**Proven by item 15's rejection test** (a wrong-company provenance row is rejected, with a
same-company positive control). As with item 4, the mechanism (a composite FK carrying `Company`,
or a trigger comparing the provenance row's company to the target's) is decided during TDD; the
test asserts the required behaviour.

### 6 · Exact cardinality: a governed snapshot member has exactly one provenance row, on every path

**Proven by three New Disposable tests, one per named path:**
- `Piece_b_docefl_insertion_without_a_matching_provenance_row_is_rejected` — the "DOCEFL insertion
  gets its own exact-one cardinality trigger" requirement named by this item: inserting a `DOCEFL`
  row inside a transaction that does not also insert its required provenance row(s) is rejected
  (deferred to end-of-statement or end-of-transaction as the implementation requires, but rejected
  before commit either way).
- `Piece_b_deleting_the_only_provenance_row_for_a_target_is_rejected` — also proves item 17 (a
  delete that would break cardinality is rejected): deleting a target's sole provenance row, with no
  replacement inserted in the same transaction, is rejected; the trigger does not return early on
  `DELETE`.
- `Piece_b_moving_a_provenance_row_to_a_new_target_rechecks_the_old_target` — also proves item 18 (a
  move that leaves the old target inconsistent is rejected): updating a provenance row's target
  reference to point at a different governed member, when doing so would leave the **old** target
  with zero provenance rows, is rejected; a companion positive case where the old target's
  cardinality is preserved (a replacement row exists) succeeds.

Together with item 13's proof (below) these four tests exercise `INSERT`, `UPDATE`, `DELETE`, and
move, exactly as this item requires.

### 7 · `absent` agrees with the value

**Proven by item 16's rejection test** (a value/provenance-contradiction row is rejected in both
directions) plus re-check-on-target-update coverage folded into the same test: after a governed
value changes from `NULL` to non-`NULL` (or vice versa) on the target row, a provenance row whose
marker/hash no longer agrees with the new value is rejected — not merely that two rows exist, but
that the marker and hash agree with the **current** governed value.

### 8 · The accepted terminal command and the invariant agree on every path — `WaiveDOCFLG`

**Proven by item 19's disposable test, on `WaiveDOCFLG`'s real path.** The `WaiveDOCFLG` closure
analysis this item requires is recorded in its own section below, immediately after item 20.

### 9 · R7 direct assertion — accepted `ImportEvidenceRow` uniqueness untouched by Piece B

**New Disposable test:**
`Piece_b_accepted_import_evidence_uniqueness_and_indexes_are_identical_after_piece_b_up` — mirrors
the A-R4 shape Piece A already proved: captures all four accepted `ImportEvidenceRow` `UNIQUE`
constraint definitions by exact `pg_get_constraintdef` text plus every `pg_indexes` definition on
that table immediately before Piece B's `Up`, runs `Up`, and asserts the captured sets are
identical. Per this item's own text, the same comparison is **re-verified again in Piece D** over
the full combined A+B+C sequence; that re-verification is Piece D's own gate, not this one's.

### 10 · Generated columns exactly as generated, store type included, for every column Piece B adds

**Shape committed now; exact column list finalized when `RegistryFieldProvenance`'s `Up` is
authored (observation 2 below).** If `Up` includes any generated column (the go-ahead names
`DOCEFLCode` / `DOCFLGFlagInstanceID`-style discriminator targets "if used, and any other"), it
gets the full three-test A-R2 shape Piece A already established:
- New Contract test asserting `GetColumnType()` (and, for any generated column, `GetComputedColumnSql()`
  / `GetIsStored()`) for every column Piece B's `Up` adds.
- New Contract test comparing `SibylaDbContextModelSnapshot.Model` against the runtime model for the
  same columns.
- New Disposable test comparing the runtime model against `information_schema.columns` in the
  migrated disposable catalog for the same columns (store type and generation flag both).

If `RegistryFieldProvenance`'s authored `Up` contains **no** generated column, this item is
satisfied vacuously and the status record states that explicitly rather than claiming a test that
does not exist — per proof-pattern rule 1.

### 11 · Closed vocabularies close twice, where they exist on this surface

**Resolved by inspection, not left open.** `RegistryFieldProvenance`'s marker vocabulary
(`extracted | authored | absent`) is a closed vocabulary on Piece B's own surface. `RegistryValidationService.cs`
and `PostgresRegistryValidationSnapshotSource.cs` were searched for `Provenance` (case-insensitive):
**zero matches in either file.** The validator does not observe `RegistryFieldProvenance` rows in
Piece B's scope — the go-ahead's scope note lists no validator wiring among Piece B's checklist
items, and none is proposed here. Per this item's own fallback clause, **closure for the marker
vocabulary is at the database `CHECK` alone**, proven by:
- New Contract test: `Up` contains a `CHECK` restricting the marker column to exactly
  `'extracted','authored','absent'`.
- New Disposable test (folded into the item-16 test): a fourth literal (e.g. `'Invented'`) is
  rejected with `check_violation`.

No validator test is proposed for this item, and this record claims none — stated explicitly per
proof-pattern rule 1, not silently assumed.

### 12 · Exact `Down`; Up/Down/Up catalog stability

**Shape committed now; exact surface finalized with item 10 (observation 2 below).** New Disposable
test `Piece_b_down_is_exact_and_up_down_up_is_catalog_stable` — migrate to the accepted-plus-Piece-A
tip, snapshot, `Up`, snapshot, `Down`, assert the additive base equals post-`Down`, `Up` again,
assert first `Up` equals second `Up`. The snapshot helper widens the existing `PieceACatalogSnapshot`
shape (or a Piece-B-scoped equivalent using the same column-store-type/index surface Piece A's item
20 already established) to cover `RegistryFieldProvenance` and any table item 6/8 adds a trigger to
(`DOCEFL`, `DOCFLG`). `Down` performs no `DROP OWNED` and changes no ownership of any object it did
not create — asserted by the same test's negative half.

### 13 · A missing provenance row is rejected

**New Disposable test:** `Piece_b_docefl_insertion_without_a_matching_provenance_row_is_rejected`
(named and described under item 6 above, which this item's positive statement mirrors). A companion
assertion in the same or a sibling test proves the `DOCFLG` insertion side of the same requirement,
if the authored schema requires provenance at `DOCFLG` insertion time as well as at `DOCEFL`
insertion time — the go-ahead names only the `DOCEFL` insertion trigger explicitly; the `DOCFLG` side
is exercised through the ordinary cardinality trigger on `RegistryFieldProvenance` itself (insert a
`DOCFLG` row, do not insert its provenance row, and confirm the transaction is rejected at commit).

### 14 · An orphan provenance row is rejected

**New Disposable test:** `Piece_b_provenance_row_referencing_a_nonexistent_target_is_rejected` —
inserting a provenance row whose target reference does not match any existing `DOCEFL`/`DOCFLG` row
raises `foreign_key_violation` (or the schema's equivalent fail-closed error).

### 15 · A wrong-company provenance row is rejected, with a same-company positive control

**New Disposable test:** `Piece_b_wrong_company_provenance_row_is_rejected` — mirrors the A-R3 shape
Piece A already proved: creates companies A and B, attempts to insert (or move, per item 18) a
provenance row asserting company B against a target row that belongs to company A, and proves inside
a rolled-back transaction that the wrong-company row is rejected while the identical row asserting
company A's own code succeeds as the positive control. This is also the piece's proof-pattern-rule-2
cross-company negative for the only company-scoped object Piece B touches.

### 16 · A value/provenance-contradiction row is rejected

**New Disposable test:** `Piece_b_absent_and_hash_agree_with_the_governed_value` — proves both
directions inside rolled-back transactions: (a) a provenance row marked `absent` whose target's
governed value is genuinely non-`NULL` is rejected; (b) a provenance row marked `extracted` or
`authored` with a `NULL` hash is rejected. Also carries item 11's fourth-literal marker-vocabulary
rejection (a `CHECK`-level negative on the same table) as a fourth assertion in the same test class,
or as a sibling method if a single method grows unwieldy — the exact split is an implementation
detail; the assertions themselves are committed here.

### 17 · A delete that would break cardinality is rejected

**New Disposable test:** `Piece_b_deleting_the_only_provenance_row_for_a_target_is_rejected` (named
and described under item 6 above).

### 18 · A move that leaves the old target inconsistent is rejected

**New Disposable test:** `Piece_b_moving_a_provenance_row_to_a_new_target_rechecks_the_old_target`
(named and described under item 6 above).

### 19 · `WaiveDOCFLG` cannot leave stale `absent` provenance with a NULL hash

**New Disposable test:** `Piece_b_waivedocflg_cannot_leave_stale_absent_provenance_with_a_null_hash`
— calls the real, unmodified `WaiveDOCFLG(p_flag_instance_id, p_evidence)` SQL function (not by
inspection) against a native `DOCFLG` row whose provenance includes a stale `absent` marker with a
`NULL` hash for a field the waiver would leave behind, and asserts the call raises an exception
propagated from the new schema-level closure (item 8), with `DOCFLG."Status"` and
`"ResolutionEvidence"` unchanged by the failed attempt. A companion positive control — identical
except the provenance is consistent — calls `WaiveDOCFLG` and asserts it succeeds, `"Status"='Waived'`,
and `"ResolutionEvidence"` is populated, proving the closure blocks only the genuinely stale case and
does not make the accepted command unusable.

### 20 · Claims equal assertions

**Documentation obligation, not a test.** The Piece B implementation's own status record will state
exactly the surface its tests assert — the exact column/constraint/trigger list authored during TDD,
no projected suite counts, no overstated catalog surface — mirroring the two honest-scope statements
Piece A's mapping used as its model (item 11's explicit "no validator test is proposed" above is the
first instance of that discipline in this mapping).

### `WaiveDOCFLG` closure-by-construction analysis — required by the go-ahead's scope note

**Question:** can checklist item 8 (and its proof, item 19) be satisfied without altering the
accepted `WaiveDOCFLG` function definition?

**`WaiveDOCFLG`'s accepted body, read in full** (`P11aSchemaSql.cs` lines 1495–1511): it validates
its own actor/authority context, requires non-blank evidence text, sets a session GUC, then issues
exactly one `UPDATE "DOCFLG" SET "Status"='Waived',"ResolutionEvidence"=p_evidence, "ResolvedBy"=…,
"ResolvedAt"=… WHERE "FlagInstanceID"=… AND "Company"=… AND "Status" IN ('Open','InReview')`, checks
`FOUND`, and inserts one audit row. It never reads or writes any provenance surface — because none
exists yet, and because nothing in its accepted text references one.

**Finding: yes, item 8/19 can be closed without altering `WaiveDOCFLG`'s accepted definition.**
PostgreSQL fires `BEFORE`/`AFTER` triggers on the table a statement actually modifies. `WaiveDOCFLG`'s
only write to `"DOCFLG"` is the `UPDATE` quoted above; a new trigger attached to `"DOCFLG"` (in
addition to the existing, unmodified `RejectTerminalDOCFLGMutation` trigger) fires automatically on
that exact `UPDATE`, regardless of which caller issued it — including `WaiveDOCFLG` itself, with no
change to its SQL text, its `pg_get_functiondef` output, or its blob ID. The new trigger's function
would query `RegistryFieldProvenance` for the target `DOCFLG` row and raise an exception (fail
closed) when the update would leave a stale `absent` marker with a `NULL` hash for a field the
waiver resolves. This is closure **by construction**: the invariant holds on every caller's path
through `DOCFLG`, not only a specifically-blessed one, because it is enforced at the row level by
the database itself.

**A constraint or trigger confined only to `RegistryFieldProvenance` cannot do this.** `WaiveDOCFLG`'s
transaction performs no `INSERT`/`UPDATE`/`DELETE` on `RegistryFieldProvenance` — it never touches
that table — so no `CHECK`, `FOREIGN KEY`, or trigger defined purely on `RegistryFieldProvenance`
(deferred or not) is ever invoked during a `WaiveDOCFLG` call. A schema object only fires in response
to DML against the table it is defined on. Read strictly, the scope note's phrase "constraints and
triggers on **Piece B's own objects**" would exclude the one mechanism capable of intercepting
`WaiveDOCFLG`'s actual write.

### Observation 1 — reported, not resolved silently: the closure mechanism touches the accepted `DOCFLG` table

The go-ahead's scope note reads "closure by construction at the schema level (constraints and
triggers on Piece B's own objects)," which on its narrowest reading names only
`RegistryFieldProvenance`. But item 6, in the same checklist, already requires "DOCEFL insertion
gets its own exact-one cardinality trigger" — an unavoidable **new** trigger on the accepted `DOCEFL`
table, not on `RegistryFieldProvenance` — and the go-ahead's own Scope paragraph describes Piece B as
covering RegistryFieldProvenance "and every governed write path that touches it," which is exactly
what a new `DOCFLG` trigger intercepting `WaiveDOCFLG`'s write is. Read against item 6's own
precedent, "Piece B's own objects" is best read as *the schema objects Piece B's migration
additively creates* — including new triggers it attaches to `DOCEFL`/`DOCFLG` for this piece's
invariant — not as a hard exclusion of any table besides `RegistryFieldProvenance` itself.

**Proposed resolution:** a new, additive `BEFORE UPDATE` trigger and trigger function on the accepted
`"DOCFLG"` table (created by Piece B's `Up`, alongside `RegistryFieldProvenance`, its own triggers,
and the item-6 `DOCEFL` insertion trigger) is the closure mechanism for item 8/19. It does not alter,
drop, or replace the existing `WaiveDOCFLG` function or the existing `RejectTerminalDOCFLGMutation`
trigger — both remain byte-identical — and is therefore consistent with minimal-surface discipline
(item 3) under the same reading item 6 already establishes. **This reading is submitted for Miguel's
explicit confirmation as part of approving this mapping**, exactly as the go-ahead's scope note
requires for this specific question; it is not adopted silently, and no code implements it yet.

### Observation 2 — reported, not resolved silently: items 10 and 12 name a shape, not an enumerated column/constraint list

Piece A's attempt-#2 mapping could enumerate an exact six-column list and an exact four-constraint
list because a rejected candidate already existed to inspect. Piece B has no candidate — `git log`
and a full-repository search confirm `RegistryFieldProvenance` has never been created in this
repository. Items 10 (store-type parity for "every column Piece B adds") and 12 (the widened
Up/Down/Up catalog surface) can therefore only commit to the **required test shape and location**
now; the literal column, constraint, and index list is necessarily fixed when `RegistryFieldProvenance`'s
own `Up` is authored during TDD (ordered instruction 3), and is then reported in the implementation's
own status evidence map against these same two items — exactly the level of specificity the checklist
items themselves use (behavioural requirements, not DDL). **Proposed resolution:** approve the
mapping on this basis, as Piece A's own test-plan gate approved shape-level commitments for items it
had not yet measured (e.g. item 20's "no suite-count projection" rule); no additional authorization
is requested beyond confirming this reading.

### Test inventory this mapping commits to

| Surface | New | Existing | Documentation-only |
|---|---:|---:|---:|
| Contract (ordinary), proposed `P11bPieceBContractTests.cs` | 4 methods (items 2/3, 10×2) — final count depends on whether item 10 applies (observation 2) | 0 | — |
| Disposable, proposed additions to `P11aDisposableDatabaseTests.cs` | 10 methods (items 6/13/17/18 as 3, 9, 10, 12, 14, 15, 16, 19) — final count depends on observation 2 | 0 | — |
| Verification command | 0 | preflight checks 1–6; base-to-implementation path list | — |
| Documentation obligation | — | — | items 11 (validator non-observation stated), 20 (claims-equal-assertions) |

**No suite-count projection is recorded**, per proof-pattern rule 1 and the same discipline Piece A's
mapping adopted: the gate does not require one, and the exact count is fixed only once
`RegistryFieldProvenance`'s DDL is authored.

### What this test-plan step did not do

No implementation, migration, model, constraint, trigger, validator, fixture, test, importer, or
Scope 1 work: not one line of code was written. `WaiveDOCFLG`'s accepted definition, the validator
source, and the migration history were inspected **read-only** (`Read`, `Grep`, `git log`) exactly as
authorized. No amendment-4 prototype preflight was run and no post-pin prototype content was read.
No prototype read, write, fetch, or checkout of content; no database, container, service, deployment,
or live-data action, disposable or otherwise; no history rewrite. Piece B implementation, Piece C,
Piece D, and Scope 1 remain gated and unstarted.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Candidate/history access mode | read-only `Read` / `Grep` / `git log` only — no candidate exists to diff |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it.

### Gate statement — Miguel's decision is required before implementation

This mapping is submitted under the go-ahead's test-plan gate. **Piece B implementation remains
unauthorized until Miguel records an explicit approval of this mapping**; the instruction to record
it is not approval of it. Requested decision: **approve**, **reject**, or **return with
corrections** — in particular on Observation 1 (whether a new additive trigger on the accepted
`DOCFLG` table is the intended, authorized mechanism for item 8/19's closure by construction) and
Observation 2 (whether committing items 10/12 to test shape now, with the literal column/constraint
list finalized during TDD and reported in the implementation's evidence map, is an acceptable reading
of the test-plan gate for a piece with no existing candidate).

## 2026-08-06 Piece B go-ahead — acceptance recorded

This step performs **ordered instruction 1 of `docs/AGENT-PROMPT-v5-P1-1b-piece-b-goahead.md`**:
the governed records commit acknowledging Piece B's go-ahead, pushed before any code. The go-ahead
prompt itself is already tracked and pushed at `5813a064b29f88ebc928cfbb0c7e68fff45bde8e`; it is
not duplicated or rewritten merely to force an unchanged path into this commit.

Live Git state was verified fresh rather than trusted: local `HEAD` = `origin/feature/p1-1b` =
`5813a064b29f88ebc928cfbb0c7e68fff45bde8e`, clean tree, `0 0` divergence against origin. That
commit added only the go-ahead prompt file (148 insertions, one path) and touched neither
`docs/p1-1b-status.md` nor `docs/PROJECT-STATE.md`, so both remained accurate as of Piece A's
Accept and are updated here for the first time to reflect the go-ahead.

**Authority and content, restated from the go-ahead.** Piece A has a recorded Accept
(`docs/p1-1b-o10-independent-review.md`, "Piece A attempt #2 review — Accept": 0 Critical / 0 High
/ 0 Medium / 0 Low). Per amendment 3, Piece A's Accept authorizes Piece B to seek its own
go-ahead; `docs/AGENT-PROMPT-v5-P1-1b-piece-b-goahead.md` is that go-ahead. It reopens no decision.
The five baselines remain 119 / 119 / 52 / 221 / **2,787**; the two `Routine` rows still import
verbatim; the pin remains `b91768513fc638381fbde91f0b576b08220a98f6`. Monolithic rejects
`b324a3e…`, `57f0f023…`, `7ea6c0f…` remain neutralized evidence only, never resurrected.

**Scope, restated.** `RegistryFieldProvenance` alone — its constraints, triggers, and every
governed write path that touches it. Additive base: the accepted P1-1a catalog plus accepted
Piece A (`f6f297b…`). No roles, `SECURITY DEFINER` functions, or governed commands — those are
Piece C. No importer, no Scope 1, no prototype access beyond the amendment-4 preflight. The
`WaiveDOCFLG` closure-by-construction scope note (checklist item 8) is analyzed at the test-plan
gate, not here, per the go-ahead's own instruction.

**The Piece B consolidated checklist** is exactly the go-ahead's 20 numbered items — preflight and
surface (1–3), R4 closed by construction (4–8), standing guarantees carried into this piece
(9–12), required schema-level rejection proofs (13–19), and proof honesty (20) — and to nothing
else. The implementer's evidence map and the reviewer's disposition key to this list only.

**Ordered execution ahead, restated:** (1) this records commit; (2) the test-plan gate — record
the checklist→test mapping and the `WaiveDOCFLG` closure analysis, then stop for Miguel's explicit
approval; (3) implement, TDD first, from the pushed tip after approval; (4) full independent
adversarial review, the first attempt of this piece.

**What this step did and did not do.** Documentation only. No implementation, migration, model,
constraint, trigger, test, fixture, importer, prototype, database, container, service, deployment,
or live-data work occurred. Piece B implementation remains unauthorized pending the test-plan gate
and Miguel's explicit approval of it — the instruction to seek the go-ahead is not approval of
implementation. Piece C, Piece D, and Scope 1 remain gated and unstarted. O5 remains the project's
only other open item.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, constraint, trigger, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |
| Local `HEAD` / `origin/feature/p1-1b` immediately before this commit | `5813a064b29f88ebc928cfbb0c7e68fff45bde8e`, clean tree, `0 0` divergence |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. The last independently reproduced
figures remain those of the Piece A attempt #2 Accept record below.

## 2026-08-06 Piece A attempt #2 — mandatory focused independent re-review recorded: Accept

This step performs **ordered instruction 4 of `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-5.md`**,
run in a fresh, independent Claude CLI session per that instruction's requirement. The full verdict,
findings, item-by-item confirmation, and independent verification evidence are recorded in
`docs/p1-1b-o10-independent-review.md` under **"Piece A attempt #2 review — Accept"**. Summary:

- **Verdict: Accept — 0 Critical, 0 High, 0 Medium, 0 Low.** Live Git state was verified fresh
  (local `HEAD` = `origin/feature/p1-1b` = `f6f297b52425464fe11a0ef3aa87f36a138e12c7`, clean tree,
  `0 0` divergence against the records/approval base `567c6ce3ebc60ffb8017b39518180a14062daa5e`)
  rather than trusted from this file.
- The amendment-4 reformulated preflight was independently re-run fresh, read-only, against the
  prototype clone: checks 1–5 passed (pin reachable and ancestral, local clone anchored, 49/49
  roster blobs with 0 mismatches, 48/48 direct `Editor/Data` surface with 0 delta); check 6
  reproduced the same live-tip divergence (`3dd4150…`, commits `1e841a4`/`3dd4150`) already on
  record, with no post-pin content read or adopted.
- The exact base-to-candidate diff was independently confirmed to touch only the same 12
  implementation/model/test paths the rejected candidate `6f86023d…` changed, plus this file and
  `docs/PROJECT-STATE.md`. The remediation delta against the candidate touches exactly six of those
  twelve files; the other six are byte-identical to the candidate.
- A-R1, A-R2, A-R3, and A-R4, and the named DOCFLG `ReviewPriority` strengthening, were each
  independently traced through the actual validator code, EF model/snapshot, and disposable SQL —
  not taken on the implementer's word — and each found to genuinely satisfy its required proof,
  including verifying the A-R1 and A-R3 tests are not vacuous through company-scope filtering.
  Every Reject #1 Pass row was confirmed to still hold on the new diff.
- Build, focused, ordinary, and disposable PostgreSQL suites were independently rerun fresh and
  reproduced the implementer's own measured counts exactly (0 warnings; 37/37; 637/637; 16/16);
  `git diff --check` clean; both accepted P1-1a migration blob IDs unchanged; 0 residual
  `sibyla-p11*` containers; 0 matches on a diff-restricted secret/role/`SECURITY DEFINER`/
  `DROP OWNED` scan.

**Piece A now has an accepted implementation.** Per amendment 5 / amendment 3, Piece B may seek its
own go-ahead; Piece C, Piece D, and Scope 1 remain gated and unstarted pending each predecessor's
own recorded Accept. No neutralization was authorized or performed. O8/O9/O10 decisions, the five
baselines 119 / 119 / 52 / 221 / 2,787, and the two verbatim `Routine` rows are unchanged. O5 remains
the project's only other open item.

## 2026-08-06 Piece A attempt #2 implementation — evidence map

This step performs **ordered instruction 3 of `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-5.md`**, under
the approval recorded above (`docs/AGENT-PROMPT-v5-P1-1b-piece-a-testplan-approval.md`, tracked and
pushed at `47d6fc2…`). Piece A attempt #2 is implemented as a **remediation of candidate
`6f86023dce83ffc02f2a0a66c14cbbdde3e55236`**: the exact 12 candidate implementation/model/test paths
were restored byte-for-byte via `git checkout 6f86023d… -- <paths>` from records base `bc835f7e…`,
then only A-R1…A-R4 and the single named DOCFLG `ReviewPriority` strengthening approved above were
applied. No other content change was made. It does not perform ordered instruction 4 (the focused
independent re-review), which is required to run in a fresh, independent session.

### Reformulated preflight — re-run fresh at attempt-#2 start

Read-only against prototype clone `D:\fileStorage\repos\invoice-skill-build`, using only `git fetch`,
`git cat-file`, `git ls-tree`, `git rev-parse`, `git merge-base`, and `git log`:

1. Pin `b91768513fc638381fbde91f0b576b08220a98f6` resolved locally before the fetch and in the
   fetched remote after `git fetch --prune origin`. **Pass.**
2. `git merge-base --is-ancestor` confirms the pin remains an ancestor of live `origin/main`. **Pass.**
3. Local prototype `HEAD` still equals the pin. **Pass.**
4. All **49/49** roster blobs (48 `Editor/Data/*.json` paths plus `Backups/Control Log.md`, with the
   O8 `entbnk.json` substitution applied) resolved at the pin with **0** hash mismatches. **Pass.**
5. The pinned direct `Editor/Data` surface contains exactly **48** blob (file) tree entries, all
   rostered, with **0** delta; the one `Editor/Data/Backups` tree entry present is a subdirectory,
   not a file, and is correctly excluded from the 48-file surface count. **Pass.**
6. (Non-stop finding.) Live tip remains `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`, with the same two
   already-recorded post-pin commits `1e841a4` (*Complete Stage 10 Round 8 reconciliation and mapping
   updates*) and `3dd4150` (*Apply Stage 10 Round 8 revenue review updates*) — no new divergence since
   Reject #1. No post-pin content was read or adopted.

### Item-by-item checklist evidence

1. **Reformulated preflight checks 1–5 and check-6 non-adoption rule** — Pass, re-proven fresh above.
2. **Exact base-to-candidate surface and Piece A strict scope** — this commit changes exactly the same
   12 Piece A implementation/model/test paths the candidate changed, plus this status record and
   `docs/PROJECT-STATE.md` (the binding same-commit rule). `git diff --name-status`, restricted to
   `src/` and `tests/`, between records base `bc835f7e…` and this commit lists exactly those 12 paths,
   with no Piece B/C/D, role, ACL, function, command, provenance-invariant, importer, or live-action
   path. `P11bPieceAContractTests.Piece_a_sql_is_schema_only_and_exactly_scoped` passes unchanged.
3. **O9-D1 `ENTMST.DirectDebit` nullable, no default** — Pass, unchanged from the candidate; the
   contract tests and the 119/119 round-trip disposable test both pass.
4. **O9-D2 `ENTMST.TaxIdVerificationStatus` nullable without invented sentinel** — Pass, unchanged;
   the same three surfaces pass.
5. **O9-D3 nullable DOCEFL `ItemClass`** — now **Pass in full**: the nullable-schema and
   NULL-observation halves are unchanged, and A-R1's new fail-closed validator gate (item 17) closes
   the previously-missing half.
6. **O9-D4 exact six `ReviewPriority` literals** — Pass, and DOCFLG coverage is now widened exactly as
   approved: `Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness`
   additionally inserts all six governed literals as DOCFLG rows (asserted count = 6) and separately
   proves the seventh literal `'Normal'` raises `check_violation` at DOCFLG as well as at DOCEFL.
7. **O9-D5 imported terminal exemption with strong company-scoped evidence identity** — now **Pass in
   full**: the existing positive/native halves are unchanged, and A-R3's new disposable test
   (item 19) proves the wrong-company case.
8. **O10-D1 nullable DOCFLG snapshot, retained composite `MATCH SIMPLE`, plain `EFCode` FK,
   prospective completeness** — Pass, unchanged.
9. **Accepted fixture `EF0000053`** — Pass, unchanged.
10. **Accepted P1-1a migration untouched** — Pass. `20260805180000_P11aFdrSchema.cs` and
    `P11aSchemaSql.cs` have the same Git blob IDs (`497ce4ecbe63aa2c5fd7dd6eb2bcac01c6b48d0e`,
    `74c5912cc85aebd99c1169a27217c67aa1955476`) as the pre-implementation `HEAD`.
11. **Accepted `ImportEvidenceRow` uniqueness unchanged** — now **fully asserted** through A-R4
    (item 20): the new disposable test directly compares all four accepted UNIQUE constraint
    definitions and every index definition, accepted-versus-first-`Up`, and finds them identical.
12. **R5 true SQL NULL round trip; no invented `false`/`Verified`/`Annotation` defaults** — Pass,
    unchanged.
13. **Complete imported ENTMST population and the 119/119 proof** — Pass, unchanged; measured
    **119** `DirectDebit` NULL / **119** `TaxIdVerificationStatus` NULL through the production
    PostgreSQL source.
14. **EF generated-column/catalog alignment** — now **Pass**: `DOCFLG.ImportTargetTable` is mapped
    `character varying(32)` in both the runtime model (`P11aRegistryModelConfiguration`) and the EF
    snapshot (`SibylaDbContextModelSnapshot`), matching the SQL catalog's
    `varchar(32) GENERATED ALWAYS AS ('DOCFLG') STORED` exactly. Proven by the strengthened contract
    test, the new snapshot-versus-runtime contract test, and the new disposable EF-versus-catalog
    test (item 18).
15. **Exact Piece A `Down` and Up/Down/Up stability** — Pass, now over the widened catalog surface
    (item 20): `PieceACatalogSnapshot` additionally captures column store types (`data_type`,
    `character_maximum_length`) and every `pg_indexes.indexdef` for `ENTMST`, `DOCEFL`, `DOCFLG`, and
    `ImportEvidenceRow`; both equalities (accepted = post-`Down`; first `Up` = second `Up`) still hold
    over that wider surface.
16. **Existing-row compatibility, null handling, reader types, rollback safety** — Pass, unchanged;
    the whole ordinary suite (637/637) and the untouched-behaviour regression test both pass.
17. **A-R1 (High) — the validator closes the D8 `ItemClass` vocabulary, fail-closed** — Pass.
    `RegistryValidationCheck.DoceflItemClassVocabulary` (`docefl.item-class.vocabulary`) and
    `DocflgSnapshotItemClassVocabulary` (`docflg.snapshot-item-class.vocabulary`) are new fail-closed
    `Result(...)` checks (not `Warning`), added to `DataCheckNames`. Four new validator tests each
    prove an unknown non-null `Invented` value fails closed — DOCEFL imported, DOCEFL native, DOCFLG
    snapshot imported, DOCFLG snapshot native — each asserting `Outcome=Failure`, `FindingCount=1`,
    `AffectedKeys` containing exactly the offending code, `report.Succeeded=false`, and that the other
    row class's vocabulary check stays `Success`. The strengthened five-warning test additionally
    asserts both new vocabulary checks are `Success` with `FindingCount=0` on the same
    all-honest-NULL snapshot. The existing database-level `check_violation` proof and the
    `Source_failure_marks_every_data_check_failed…` regression both still pass.
18. **A-R2 (Medium) — EF store-type parity for every column Piece A adds or alters** — Pass. The
    runtime model (`P11aRegistryModelConfiguration.ConfigurePieceAStoreTypes`) and the EF snapshot now
    declare the exact SQL store types for the six named columns (`boolean`;
    `character varying(24)`; `character varying(16)` ×2; `uuid`; `character varying(32)`
    generated/stored). Proven by: the strengthened contract test asserting `GetColumnType()` for all
    six; the new contract test comparing the runtime model against the EF snapshot for all six; and
    the new disposable test comparing the runtime model against `information_schema.columns` in the
    migrated disposable catalog for all six. Scope is deliberately the six touched columns only, per
    the approved reading; `DOCEFL`/`DOCFLG.ReviewPriority` remain untouched and unclaimed.
19. **A-R3 (Medium) — the imported terminal exemption is proven company-isolated** — Pass. The new
    disposable test creates companies A and B, gives company B same-code `ImportEvidenceRow` evidence
    targeting the same `FlagInstanceID` company A will use, and proves inside a rolled-back
    transaction: (1) binding company A's terminal DOCFLG row to company B's evidence raises
    `foreign_key_violation` on `FK_DOCFLG_ImportEvidenceRow`; (2) the same row with no evidence raises
    `check_violation` on the terminal-evidence CHECK; (3) the positive control with company A's own
    evidence inserts successfully.
20. **A-R4 (Low) — the catalog/uniqueness proof asserts everything status claims** — Pass. The new
    disposable test migrates to the accepted tip, captures all four accepted `ImportEvidenceRow`
    UNIQUE constraints by exact `pg_get_constraintdef` text and every `pg_indexes` definition,
    migrates `Up`, and asserts both sets are identical; the four accepted definitions are also
    asserted individually by exact text. This status record claims exactly this surface and no more.

### Measured verification (this attempt-#2 implementation)

| Verification | Measured result |
|---|---:|
| `dotnet build GOTT.Sibyla.slnx --no-incremental` | 0 warnings, 0 errors; 13.15 s |
| Focused (Piece A + validator + authored-fixture) | **37** passed, 0 failed, 0 skipped |
| Ordinary `dotnet test --no-build` | **637** passed, 0 failed, 0 skipped; 16 s test duration |
| Disposable PostgreSQL 17 suite (`scripts\run-p11a-disposable-tests.ps1`) | **16** passed, 0 failed, 0 skipped; 11 s test duration |
| `git diff --check` | clean |
| Accepted migration blob IDs (`20260805180000_P11aFdrSchema.cs`, `P11aSchemaSql.cs`) | unchanged — identical to pre-implementation `HEAD` |
| Diff-only common-secret-pattern scan | 0 matches |
| Residual `sibyla-p11*` containers | **0** |

Focused count grows from the candidate's 32 to **37** (+4 new A-R1 validator tests, +1 new A-R2
contract test). Disposable count grows from the candidate's 13 to **16** (+1 A-R2 EF-versus-catalog
test, +1 A-R3 wrong-company test, +1 A-R4 catalog/uniqueness test). No suite-count projection was made
in advance; these are measured totals only, per proof-pattern rule 1.

### What this step did and did not do

Restored the exact 12 candidate paths from `6f86023dce83ffc02f2a0a66c14cbbdde3e55236` content-identical
via `git checkout <candidate> -- <paths>`, then applied only A-R1…A-R4 and the single named DOCFLG
`ReviewPriority` strengthening. No other content change was made: the migration SQL, the
`ReviewPriority`/`EF0000053`/O10-D1 FK semantics, and every Reject #1 Pass surface are byte-identical
to the candidate except where a named remediation changes them. No prototype write or post-pin read.
No shared/live database, service, deployment, or production action. No role, ACL, or
`SECURITY DEFINER` surface was added. The candidate commit is the commit containing this
self-referential status section; its full SHA is recorded in the review handoff rather than invented
inside its own content. Ordered instruction 4 — the focused independent re-review — has not run; per
amendment 5 it must run in a fresh, independent session.

## 2026-08-06 Piece A attempt #2 test-plan gate — Miguel's approval recorded

This step records the gate decision required by amendment 5's ordered instruction 2, per
`docs/AGENT-PROMPT-v5-P1-1b-piece-a-testplan-approval.md`, already tracked and pushed at
`47d6fc2e5ac87323c47cd7b82d8e1d5dae37ff7a`; it is not duplicated or rewritten merely to force an
unchanged path into this commit. This commit performs the Records instruction of that approval
file: recording the decision here and repairing `docs/PROJECT-STATE.md` in the same commit. It
does not perform ordered instruction 3 (attempt #2 implementation) or ordered instruction 4 (the
focused re-review).

### Decision: Approved, with one named addition

The 20-item checklist→test mapping recorded below — the 16 Reject #1 disposition rows in the
review's own order plus A-R1…A-R4 — is **approved as the binding attempt-#2 test plan**. The A-R1
gate shape is confirmed as intended: the four new fail-closed validator tests across
DOCEFL/DOCFLG × imported/native, the two new failure-outcome check identifiers
(`docefl.item-class.vocabulary`, `docflg.snapshot-item-class.vocabulary`) joining the data-check
list, the cross-independence assertions between the two row classes, and the strengthened
five-warning test proving honest NULL remains an observation and that known values pass. The
closed D8 vocabulary is confirmed against the normative annex as exactly `Annotation`, `Decision`,
`Status`.

**The two reported observations are decided:**

1. **"Both" versus four accepted `ImportEvidenceRow` unique constraints.** A-R4's word "both" is
   corrected on the record: it inherited the review's wording and undercounted. The accepted
   P1-1a DDL declares four UNIQUE constraints on `ImportEvidenceRow`, and the plan's resolution —
   asserting all four by exact name and `pg_get_constraintdef` text, plus every `pg_indexes`
   definition — is a strict superset of any reading and is **approved**.
2. **Store-type parity scope.** The six-column scope (`ENTMST.DirectDebit`,
   `ENTMST.TaxIdVerificationStatus`, `DOCEFL.ItemClass`, `DOCFLG.ItemClass`,
   `DOCFLG.ImportEvidenceRowId`, `DOCFLG.ImportTargetTable`) is confirmed as the intended reading
   of "every column Piece A adds or alters". Project-wide store-type parity is explicitly out of
   attempt #2's scope; if ever wanted, it needs its own authorization and is not implied by this
   approval.

**One named addition, authorized here so it is in scope:** item 6's DOCFLG coverage nick is closed
by name — the disposable test
`Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness` (or a companion
assertion in the same disposable class) additionally inserts all six governed `ReviewPriority`
literals as DOCFLG rows and proves the seventh literal `'Normal'` raises `check_violation` at
DOCFLG, mirroring the existing DOCEFL half. This is a test-only strengthening explicitly
authorized by this approval; it changes no migration, model, or validator content. With it, item
6's status wording may state the widened coverage — and, per proof-pattern rule 1, must state
exactly that and no more. No other addition beyond A-R1…A-R4 and this named item is authorized;
an apparent need for one remains a stop-and-report.

### What is now authorized

Ordered instruction 3 of amendment 5: implement Piece A attempt #2 as a **remediation of
candidate `6f86023d…`** under the amendment-4 reformulated preflight, applying A-R1…A-R4 exactly
plus the named DOCFLG strengthening above; full ordinary, focused, and disposable suites green;
build 0 warnings; 0 residual containers; the status evidence map keyed to the 20-item checklist
item by item, with measured counts only; commit and push. Then ordered instruction 4: the focused
independent re-review (full adversarial depth on A-R1…A-R4 and the named addition; regression
confirmation that every Reject #1 Pass row still holds on the new diff), verdict recorded. On
Accept, stop and report — Piece B still needs its own go-ahead. On Reject, neutralize per
amendment 3, stop, and escalate to Miguel: attempt #2 is the second and final attempt before
escalation.

### What this approval does not authorize

Starting Piece B, C, or D. Any content change beyond A-R1…A-R4 and the single named DOCFLG test
strengthening. Resurrecting any part of the three named monolithic rejects. Any prototype write or
post-pin read. Reopening any closed decision or changing any baseline. Any shared/live database
write. Production go-live (O5 remains the only other open item). History rewrite in either
repository.

Baselines 119 / 119 / 52 / 221 / 2,787, the two verbatim `Routine` rows, pin `b917685…`, and every
O8/O9/O10 decision are unchanged. This records step performs no implementation, migration, model,
fixture, test, prototype, database, container, service, deployment, or live-data work; Piece A
attempt #2 implementation has not started.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. The last independently reproduced
figures remain those of the Reject #1 record below.

## 2026-08-06 Piece A attempt #2 test-plan gate — checklist→test mapping, awaiting Miguel's approval

This step performs **ordered instruction 2 of `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-5.md` only**:
it records the attempt-#2 checklist→test mapping required by the test-plan gate. It does **not**
perform ordered instruction 3 (attempt #2 implementation) or ordered instruction 4 (the focused
re-review), and it does not re-run the amendment-4 preflight, which belongs to instruction 3.
**Implementation remains unauthorized until Miguel explicitly approves this mapping.** Approval is
not implied by the instruction to record it.

Nothing here changes a decision, a baseline, or the candidate's authorized content. The five
expected completeness baselines remain **119 / 119 / 52 / 221 / 2,787**, the two pinned `Routine`
rows still import verbatim, and the immutable source pin remains
`b91768513fc638381fbde91f0b576b08220a98f6`. The monolithic rejects `b324a3e…`, `57f0f023…`, and
`7ea6c0f…` remain neutralized evidence only.

### The checklist being mapped

Per amendment 5, **the attempt-#2 checklist is exactly the Reject #1 requirement-by-requirement
disposition table plus A-R1…A-R4** — 16 disposition rows (items 1–16 below, in the review's own
order) and four binding remediations (items 17–20). No other item exists, and no other content
change is authorized; an apparent need for one is a stop-and-report.

### Legend — test surfaces and status labels

| Label | Meaning |
|---|---|
| **Contract (ordinary)** | `tests/Sibyla.Tests/Persistence/P11bPieceAContractTests.cs` — SQL-text and EF-model assertions, no infrastructure; runs in the ordinary suite. A candidate-added path, so it is absent at the current branch tip and returns with the remediation base |
| **Validator (ordinary)** | `tests/Sibyla.Tests/Registry/RegistryValidationServiceTests.cs` — in-memory snapshot through `RegistryValidationService`; ordinary suite |
| **Fixture (ordinary)** | `tests/Sibyla.Tests/Persistence/P11aAuthoredRowFixtureTests.cs` — authored-row shapes; ordinary suite |
| **Disposable** | `tests/Sibyla.Tests/Persistence/P11aDisposableDatabaseTests.cs`, class-level `[Trait("Category","P11aDatabase")]`; excluded from ordinary `dotnet test` and run only by `scripts\run-p11a-disposable-tests.ps1` against a disposable PostgreSQL 17 container |
| **Verification command** | Non-test evidence (read-only Git or preflight commands). Recorded as a command because no test can assert it; never described as a test |
| **Existing (regression)** | The method exists in candidate `6f86023d…` and is re-run unchanged; it re-proves a Reject #1 Pass row on the new diff. Because Reject #1's neutralization restored all 12 paths to `bc835f7e…`, every `Piece_a_*` method named below is present **in the candidate**, not at the current branch tip; it returns with the remediation base under amendment 5 |
| **Strengthened** | An existing candidate method that gains named additional assertions |
| **New** | A method that does not exist in candidate `6f86023d…` |

Amendment 5's re-review scope requires that every Reject #1 Pass row still holds on the new diff.
Items 1–16 therefore carry their existing proofs forward unchanged unless a remediation names them;
only items 5, 7, 11, 14, 15 and 17–20 gain new or strengthened assertions.

### 1 · Reformulated preflight checks 1–5 and the check-6 non-adoption rule

*Reject #1: Pass.* **Verification command; not a test — existing procedure, re-run.**
Re-run read-only at attempt-#2 start under amendment 4: `git fetch`, `git cat-file`, `git ls-tree`,
`git log`, `git merge-base` only. Asserted: pin `b917685…` resolves locally and in the fetched
remote; pin is an ancestor of live `refs/heads/main`; local prototype `HEAD` equals the pin; 49/49
roster blobs resolve with 0 hash mismatches; the pinned direct `Editor/Data` surface is exactly
48 files with 0 delta. Check 6 logs the live tip and each post-pin commit by hash and subject only.
Checks 1–5 failing is a hard stop. No post-pin content is read or adopted.

### 2 · Exact base-to-candidate surface and Piece A strict scope

*Reject #1: Pass.* **Verification command plus Contract (ordinary) — existing regression.**
`git diff --name-status <attempt-#2 base>..<attempt-#2 commit>` must list only this status record and
the Piece A implementation/model/test paths, with no Piece B/C/D, role, ACL, function, command,
provenance-invariant, importer, or live-action path. The negative half is asserted in code by
`P11bPieceAContractTests.Piece_a_sql_is_schema_only_and_exactly_scoped`, which already asserts that
`Up` contains no `CREATE ROLE`, `SECURITY DEFINER` or `CREATE FUNCTION`, that `Down` contains no
`DROP OWNED`, and that neither `Up` nor `Down` drops an `ImportEvidenceRow` constraint.

### 3 · O9-D1 `ENTMST.DirectDebit` nullable, no default

*Reject #1: Pass.* **Existing regression, three surfaces.**
- Contract: `P11bPieceAContractTests.Piece_a_sql_is_schema_only_and_exactly_scoped` — `Up` contains
  `ALTER TABLE "ENTMST" ALTER COLUMN "DirectDebit" DROP NOT NULL`; `Down` contains
  `ALTER COLUMN "DirectDebit" SET NOT NULL`.
- Contract: `P11bPieceAContractTests.Piece_a_nullable_and_generated_columns_are_modelled_truthfully`
  — the EF CLR type is `bool?`.
- Disposable: `P11aDisposableDatabaseTests.Piece_a_validator_round_trips_119_unreferenced_imported_entity_nulls`
  — 119 genuine SQL `NULL` values are written, read through
  `PostgresRegistryValidationSnapshotSource`, asserted `Assert.Null(entity.DirectDebit)`, and counted
  119 by `RegistryValidationCheck.EntmstDirectDebitAbsent`. No default is inserted anywhere.

### 4 · O9-D2 `ENTMST.TaxIdVerificationStatus` nullable without an invented sentinel

*Reject #1: Pass.* **Existing regression, three surfaces.**
Same three methods as item 3, asserting the `DROP NOT NULL` / `SET NOT NULL` pair, EF nullability
(`IsNullable` true, CLR `string`), and the 119 `Assert.Null(entity.TaxIdVerificationStatus)`
round-trip pairs with `EntmstTaxIdVerificationUnverified` = 119. The absence of a production
`Verified` default is proven by the same round trip: the value read back is null, not `Verified`.

### 5 · O9-D3 nullable DOCEFL `ItemClass`

*Reject #1: **Partial / Reject** — nullable schema and NULL observation pass; the unknown non-null
validator identity gate is absent.* **Converts to Pass through item 17 (A-R1).**
- Existing regression (schema half): Contract
  `Piece_a_nullable_and_generated_columns_are_modelled_truthfully` (`DOCEFL.ItemClass` is nullable)
  and Disposable
  `Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness`, which inserts
  an imported rule with `ItemClass` NULL and proves PostgreSQL rejects `'Invented'`.
- Existing regression (observation half): Validator
  `RegistryValidationServiceTests.Piece_a_reports_all_five_honest_historical_completeness_findings`
  — two null imported rules produce `DoceflItemClassUnassigned` = 2 as a **Warning**.
- New (the missing gate): the four A-R1 validator tests in item 17, of which
  `Piece_a_validator_fails_closed_on_unknown_non_null_imported_docefl_item_class` and
  `..._native_docefl_item_class` are the DOCEFL half.

### 6 · O9-D4 exact six `ReviewPriority` literals

*Reject #1: Pass.* **Existing regression, two surfaces — stated exactly as the candidate asserts.**
- Contract: `Piece_a_sql_is_schema_only_and_exactly_scoped` asserts that the governed six-literal
  sequence `'Before Posting','High','Immediate','Informational','Periodic Review','Routine'` occurs
  in Piece A's `Up`. That is a single substring assertion over the migration text; it does not
  independently count or compare the two CHECK definitions, and nothing here claims it does.
- Disposable: `Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness`
  inserts all six literals as **DOCEFL** rows and asserts the count is exactly 6, and proves the
  seventh literal `'Normal'` raises `check_violation` at DOCEFL. The DOCFLG CHECK is exercised in
  the same test by the terminal and native DOCFLG rows, which carry `'Routine'` — the literal O9-D4
  adds. The test does not insert all six values into DOCFLG, and this record does not claim it does.

Reject #1 recorded this row as Pass on exactly that evidence, and it is carried forward unchanged as
regression evidence; no additional assertion is invented for it here.

### 7 · O9-D5 imported terminal exemption with strong company-scoped evidence identity

*Reject #1: **Partial** — FK and CHECK semantics are correct by inspection; the mandated
other-company rejection test is missing.* **Converts to Pass through item 19 (A-R3).**
- Existing regression (positive and native halves): Disposable
  `Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness` — an imported
  terminal DOCFLG row with matching-company evidence is accepted; a native terminal row without
  evidence raises `check_violation`.
- New (the negative half): Disposable
  `Piece_a_wrong_company_import_evidence_cannot_exempt_a_terminal_docflg_row`, item 19.

### 8 · O10-D1 nullable DOCFLG snapshot, retained composite `MATCH SIMPLE`, plain `EFCode` FK, prospective completeness

*Reject #1: Pass.* **Existing regression, two surfaces.**
- Contract: `Piece_a_sql_is_schema_only_and_exactly_scoped` asserts `MATCH SIMPLE` and
  `FOREIGN KEY ("EFCode") REFERENCES "DOCEFL"("EFCode")` in `Up`.
- Disposable: `Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness` —
  an imported NULL snapshot inserts; a native incomplete snapshot raises `check_violation`; a row
  whose composite FK self-exempts on NULL still raises `foreign_key_violation` on the plain `EFCode`
  FK; and `pg_constraint.confmatchtype='s'` is asserted for both `FK_DOCFLG_DOCEFL_EFCode` and the
  retained accepted composite FK.

### 9 · Accepted fixture `EF0000053`

*Reject #1: Pass.* **Existing regression, two surfaces.**
- Fixture: `P11aAuthoredRowFixtureTests.Authored_shapes_use_honest_nulls_and_no_placeholder_literals`
  — the authored code set is exactly `{ BT000012, EF0000000, EF0000053 }` and the `EF0000053` row is
  inactive. Historical `EF0000046` is absent from that surface.
- Disposable: `P11aDisposableDatabaseTests.Migration_applies_and_core_database_postconditions_hold`
  — the authored `EF0000000` / `EF0000053` pair seeds with NULL `EffectiveFrom`, count 2.

### 10 · Accepted P1-1a migration untouched

*Reject #1: Pass.* **Verification command plus Contract (ordinary) — existing regression.**
`git rev-parse <attempt-#2 commit>:src/Sibyla.Infrastructure/Persistence/Migrations/20260805180000_P11aFdrSchema.cs`
and the same for `P11aSchemaSql.cs` must equal the blob IDs at the attempt-#2 base. This is a command,
not a test, and is recorded as such. The in-code half is the `Piece_a_sql_is_schema_only_and_exactly_scoped`
negative assertions that Piece A's own `Up`/`Down` drop no accepted `ImportEvidenceRow` constraint.

### 11 · Accepted `ImportEvidenceRow` uniqueness unchanged

*Reject #1: **Pass by exact source/catalog inspection; coverage incomplete** — no direct
accepted-versus-first-`Up` comparison.* **Converts to fully asserted through item 20 (A-R4).**
- Existing regression: `Piece_a_sql_is_schema_only_and_exactly_scoped` (no `DROP CONSTRAINT` against
  `ImportEvidenceRow` in either direction) and
  `Piece_a_down_is_exact_and_up_down_up_is_catalog_stable`, whose snapshot already includes every
  `pg_constraint` row of `ImportEvidenceRow`.
- New: Disposable
  `Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up`,
  item 20 — the missing direct comparison.

### 12 · R5 true SQL NULL round trip; no invented `false` / `Verified` / `Annotation` defaults

*Reject #1: Pass.* **Existing regression.**
Disposable `Piece_a_validator_round_trips_119_unreferenced_imported_entity_nulls` writes genuine SQL
NULL, reads it through the production `PostgresRegistryValidationSnapshotSource`, and asserts the DTO
values are still null — no in-memory construction and no reflection over constructor defaults.

### 13 · Complete imported ENTMST population and the 119/119 proof

*Reject #1: Pass.* **Existing regression.**
The same round-trip test: all 119 synthetic imported entities are deliberately unreferenced by
FDCHDR/FDCDTL, `snapshot.Entities.Count` is 119, `snapshot.Headers` and `snapshot.Details` are empty,
and both findings count 119. Company scope stays in the query.

### 14 · EF generated-column / catalog alignment

*Reject #1: **Fail** — the generated/stored expression is mapped but `text` does not match SQL
`varchar(32)`.* **Converts to Pass through item 18 (A-R2).**
- Existing regression (expression half): Contract
  `Piece_a_nullable_and_generated_columns_are_modelled_truthfully` asserts
  `GetComputedColumnSql() == "'DOCFLG'"` and `GetIsStored()`.
- Strengthened and New: item 18's store-type assertions and the EF-versus-catalog comparison.

### 15 · Exact Piece A `Down` and Up/Down/Up stability

*Reject #1: **Pass for the exercised touched constraints/columns, with the Low coverage
limitation.*** **Strengthened by item 20 (A-R4).**
Disposable `Piece_a_down_is_exact_and_up_down_up_is_catalog_stable` — migrate to
`20260805180000_P11aFdrSchema`, snapshot, `Up`, snapshot, `Down`, assert accepted equals post-`Down`,
`Up` again, assert first `Up` equals second `Up`. The helper `PieceACatalogSnapshot` is **strengthened**
under item 20 to add column store types and index definitions, so the same two equalities are asserted
over the wider surface. Piece A creates no roles, ACLs or functions, so none is in scope.

### 16 · Existing-row compatibility, null handling, reader types, rollback safety

*Reject #1: Pass.* **Existing regression, four surfaces.**
`Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness` (added constraints
are satisfied by accepted-shaped rows; the transaction is rolled back),
`Piece_a_validator_round_trips_119_unreferenced_imported_entity_nulls` (`IsDBNull`/nullable reader
paths), `Piece_a_down_is_exact_and_up_down_up_is_catalog_stable` (`Down` fails closed rather than
inventing values), and the whole ordinary suite plus
`Database_backed_registry_validation_is_clean_and_exercises_query_sensitive_semantics` as the
untouched-behaviour regression.

### 17 · A-R1 (High) — the validator closes the D8 `ItemClass` vocabulary, fail-closed

**Required behaviour:** any **non-null** `ItemClass` outside the closed D8 vocabulary
(`Decision`, `Status`, `Annotation`) produces an identity-class **Failure** in
`RegistryValidationService`, for **DOCEFL rules and DOCFLG snapshots, imported and native alike**.
The database CHECKs remain an independent second barrier, never the gate.

**Mechanism to be implemented:** two new checks in `RegistryValidationCheck` —
`DoceflItemClassVocabulary` (`"docefl.item-class.vocabulary"`) and
`DocflgSnapshotItemClassVocabulary` (`"docflg.snapshot-item-class.vocabulary"`) — emitted through the
existing failure-producing `Result(...)` helper, not the `Warning(...)` helper, and added to the
service's data-check list so a source failure marks them failed like every other data check.

**Four New Validator (ordinary) tests, one per required row class:**
1. `RegistryValidationServiceTests.Piece_a_validator_fails_closed_on_unknown_non_null_imported_docefl_item_class`
2. `RegistryValidationServiceTests.Piece_a_validator_fails_closed_on_unknown_non_null_native_docefl_item_class`
3. `RegistryValidationServiceTests.Piece_a_validator_fails_closed_on_unknown_non_null_imported_docflg_snapshot_item_class`
4. `RegistryValidationServiceTests.Piece_a_validator_fails_closed_on_unknown_non_null_native_docflg_snapshot_item_class`

Each builds a `CleanValidationSnapshot()` whose single offending row carries `ItemClass = "Invented"`
with `Imported` true or false as named, and asserts: the relevant vocabulary check `Outcome` is
`RegistryValidationOutcome.Failure`, `FindingCount` is exactly 1, `AffectedKeys` contains exactly the
offending `EFCode` / `FlagInstanceId`, and `report.Succeeded` is `false`. The DOCEFL tests assert the
DOCFLG check is unaffected and vice versa, so neither row class can be proven by the other's gate.

**Unchanged null observation — one Strengthened Validator (ordinary) test:**
`RegistryValidationServiceTests.Piece_a_reports_all_five_honest_historical_completeness_findings`
keeps its existing five-warning assertions verbatim (`EntmstDirectDebitAbsent` 1,
`EntmstTaxIdVerificationUnverified` 1, `DoceflItemClassUnassigned` 2,
`DocflgTerminalResolutionEvidenceAbsent` 1, `DocflgSnapshotItemClassAbsent` 1, all
`RegistryValidationOutcome.Warning`) and gains the assertion that **both new vocabulary checks are
`Success` with `FindingCount` 0** on that same snapshot — proving honest NULL is still an observation
and never a failure, and that known values (`Annotation`) pass the gate.

**Existing regression retained:** the database half in
`Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness` (PostgreSQL raises
`check_violation` on `'Invented'`) stays exactly as it is; A-R1 is proven at the validator, and the
CHECK is recorded as the second barrier, not as the gate.

**Existing regression that widens automatically:**
`RegistryValidationServiceTests.Source_failure_marks_every_data_check_failed_instead_of_silently_passing`
covers the two new checks once they join the data-check list, proving they cannot silently pass when
the snapshot source fails.

### 18 · A-R2 (Medium) — EF store-type parity for every column Piece A adds or alters

**The exact column set, taken from Piece A's own `Up` (six columns):**

| # | Column | Piece A action | Accepted / created SQL store type |
|---:|---|---|---|
| a | `ENTMST.DirectDebit` | altered — `DROP NOT NULL` | `boolean` |
| b | `ENTMST.TaxIdVerificationStatus` | altered — `DROP NOT NULL` | `varchar(24)` |
| c | `DOCEFL.ItemClass` | altered — `DROP NOT NULL` | `varchar(16)` |
| d | `DOCFLG.ItemClass` | altered — `DROP NOT NULL` | `varchar(16)` |
| e | `DOCFLG.ImportEvidenceRowId` | added | `uuid` |
| f | `DOCFLG.ImportTargetTable` | added | `varchar(32)`, `GENERATED ALWAYS AS ('DOCFLG') STORED` |

**One New Disposable test — the EF-versus-catalog comparison A-R2 names:**
`P11aDisposableDatabaseTests.Piece_a_ef_store_types_match_the_disposable_catalog_for_every_touched_column`
builds the runtime model, reads each property's relational store type
(`property.GetColumnType()`), reads `information_schema.columns` (`data_type`,
`character_maximum_length`, `is_generated`, `generation_expression`) from the migrated disposable
database for the same six columns, and asserts the pairs are equal, store type and all — for the six
columns above and not only for the expression/stored flags.

**One Strengthened Contract (ordinary) test — fast, infrastructure-free half:**
`P11bPieceAContractTests.Piece_a_nullable_and_generated_columns_are_modelled_truthfully` keeps every
existing nullability and computed-column assertion and gains explicit `GetColumnType()` assertions for
all six columns (`boolean`, `character varying(24)`, `character varying(16)`, `character varying(16)`,
`uuid`, `character varying(32)`), so a model regression fails without a container.

**One New Contract (ordinary) test — the snapshot half A-R2 also names:**
`P11bPieceAContractTests.Piece_a_model_snapshot_matches_the_runtime_model_for_touched_columns` reads
`SibylaDbContextModelSnapshot.Model` and asserts, for the same six columns, that store type,
nullability, computed-column SQL and stored flag equal the runtime model's — closing the "EF model
**and** snapshot" wording of A-R2 without a database.

**Deliberate scope limit, stated so it is approved rather than assumed:** the parity assertions cover
exactly the six columns Piece A adds or alters. Accepted columns Piece A does not touch — including
`DOCEFL.ReviewPriority` and `DOCFLG.ReviewPriority`, where Piece A replaces a CHECK constraint but
not the column — are **not** given new EF store types, because that would be a content change outside
A-R1…A-R4 and therefore a stop-and-report. Those columns are still compared accepted-versus-post-cycle
in the item-20 catalog surface as touched objects.

### 19 · A-R3 (Medium) — the imported terminal exemption is proven company-isolated

**One New Disposable test:**
`P11aDisposableDatabaseTests.Piece_a_wrong_company_import_evidence_cannot_exempt_a_terminal_docflg_row`
creates two companies (A and B) with their own import batches, then an `ImportEvidenceRow` owned by
**company B** whose `TargetTable` is `'DOCFLG'` and whose `TargetPermanentCode` is **the same
`FlagInstanceID` value** used by company A — the same-code, wrong-company case A-R3 requires. It then
proves, inside a rolled-back transaction:
1. inserting a terminal (`Status='Resolved'`) DOCFLG row for **company A** that points
   `ImportEvidenceRowId` at company B's evidence raises `foreign_key_violation` on
   `FK_DOCFLG_ImportEvidenceRow`, whose fourth column is `Company` — the wrong-company evidence
   cannot bind at all, so it cannot exempt;
2. the same row without any evidence raises `check_violation` on
   `CK_DOCFLG_TerminalResolutionEvidence` — proving the exemption, not some other predicate, is what
   the evidence would have satisfied;
3. the positive control: the identical row with **company A's own** evidence inserts successfully.

Together these assert that the exemption is company-isolated, not merely inspected as such. This also
satisfies proof-pattern rule 2 (cross-company negatives) for the only company-scoped object Piece A
touches.

### 20 · A-R4 (Low) — the catalog/uniqueness proof asserts everything status claims

**One New Disposable test — the direct accepted-versus-first-`Up` comparison:**
`P11aDisposableDatabaseTests.Piece_a_accepted_import_evidence_uniqueness_and_indexes_are_identical_from_accepted_to_first_up`
migrates to `20260805180000_P11aFdrSchema`, captures every `ImportEvidenceRow` unique constraint by
name and `pg_get_constraintdef` plus every `pg_indexes` definition on that table, migrates `Up`, and
asserts the captured sets are **identical** — the comparison Reject #1 recorded as missing. It asserts
the accepted uniqueness definitions **by exact definition text**, covering:
- `UNIQUE NULLS NOT DISTINCT ("ImportBatchId","SourceTable","SourcePermanentCode")`
- `UNIQUE NULLS NOT DISTINCT ("ImportBatchId","SourceTable","SourceRecordKey")`
- `UNIQUE ("Id","TargetTable","TargetPermanentCode")`
- `UNIQUE ("Id","CompanyCode","TargetTable","TargetPermanentCode")`

**One Strengthened Disposable helper, widening item 15's two equalities:**
`P11aDisposableDatabaseTests.PieceACatalogSnapshot` (used by
`Piece_a_down_is_exact_and_up_down_up_is_catalog_stable`) gains, for the touched objects
`ENTMST`, `DOCEFL`, `DOCFLG` and `ImportEvidenceRow`:
- **column store types** — `data_type` and `character_maximum_length` added to the existing
  nullability/generated/expression lines, for all eight already-listed touched columns
  (`DirectDebit`, `TaxIdVerificationStatus`, `ItemClass`, `ReviewPriority`, `BlockingLevel`,
  `ResolutionEvidence`, `ImportEvidenceRowId`, `ImportTargetTable`);
- **indexes** — every `pg_indexes.indexdef` for those four tables, which the helper omitted entirely.

Both existing equality assertions (accepted equals post-`Down`; first `Up` equals second `Up`) then
run over that wider surface without any change to their own wording.

**Status-wording obligation (documentation, not a test):** the attempt-#2 status record will claim
exactly this surface — accepted `ImportEvidenceRow` uniqueness and indexes asserted identical from
accepted to first `Up`; column store types and indexes included in the Up/Down/Up comparison for the
four touched tables — and will claim **no** role, ACL, function or whole-catalog proof, because Piece A
creates none and none is asserted. Under proof-pattern rule 1 an overstated claim is a defect even
where the code is correct.

### Test inventory this mapping commits to

| Surface | New | Strengthened | Existing regression re-run |
|---|---:|---:|---:|
| Validator (ordinary) | 4 | 1 | all existing `RegistryValidationServiceTests` methods |
| Contract (ordinary) | 1 | 1 | `Piece_a_sql_is_schema_only_and_exactly_scoped` |
| Fixture (ordinary) | 0 | 0 | `Authored_shapes_use_honest_nulls_and_no_placeholder_literals` |
| Disposable | 3 | 1 helper (`PieceACatalogSnapshot`) + the test that uses it | the other Piece A and accepted P11a disposable tests |
| Verification command | 0 | 0 | preflight checks 1–6; base-to-candidate path list; accepted-migration blob IDs |

**No suite-count projection is recorded.** The gate does not require one, and a projected total would
mix the ordinary and disposable surfaces, which run under different commands. Under proof-pattern
rule 1 the attempt-#2 record states measured counts only, after implementation.

### Two observations reported, not resolved

1. **"Both" versus four accepted `ImportEvidenceRow` unique constraints.** A-R4 requires a direct
   comparison of *"both accepted `ImportEvidenceRow` unique-constraint definitions"*. The accepted
   P1-1a DDL declares **four** UNIQUE constraints on that table (the two `NULLS NOT DISTINCT` source-key
   constraints and the two target-identity constraints, `P11aSchemaSql.cs` lines 541–543). Rather than
   guess which two amendment 5 means, item 20 asserts **all four** by name and definition; that is a
   strict superset of either reading and adds no content change. Reported here for the record.
2. **Store-type parity scope.** The EF model maps string columns as `text` project-wide; item 18
   corrects that for the six columns Piece A adds or alters and no others, because a wider correction
   would exceed A-R1…A-R4. If Miguel wants project-wide store-type parity it needs its own
   authorization; it is not in attempt #2.

### What this test-plan step did not do

No implementation, migration, model, validator, fixture, test, importer or Scope 1 work: not one line
of code was written, and no candidate content was restored, checked out, cherry-picked or edited.
Candidate `6f86023d…` and its tests were inspected **read-only through Git history** (`git show`,
`git diff`, `git log`) exactly as authorized. No amendment-4 prototype preflight was run and no
post-pin prototype content was read. No prototype read, write, fetch or checkout of content; no
database, container, service, deployment or live-data action, disposable or otherwise; no history
rewrite — no amend, reset, rebase, revert or force push. Piece B, Piece C, Piece D and Scope 1 remain
gated and unstarted, and Piece A still has no accepted implementation.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Candidate/history access mode | read-only `git show` / `git diff` / `git log` only |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. The last independently reproduced figures
remain those of the Reject #1 record below.

### Gate statement — Miguel's decision is required before implementation

This mapping is submitted under amendment 5's test-plan gate. **Piece A attempt #2 implementation
remains unauthorized until Miguel records an explicit approval of this mapping**; the instruction to
record it is not approval of it. Requested decision: **approve**, **reject**, or **return with
corrections** — in particular on the two reported observations above, on whether the four new
validator tests and two new check identifiers are the intended shape of the A-R1 gate, and on whether
the six-column store-type scope in item 18 is the intended reading of *"every column Piece A adds or
alters"*.

## 2026-08-06 O10 amendment 5 governed records — Piece A attempt #2 authorized as a remediation

Miguel accepts `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-5.md` in full. The prompt is already
tracked and pushed at `ccc9146fa64c1882bf94899538c7abb982882b62`; it is not duplicated or rewritten
merely to force an unchanged path into this commit. This step performs **ordered instruction 1
only** — the governed records commit. It does not perform ordered instruction 2 (the test-plan
mapping), ordered instruction 3 (attempt #2 implementation), or ordered instruction 4 (the focused
re-review).

Amendment 5 reopens no decision and changes no baseline. O8-D1/D2, O9-P, O9-D1…D5, O10-D1/D2,
amendment 3's four-piece decomposition, and amendment 4's reformulated preflight all remain in force
unchanged. The five expected completeness baselines remain **119 / 119 / 52 / 221 / 2,787**, the two
pinned `Routine` rows still import verbatim, and the immutable source pin remains
`b91768513fc638381fbde91f0b576b08220a98f6`. The monolithic rejects `b324a3e…`, `57f0f023…`, and
`7ea6c0f…` remain neutralized evidence only, never resurrected, not even in part. O5 remains the
project's only other open item.

### What Reject #1 established

The Reject #1 record in `docs/p1-1b-o10-independent-review.md` disposes **13 of 16 requirement rows
as Pass** against the exact records-base-to-candidate diff, with **0 Critical** and four narrow
findings: one behavioral (the identity-class validator gate for unknown non-null `ItemClass` is
absent) and three of proof (EF store-type parity, the wrong-company evidence test, and status claims
exceeding their assertions).

Miguel's recorded diagnosis is that the High finding's root cause is a **specification-integration
failure, not a design failure**: the identity-class validator gate is a standing amendment-2
requirement that amendment 3's Piece A list did not restate, despite amendment 3's promise that
every open finding is assigned to exactly one piece. Amendment 5 assigns it explicitly to Piece A.

### Remediation basis — piece candidates may be remediated, monoliths may not

The never-resurrect rule continues to bind `b324a3e…`, `57f0f023…`, and `7ea6c0f…` **by name and in
full**. For **piece** candidates under amendment 3, where a Reject records **0 Critical** and an
enumerated requirement-by-requirement disposition table, the reattempt is a **remediation of the
rejected candidate**, not a from-scratch rewrite: it takes the rejected candidate's content as its
base and applies exactly the named remediations and nothing else. The recorded rationale is that the
review confirmed the passing surfaces against the exact diff, so rewriting them from zero re-rolls
implementation variance on proven ground — the failure mode the decomposition exists to eliminate —
and doubles the review burden. The guard is the re-review scope below. This basis applies to Piece A
attempt #2 now and to future piece reattempts meeting the same two conditions; it never applies to
the three named monolithic rejects.

Piece A attempt #2 therefore starts from candidate `6f86023dce83ffc02f2a0a66c14cbbdde3e55236`, whose
implementation content is neutralized at the branch tip and preserved as evidence in history.

### Binding remediations A-R1…A-R4

| # | Binding requirement | Required proof |
|---:|---|---|
| **A-R1 (High)** | `RegistryValidationService` enforces the closed D8 `ItemClass` vocabulary: any **non-null** value outside the closed vocabulary produces an identity-class failure, fail-closed, for **DOCEFL rules and DOCFLG snapshots, imported and native alike**. The database CHECKs remain an independent second barrier, never the gate. | Four validator tests — DOCEFL and DOCFLG, imported and native each — proving an unknown non-null value (e.g. `Invented`) fails closed at the validator; plus the existing null-observation behaviour unchanged. |
| **A-R2 (Medium)** | The EF model and snapshot map `DOCFLG.ImportTargetTable` with its actual store type `varchar(32)`, generated/stored expression included — the model matches the SQL catalog **exactly**, store type and all. | A test comparing the EF relational store type against the disposable-database catalog for **every column Piece A adds or alters**, not only the expression/stored flags. |
| **A-R3 (Medium)** | The imported terminal-evidence exemption is proven company-isolated, not only inspected. | A disposable test creating same-code `ImportEvidenceRow` evidence for **another company** and proving it cannot exempt a terminal DOCFLG row. |
| **A-R4 (Low)** | The catalog/uniqueness proof asserts everything its status claims — or the claim is narrowed to what is asserted. | A direct accepted-versus-first-`Up` comparison of **both** accepted `ImportEvidenceRow` unique-constraint definitions, and inclusion of indexes and column store types for touched objects in the compared catalog surface. Status wording may not exceed the assertions. |

**The attempt-#2 checklist is the Reject #1 disposition table plus A-R1…A-R4.** Every row recorded
Pass must still pass on the new diff; the Partial/Fail rows convert to Pass through the remediations
above. **No other change to the candidate's content is authorized**; an apparent need for one is a
stop-and-report, not a judgment call.

### Second and final pre-escalation attempt

Amendment 3's rule that a piece rejected twice stops and escalates to Miguel is unchanged and now
binds concretely: attempt #2 is the **second and final Piece A attempt before escalation**. A second
Piece A Reject stops everything — no third attempt is authorized — and escalates to Miguel, after
the amendment-3 neutralization is performed exactly as defined.

The re-review scope for attempt #2 is a **focused independent review**: full adversarial depth on
A-R1…A-R4 and their proofs, plus regression confirmation against the new exact diff that every
disposition row recorded Pass in Reject #1 still holds. An explicit Accept/Reject verdict is recorded
as always. On Accept the work stops and reports; Piece B still needs its own go-ahead.

### Consolidated checklist discipline — binding for attempt #2 and for Pieces B, C, D

Each piece's go-ahead must carry **one numbered, exhaustive checklist** merging every applicable
requirement from every standing amendment. The implementer's evidence map and the reviewer's
disposition both key to that checklist and to nothing else. If an implementer or reviewer finds a
standing requirement absent from the checklist, that is a **stop-and-report** — never silently
satisfied, never silently skipped. For attempt #2 the checklist is the one defined above; the
checklists for Pieces B, C, and D are authored with their go-aheads and may be pre-drafted for
Miguel's approval while a prior piece is under review.

### Proof-pattern annex — binding on every piece from this amendment forward

1. **Claims equal assertions.** Every proof asserts exactly the state its status record claims; an
   overstated claim is a defect even when the code is correct.
2. **Cross-company negatives.** Every company-scoped object, predicate, or exemption gets a negative
   test proving the wrong-company case fails.
3. **Store-type parity.** Every column a piece adds or alters — generated columns especially — gets
   an EF-versus-catalog store-type comparison test.
4. **"Unchanged" is asserted, not assumed.** Every claim that an accepted object is untouched gets a
   direct catalog assertion comparing accepted definitions with post-`Up` state.
5. **Vocabularies close twice.** Every closed vocabulary is enforced at the database **and** at the
   validator, with unknown-value fail-closed tests covering imported and native rows.

### Test-plan gate — binding on every piece from this amendment forward

After the governed records commit and **before any implementation code**, the implementer records
the checklist→test mapping — a numbered list mapping each checklist item to the exact test(s) that
will prove it — in this file and submits it to Miguel for a quick approval. **Implementation starts
only after that approval.** For attempt #2 this is a short delta list, and it is still required. The
gate exists because all four Reject #1 findings were visible at test-plan level before a line of
code was written.

**That mapping is deliberately not written in this commit.** This step is ordered instruction 1
only; the mapping is ordered instruction 2. Piece A attempt #2 implementation remains gated on the
separate test-plan mapping and Miguel's explicit approval of it.

### PROJECT-STATE repair, the recorded process finding, and one reported contradiction

Amendment 5 records a process finding that `docs/PROJECT-STATE.md` was not updated for amendment 3,
amendment 4, the amendment-4 preflight pass, or the Piece A candidate/Reject #1/neutralization
cycle, and orders those repairs in this commit.

**Verified against the real history, that premise is stale, and the contradiction is reported rather
than resolved silently.** The repairs amendment 5 names were already made in earlier commits:

- `bc835f7e11fa3d7e7c95b0f0d26730f4508833e1` updated the header, the P1-1b phase row, and added the
  changelog entry *"O10 amendments 3 and 4 accepted; Piece A authorized at reformulated preflight"*,
  including the recorded live tip `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` and the two post-pin
  commits `1e841a4` and `3dd4150`.
- `f3ea530aad8bdbac98173e6f429255480be47711` updated the header and the P1-1b phase row — including
  the statement that amendment 4's reformulated preflight passed without reading or adopting post-pin
  content — and added the changelog entry *"Piece A candidate `6f86023d…` independently rejected and
  neutralized — Reject #1"*.

What was genuinely missing is the amendment-5 record itself, because `ccc9146f…` tracked only the
prompt file. This commit therefore makes the amendment-5 header, O10 decision-row, phase-row,
"Still not authorized", and changelog repairs, and records the amendment-3/4/Reject-#1 repairs as
already present rather than duplicating them. Historical entries are preserved verbatim; no closed
decision or baseline is touched.

The binding rule amendment 5 introduces is adopted unchanged and applies from now on: **every
records commit that changes `docs/p1-1b-status.md` or `docs/p1-1b-o10-independent-review.md` must
update `docs/PROJECT-STATE.md` in the same commit**; a records commit that leaves them contradictory
is itself a defect. This commit satisfies that rule.

### Parallel O5-prep

Miguel green-lights running `docs/AGENT-PROMPT-v5-P1-2-o5-prep.md` **in parallel** with Piece A
attempt #2, under its own authority, on its own disjoint branch and file surface. Its
file-surface disjointness rule stands: needing to touch a P1-1b file is a stop-and-report. No
O5-prep work is performed or reported by this records step, and O5 remains open.

### What this records step did not do

No test-plan mapping, implementation, migration, model, validator, fixture, test, importer, or
Scope 1 work. No prototype read, write, fetch, or checkout, and no post-pin prototype content of any
kind. No database, container, service, deployment, or live-data action, disposable or otherwise. No
history rewrite: no amend, reset, rebase, revert, or force push. Piece B, Piece C, Piece D, and
Scope 1 remain gated and unstarted, and Piece A still has no accepted implementation.

### Verification of this records stage

| Verification | Result |
|---|---:|
| Changed paths in this commit | exactly **2** — `docs/p1-1b-status.md` and `docs/PROJECT-STATE.md` |
| Implementation, migration, model, fixture, or test paths changed | **0** |
| `git diff --check` | clean |
| Local documentation links referenced by the new records | **0 missing** |
| Prototype repository operations | **0** |
| Disposable, shared, or live database and container operations | **0** |

No build or test figures are claimed for this stage: it changes documentation only, touches no
compiled or test path, and no build or suite was run in it. Under proof-pattern rule 1 the record
states exactly what was asserted. The last independently reproduced figures remain those of the
Reject #1 record and its post-neutralization proof below.

## 2026-08-06 Piece A independent review — Reject #1 and neutralized

Fresh independent adversarial review of pushed candidate
`6f86023dce83ffc02f2a0a66c14cbbdde3e55236` against records base
`bc835f7e11fa3d7e7c95b0f0d26730f4508833e1` returns **Reject: 0 Critical, 1 High,
2 Medium, 1 Low**. The complete versioned verdict is
`docs/p1-1b-o10-independent-review.md`.

The High blocker is the missing validator fail-closed gate for unknown non-null D8 `ItemClass`
values: the database rejects the tested DOCEFL value, but imported/native DTO rows with an unknown
DOCEFL or DOCFLG value produce no validator identity failure. The Medium findings are EF/catalog
drift for the new generated `DOCFLG.ImportTargetTable` store type (`text` in the model versus
`varchar(32)` in SQL) and missing mandatory other-company evidence rejection coverage. The Low
finding is an overstated catalog/accepted-uniqueness proof whose helper omits store types/indexes
and never compares accepted uniqueness directly with first Up.

Independent reproduction passed build at 0 warnings/errors, focused 32/32, ordinary 632/632, and
disposable PostgreSQL 13/13; it also independently re-proved the effective amended prototype
roster 49/49 with zero mismatches, pinned JSON surface 48/48 with zero delta, genuine 119/119 NULL
round trips including entirely unreferenced entities, clean whitespace/risk scans, and zero
residual `sibyla-p11*` containers. These green results do not waive the findings.

The normal branch-tip stop commit restores exactly the 12 Piece A implementation/model/test paths
changed by `6f86023d…` byte-for-byte to `bc835f7e…`; its three candidate-added paths are absent.
The amendment-4 records, candidate record, this Reject record, and current-state record are
preserved. This is **Piece A Reject #1**. No remediation is performed, and Piece B, Piece C,
Piece D, and Scope 1 remain gated and unstarted. O8/O9/O10 stay closed; baselines
119 / 119 / 52 / 221 / 2,787 and the two future `Routine` rows are unchanged.

Post-neutralization proof: exact implementation roster **12**, mismatches against `bc835f7e…`
**0**, candidate-added paths present **0**; build **0 warnings/errors**; ordinary suite **629/629**;
accepted disposable PostgreSQL suite **10/10**; residual `sibyla-p11*` containers **0**.

## 2026-08-06 Piece A candidate — schema completeness and honest validator observation

This section records the fresh Piece A implementation candidate requested under ordered
instruction 2 of O10 amendment 4. It is a candidate for the mandatory independent review, not an
independent verdict. This pass stops after implementation, verification, commit, and push; it does
not perform or invent the independent review and does not start Piece B, C, D, or Scope 1.

### Records-base and reformulated prototype preflight

Before any implementation edit, Sibyla was clean on `feature/p1-1b` at required pushed records
base `bc835f7e11fa3d7e7c95b0f0d26730f4508833e1`. Local `HEAD`, its upstream, and live
`refs/heads/feature/p1-1b` were equal; divergence was `0 0`; the required base was an ancestor of
`HEAD`.

The prototype check used only metadata, `git fetch`, `git cat-file`, `git ls-tree`, `git log`, and
`git merge-base`. No floating worktree content was read. Reformulated checks 1–5 all passed:

1. pin `b91768513fc638381fbde91f0b576b08220a98f6` resolved before and after the remote fetch;
2. the pin was an ancestor of fetched and live `main`;
3. local prototype `HEAD` equalled the pin;
4. all **49/49** roster blobs resolved at the pin with **0** hash mismatches;
5. the pinned direct `Editor/Data` surface held **48** rostered JSON files with **0** surface delta.

Check 6 recorded live tip `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` and exactly these
post-pin commit metadata records:

- `1e841a4f9a88cd6a5e90e6632dff54185be9949e` — `Complete Stage 10 Round 8 reconciliation and mapping updates`
- `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54` — `Apply Stage 10 Round 8 revenue review updates`

**No post-pin content was read or adopted.** No post-pin file content, count, code, mapping, or
value informed the migration, model, fixture, validator, tests, or this record beyond the required
hash-and-subject divergence log.

### Candidate surface

Piece A is one additive migration, `20260806180000_P11bPieceASchemaCompleteness`, plus the EF model,
validator observation surface, the O8 fixture correction, and tests. The accepted
`20260805180000_P11aFdrSchema` files are byte-untouched. There are no roles, grants,
`SECURITY DEFINER` functions, governed commands, importer, shared/live database action, deployment,
prototype write, or Piece B/C/D content.

The migration implements O9-D1/D2/D3 nullability, both exact six-literal `ReviewPriority` CHECKs,
O9-D5's imported terminal-evidence exemption through the existing `ImportEvidenceRow` identity,
and O10-D1's nullable snapshot, retained composite `MATCH SIMPLE` FK, plain `EFCode` FK, and
prospective complete-snapshot CHECK. `DOCFLG.ImportTargetTable` is generated in PostgreSQL and is
modelled as generated/stored in the runtime model and EF snapshot. The accepted authored fixture
uses `EF0000053`, not historical `EF0000046`.

### Requirement-to-test evidence map

| Requirement | Direct proof |
|---|---|
| O9-D1/D2/D3 nullability; exact six priorities; O9-D5; O10-D1 DDL; no roles/functions/commands | `P11bPieceAContractTests.Piece_a_sql_is_schema_only_and_exactly_scoped` |
| Nullable EF metadata and generated-column alignment | `P11bPieceAContractTests.Piece_a_nullable_and_generated_columns_are_modelled_truthfully` |
| Imported NULL snapshot accepted; native incomplete snapshot rejected; imported terminal evidence exemption; native terminal evidence required | `P11aDisposableDatabaseTests.Piece_a_database_constraints_enforce_honest_history_and_prospective_completeness` |
| Plain `EFCode` FK remains binding when the composite FK self-exempts; retained composite FK is `MATCH SIMPLE`; all six and only six priority literals; unknown non-null `ItemClass` rejected | same database semantic test |
| R5 genuine PostgreSQL NULL → `PostgresRegistryValidationSnapshotSource` → DTO/validator preservation | `P11aDisposableDatabaseTests.Piece_a_validator_round_trips_119_unreferenced_imported_entity_nulls` |
| ENTMST full imported population, 119/119 counts, including entities with no FDCHDR/FDCDTL reference | same database round-trip test; all 119 fixture entities are unreferenced and still selected/countable |
| Five named honest-history observations | `RegistryValidationServiceTests.Piece_a_reports_all_five_honest_historical_completeness_findings` |
| O8 fixture `EF0000046` → `EF0000053` before seeding | `P11aAuthoredRowFixtureTests.Authored_shapes_use_honest_nulls_and_no_placeholder_literals` and the disposable authored-row assertion |
| Exact scoped `Down`; Up/Down/Up catalog stability; accepted `ImportEvidenceRow` uniqueness unchanged | `P11aDisposableDatabaseTests.Piece_a_down_is_exact_and_up_down_up_is_catalog_stable` |

The full-scope ENTMST fixture uses separate synthetic import batches because the accepted
`ImportEvidenceRow` uniqueness definitions are deliberately left exactly untouched; the validator
selects the full company/import-evidence population across batches rather than deriving entities
through FDCHDR/FDCDTL.

### Measured candidate verification

| Verification | Measured result |
|---|---:|
| `dotnet build GOTT.Sibyla.slnx --no-incremental` | succeeded; **0 warnings, 0 errors**; 16.61 s |
| Piece A + validator + authored-fixture focused tests | **32 passed, 0 failed, 0 skipped** |
| ordinary `dotnet test ... --no-build` | **632 passed, 0 failed, 0 skipped**; 15 s test duration |
| full disposable PostgreSQL 17 suite | **13 passed, 0 failed, 0 skipped**; 12 s test duration |
| genuine ENTMST NULL/count proof | **119 DirectDebit NULL / 119 tax-status NULL**, read through the production PostgreSQL source; 119 rows had no FDCHDR/FDCDTL reference |
| Up/Down/Up and exact scoped Down | passed; accepted catalog restored exactly and first/second Up snapshots equal |
| residual `sibyla-p11*` containers | **0** |

No imported production baseline was measured because Scope 1 has not run. The governed expected
baselines remain **119 / 119 / 52 / 221 / 2,787**, and the two pinned `Routine` rows remain a future
Scope 1 import measurement. The candidate commit is the commit containing this self-referential
status section; its full SHA is recorded in the review handoff rather than invented inside its own
content.

## 2026-08-06 O10 amendment 4 governed records — live-source preflight reformulated

Miguel accepts `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-4.md`. The prompt is already tracked in
this records stage's base commit, `0077e2d5c61bdf5e2712d3562719cb7dac54250c`, and is not rewritten
merely to include it in this commit. Amendment 4 supersedes amendment 2's frozen-tip prototype
preflight shape only; it reopens no decision and changes no baseline. O8-D1/D2, O9-P,
O9-D1…D5, O10-D1/D2, the five expected completeness baselines
**119 / 119 / 52 / 221 / 2,787**, the two verbatim `Routine` rows, and O5 are unchanged.

The 2026-08-06 Piece A preflight stopped correctly before Piece A changed anything. Its findings
were:

- Prototype local `HEAD` remained the immutable pin
  `b91768513fc638381fbde91f0b576b08220a98f6`.
- Prototype local `origin/main` and live `refs/heads/main` had advanced to
  `3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`, so the former all-tips-equal check failed.
- The pin remained reachable and was an ancestor of the live tip; no history rewrite was found.
- The two post-pin commits, recorded as metadata only, were:
  - `1e841a4` — `Complete Stage 10 Round 8 reconciliation and mapping updates`
  - `3dd4150` — `Apply Stage 10 Round 8 revenue review updates`
- The preflight changed no Sibyla or prototype content and performed no implementation, migration,
  fixture, test, database, container, service, deployment, or live-data action.

Amendment 4 replaces the permanently unsatisfiable frozen-tip equality requirement with six
snapshot-integrity checks. Checks 1–5 remain mandatory stop conditions: pin reachability, pin
ancestry of live `main`, local clone `HEAD` anchored at the pin, 49/49 roster integrity at the pin,
and the exact 48-file direct `Editor/Data` surface at the pin. Check 6 makes forward divergence a
recorded finding rather than a stop. The complete check-6 divergence record is: live tip
`3dd4150caef7e3a1d2a77c5fa34361d2aefe4c54`; post-pin commits and subjects exactly as listed above;
**no post-pin content was read or adopted**. No file content, count, code, mapping, or value from
either post-pin commit informed any Sibyla artifact.

Piece A is now authorized under amendment 3, but may begin only after a fresh read-only preflight
passes reformulated checks 1–5. Pieces B, C, and D remain ordered behind their predecessor's
independent Accept verdict. Scope 1 remains unstarted and, after Piece D's Accept, is additionally
gated by Miguel's explicit confirm-pin-or-re-pin checkpoint. This governed-records step performs
only ordered instruction 1; it does not run the reformulated preflight or begin Piece A.

## 2026-08-06 amendment-2 step 4 — third independent verdict Reject

Fresh independent adversarial review of pushed candidate
`7ea6c0f16ce5c9328b881d5abec3c74b44063000` returned **Reject: 0 Critical, 2 High,
4 Medium, 1 Low**. The complete findings, requirement-by-requirement disposition, coverage audit,
and positive confirmations are prepended to `docs/p1-1b-o10-independent-review.md` while both prior
rejection records remain intact.

The High blockers are bypassable provenance cardinality/value/hash integrity (including stale
`absent` provenance after accepted `WaiveDOCFLG`) and a global assignment command that writes
companies outside the authenticated company boundary and can omit affected inactive-company
audits. Medium findings are incomplete ENTMST population/count scope, absence of the mandated real
NULL database round trip, an incomplete exact-catalog proof, and generated-column/model-snapshot
misalignment. The Low finding is that only one of R3's two mapped orderings is genuinely
concurrent.

The normal additive stop commit containing this record restores all **15** implementation
code/test/migration/model paths changed by `7ea6c0f…` byte-for-byte to records parent
`01c92cb2d214331a0b32de8a571031e7200125c9`; the implementation evidence-map edit is superseded by
this review record. O9-P/D1…D5, O10-D1/D2, the 119 / 119 / 52 / 221 / 2,787 baselines, and the two
verbatim `Routine` rows remain governed and unchanged.

This is the **third Reject**. Amendment 2 therefore stops every further reimplementation pending
Miguel's review of the pattern itself. Scope 1 has not run and is not authorized to restart. No
prototype, shared/live database, service, deployment, or live-data action occurred in this review.

## 2026-08-06 O10 amendment 2 governed records — second-review findings accepted

Miguel's `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment-2.md` is already tracked at this
records stage's base commit, `a570643c1133a6470f9b0b26ab1e7046e5db71a3`; it is not rewritten
merely to include it in this commit. The host and prototype read-only preflights were completed
before this records work exactly as recorded in the amendment-2 assignment. The prototype is not
touched or re-checked out by this step.

The second independent review's seven findings are accepted in full as binding requirements
**R1–R7** for the third, fresh step-3 implementation. The review's four missing-coverage items are
also binding and require explicit disposable-suite proof. O10-D1/D2 and O9-P/D1…D5 remain closed
and unchanged. Rejected commits `b324a3e…` and `57f0f023…` remain neutralized evidence only and
must never be resurrected or cherry-picked.

### Binding minimal-surface discipline

- The corrective migration is strictly additive against the accepted P1-1a catalog. It may not
  alter, drop, re-own, or replace any accepted table, constraint, index, function, role, ownership,
  or ACL unless a numbered standing or amendment-2 requirement explicitly names that exact change.
- An apparent need to touch an unnamed accepted object is a design contradiction and requires an
  immediate stop-and-report; it is not authority to adapt.
- `Down` removes exactly and only what `Up` added and restores the accepted catalog exactly.
- No DTO, validator, command, or fixture may invent a value, default, or provenance marker that no
  governing decision authored.

### R1–R7 — binding remediation requirements

| # | Binding requirement | Required proof |
|---:|---|---|
| **R1 — fail-closed role provisioning** | Grant ownership, DML, or `SECURITY DEFINER` reachability only to roles created by the migration itself; fail closed if an expected role name already exists. | A hostile pre-existing-role test proves `Up` refuses, and the normal path proves the roles are created rather than reused. |
| **R2 — exactly-inverse `Down`** | Perform no `DROP OWNED`, change no ownership of an object the migration did not create (including `WaiveDOCFLG`), and restore any necessarily recreated accepted function byte-exactly. | A before-`Up` versus after-`Down` `pg_catalog` snapshot proves exact equality for objects, owners, ACLs, names, indexes, constraints, and function definitions, plus an Up/Down/Up cycle. |
| **R3 — assignment/import serialization** | Serialize governed rule assignment and import on the parent DOCEFL rule so no post-assignment NULL snapshot survives outside the audited completion count. | Two concurrency tests prove both orderings and the exact audited count. |
| **R4 — provenance integrity** | Constraint-enforce target FK, target-company agreement, exact one-row cardinality for each governed snapshot member, and `absent` only when the governed value is NULL. | Schema-level tests reject missing, orphan, wrong-company, and value/provenance-contradictory rows. |
| **R5 — no invented validator values** | Preserve NULL as NULL and require explicit values elsewhere; no implicit `false`, `Verified`, or `Annotation`. | Round-trip tests prove NULL survives unchanged and an unspecified required member errors instead of defaulting. |
| **R6 — accurate audit scope and content** | Audit every affected company with its exact completion count and include the governed appended evidence value/hash. | Multi-company assignment and evidence-append tests prove complete company/count and value/hash audit content. |
| **R7 — accepted uniqueness untouched** | Preserve the accepted `ImportEvidenceRow` uniqueness constraints exactly in name, definition, and semantics. | A post-`Up` catalog assertion proves those accepted constraints are unchanged. |

The four explicit coverage obligations are: unknown non-null DOCFLG snapshot `ItemClass` fails
closed on both imported and non-imported rows; the hostile pre-existing-role case for R1; exact
post-`Down` catalog equality for R2; and both assignment/import concurrency orderings for R3.
Each obligation needs its own mapped proof; aggregate green tests do not substitute for it.

No governed baseline changes. `ENTMST.DirectDebit absent` remains **119**;
`ENTMST.TaxIdVerificationStatus unverified` remains **119**; `DOCEFL.ItemClass unassigned`
remains **52**; `DOCFLG terminal without ResolutionEvidence` remains **221**; and
`DOCFLG snapshot ItemClass absent` remains **2,787**. The two source rows using
`ReviewPriority = Routine` still import verbatim. The closed O7 `CaptureQuality` rule is unchanged:
historical NULL / `absent` rows produce no finding, while non-imported missing values do.

This is a governed-records step only. It performs no implementation, test, fixture, migration,
prototype, database, container, service, deployment, or live-data work. Scope 1 and Scopes 2–8
remain unstarted. Amendment-2 step 3 is pending and must begin fresh from this pushed records tip;
O5 remains the project's only open item.

## 2026-08-06 O10 step-4 stop — independent verdict Reject

Mandatory independent review of pushed implementation
`57f0f023bb1ff1d117b5767103bf4df310fb4a98` returned **Reject: 0 Critical, 4 High, 3
Medium**. The complete verdict, findings, missing Low coverage, and positive confirmations are
recorded in `docs/p1-1b-o10-independent-review.md`.

The normal additive stop commit containing this section restores exactly the 14
code/test/migration/model paths changed by `57f0f023…` byte-for-byte to its records parent
`15679e78`. Newly added files are removed and modified surrounding model/test files are restored;
the accepted P1a migrations remain untouched. This is neutralization, not remediation: no reset,
amend, rebase, force-push, or history rewrite is used.

O10-D1/D2 remain closed and the governed **2,787** `DOCFLG snapshot ItemClass absent` baseline is
unchanged. The rejected implementation is evidence only. Scope 1 has not started, and no
database, container, service, deployment, live-data, or prototype work is authorized or performed
by this stop. Work stops at the O10 amendment step-4 Reject gate.

## 2026-08-06 O10 governed records amendment — O10-D1 and O10-D2

Miguel's `docs/AGENT-PROMPT-v5-P1-1b-o10-amendment.md` is already tracked at this records
stage's base commit, `7280236c21f480fa28b652591bc3ad5091349d0d`. This commit records its
decisions and binding remediation requirements; the governing prompt is not rewritten, duplicated,
or history-rewritten merely to force an unchanged path into this commit.

The host-verified mandatory preflight passed before this records work: Sibyla local `HEAD`, its
upstream, and live `refs/heads/feature/p1-1b` were all
`7280236c21f480fa28b652591bc3ad5091349d0d` with a clean worktree. Prototype local `HEAD`, local
`origin/main`, and live `refs/heads/main` were all immutable pin
`b91768513fc638381fbde91f0b576b08220a98f6`; all 49 roster paths resolved with zero blob
mismatches, and the direct `Editor/Data` surface was exactly the 48 rostered JSON files. No
prototype write or database, container, service, deployment, or live action occurred.

### O10-D1 — absence snapshots as absence

A DOCFLG snapshot records the governed state at detection or import. When an imported DOCEFL
rule's `ItemClass` is honest SQL `NULL` / `absent` under O9-D3, its imported DOCFLG instances
therefore carry nullable snapshot `ItemClass = NULL` with provenance `absent`; no class is
invented to satisfy a constraint.

The accepted composite FK `(EFCode, ItemClass, ReviewPriority, BlockingLevel)` remains declared.
Under SQL `MATCH SIMPLE` semantics, a composite-FK row with any NULL member is not checked, so the
FK binds every fully-valued snapshot and self-scopes away from honest historical absence. Because
that makes the composite FK vacuous for such history, a mandatory plain FK on `EFCode` alone to
DOCEFL must exist, ensuring every DOCFLG instance still resolves to its rule.

The exemption is prospective-only. A new CHECK uses the existing import marker and requires
`Imported = true OR (ItemClass IS NOT NULL AND ReviewPriority IS NOT NULL AND BlockingLevel IS NOT
NULL)`. Every non-imported Sibyla-era detection must therefore carry a complete snapshot and is
fully enforced by the composite FK.

The new named non-blocking data-quality finding is **`DOCFLG snapshot ItemClass absent`**, with
expected baseline **2,787**: every imported instance, because all 52 imported parent rules are
unassigned at import. This is measured at import; a different measured value is recorded and
flagged, not treated as a stop.

### O10-D2 — atomic NULL-only snapshot completion

When the governed `AssignDOCEFLItemClass`-shaped command assigns a rule's `ItemClass`, that same
atomic, audited, actor-stamped operation also completes only that rule's instance snapshots whose
snapshot `ItemClass` is `NULL`: value NULL → assigned value and provenance `absent` → `authored`.
It must never modify a non-null snapshot; once present, a snapshot value remains immutable under
S2. The audit record states the rule, assigned value, actor, and exact count of completed instance
snapshots. The `DOCFLG snapshot ItemClass absent` finding decreases by exactly that audited count.
This decision authors none of the 52 rule assignments; they remain O9-D3's governed work over time.

### Binding remediation requirements for the fresh reimplementation

The independent review's five findings on rejected `b324a3e…` are accepted in full. That commit
remains neutralized evidence of what failed and is never code to resurrect or cherry-pick. Each
requirement below needs explicit test evidence; green build and aggregate test results alone are
not semantic proof.

| # | Binding requirement | Required proof |
|---:|---|---|
| **1** | Implement O10-D1/D2 so an imported instance may carry a NULL snapshot, while a non-imported instance must have every snapshot member. | Disposable tests prove the imported NULL snapshot inserts and any NULL snapshot member on a non-imported instance is rejected. |
| **2** | No governed command trigger may trust caller-controlled GUCs; authorization binds to the accepted server-side trusted principal keyed by `session_user`. | Run from a non-owner role and prove forged `sibyla.actor` / `sibyla.authorities` values grant nothing. |
| **3** | The terminal-integrity CHECK's `ImportEvidenceRow` predicate is company-scoped and uses the stronger evidence identity already present in the accepted schema. | Prove a same-code evidence row from another company cannot satisfy the predicate. |
| **4** | Migration `Down` drops exactly the names `Up` creates. | A disposable Up/Down/Up cycle succeeds without constraint-name drift. |
| **5** | The closed `ItemClass` vocabulary remains identity-class for every row: an unknown non-null literal fails closed for imported and non-imported rows; only NULL / `absent` is a completeness finding. | Test both imported and non-imported unknown non-null rejection, plus the allowed historical NULL case. |

O10 is closed by O10-D1/D2 and these recorded requirements. This is a decisions-only records
stage: the fresh additive corrective migration, validator scoping/findings, governed commands,
fixture update, importer, and tests are still pending. Step 3 must be reimplemented fresh from the
stop-record tip and independently reviewed before Scope 1 can restart. No P1-1b implementation is
accepted by this record, and Scopes 1–8 remain uncompleted and ordered. O5 is the project's only
open item.

## 2026-08-06 fail-closed step-3 stop — independent verdict Reject; O10 open

O9-P and O9-D1…O9-D5 remain governed and closed. The four named data-quality improvements remain
non-blocking decisions with expected baselines 119 / 119 / 52 / 221; none is reopened by this
stop. Step 3 of the O9 amendment, however, is **not accepted or complete**. Independent review
returned **Reject** on pushed commit `b324a3e40dc663e644aac5b0be566c1a8a915a5a` (`Align P1-1b
import contract`). The normal stop-record commit containing this section neutralizes every tree
change introduced by `b324a3e…` at the branch tip; it does not reset, amend, rewrite history, or
revert the earlier governed-records commit `6e18e1c72f49fffa61c5f9baeffec0682bdd20e9`.

### O10 — historical DOCFLG snapshot/FK representation requires a contract decision

O9-D3 requires all **52 imported DOCEFL rows** to carry honest SQL `NULL` / `absent`
`ItemClass`. The accepted S2/DOCFLG schema simultaneously requires each DOCFLG instance to retain
a **non-null snapshot `ItemClass`** and enforces the composite foreign key
`(EFCode, ItemClass, ReviewPriority, BlockingLevel)` to DOCEFL. Those requirements cannot be
satisfied together for imported historical DOCFLG rows when their referenced imported DOCEFL
parent has `ItemClass = NULL`. The O9 amendment governs nullable DOCEFL history but does not govern
an honest historical DOCFLG snapshot/FK representation.

This is newly exposed contract gate **O10**. It is recorded without choosing a representation.
**Miguel must explicitly reconcile it. Scope 1 and every later scope are stopped until that
decision is recorded.** O5 remains open independently for P1-2 production identity design.

### Independent review findings on rejected `b324a3e…`

| Severity | Blocking finding |
|---|---|
| **High** | O9-D3's 52 imported DOCEFL `ItemClass = NULL` rows cannot back the accepted non-null DOCFLG snapshot through the existing four-column composite FK. |
| **High** | The governed command trigger trusted caller-controlled transaction-local GUC values; the database test exercised the owner session only, so it did not prove the non-owner execution boundary and allowed a command-boundary bypass. |
| **High** | The `ImportEvidenceRow` predicate used by the DOCFLG terminal-integrity CHECK matched only target table and permanent code, without company scope or the stronger evidence identity already present in the accepted schema. |
| **Medium** | `Down` recreated constraint names that did not match the names `Up` expected to drop, so an Up/Down/Up cycle drifted and could fail. |
| **Medium** | The validator rejected unknown `ItemClass` only for non-imported DOCEFL rows; an imported unknown non-null literal escaped the closed D8 vocabulary gate. |

The green build and tests on `b324a3e…` were insufficient semantic proof. These implementation
defects must be corrected only after Miguel decides O10; no replacement migration, validator
change, command surface, importer, reconciliation, or further scope work is authorized by this
record.

No migration or import ran outside disposable tests, and no shared/live database action,
container, service, deployment, live-system action, or prototype write occurred in this pass. The
rejected migration was exercised only in disposable tests and was never applied to a shared or
live database. Step 3 and Scope 1 are stopped, not accepted, deployed, or imported; Scopes 2–8
remain unstarted.

## 2026-08-06 O9 governed records amendment — O9-P and O9-D1…O9-D5

Miguel's `docs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md` is already tracked at this records stage's
base commit, `3dd8fa729964e3ed8f7eb4c050c5097501b71fee`. This commit records and applies its documentation
decisions; the governing prompt is not rewritten, duplicated, or history-rewritten merely to force
an unchanged path into a later commit.

The host-verified mandatory preflight passed before this records work: Sibyla local `HEAD`, its
upstream, and live `refs/heads/feature/p1-1b` were all `3dd8fa729964e3ed8f7eb4c050c5097501b71fee`
with a clean worktree. Prototype local `HEAD`, local `origin/main`, and live `refs/heads/main` were
all immutable pin `b91768513fc638381fbde91f0b576b08220a98f6`; all 49 roster paths resolved with
zero blob mismatches, and the direct `Editor/Data` surface was exactly the 48 rostered JSON files.
No prototype write or database/container/deploy/live action occurred.

### O9-P — historical conformance gaps are measured data quality

O9-P divides import findings permanently into two classes. Identity-class violations remain
fail-closed: permanent-code conflict or reassignment, an unknown closed-vocabulary literal, an
undecided natural-key collision, roster/blob drift, an unrostered source surface, or a row that
cannot import without an invented permanent code still stops the scope. Completeness-class gaps do
not: an absent, blank, or ungoverned field on an imported historical row imports as honest SQL
`NULL` with provenance `absent` — never empty string, sentinel, inferred value, default, or
backfill — and is counted as a named validator warning to work down through governed, audited
commands over time.

A new completeness-class gap not enumerated below is recorded with its measured count. If the
corrected accepted schema rejects it, only the affected rows are excluded with an explicit
per-table exclusion record; the rest of the import proceeds. This policy changes no identity-class
control.

### O9-D1…O9-D5 — governed import contract

| Decision | Governed record | Expected baseline and honest historical semantics |
|---|---|---|
| **O9-D1 — ENTMST `DirectDebit`** | The provenance register's former `source` claim is corrected with provenance: the column is target-only, nullable, and has no default. A later governed audited assignment is `authored`. | `ENTMST.DirectDebit absent`: **119**; every imported row is SQL `NULL` / `absent`. |
| **O9-D2 — ENTMST `TaxIdVerificationStatus`** | The column becomes nullable. Every new Sibyla-era entity must supply a governed value at creation; its deterministic gate lands with the entity-maintenance path. The validator warning applies to non-imported rows only, while historical verification proceeds through the governed flow. No `Unverified` sentinel exists. | `ENTMST.TaxIdVerificationStatus unverified`: **119**; every imported row is SQL `NULL` / `absent`. |
| **O9-D3 — DOCEFL `ItemClass`** | The column becomes nullable. Assignment is over time through an atomic, audited, actor-stamped governed command restricted to the closed D8 `Decision` / `Status` / `Annotation` vocabulary and records `authored` provenance. The authored sentinel `EF0000000` and Monthly-gap `EF0000053` retain their existing `authored` / `absent` markers. | `DOCEFL.ItemClass unassigned`: **52** imported source rows at SQL `NULL` / `absent`; authored rows count only when their recorded state is `absent`. |
| **O9-D4 — DOCEFL `ReviewPriority`** | The generated annex table is normative. The accepted five-literal CHECK is the defective artifact and must be replaced by the exact six-literal set `Before Posting`, `High`, `Immediate`, `Informational`, `Periodic Review`, `Routine`, without translation. This completes the CHECK; it does not change the vocabulary. | The **2** pinned `Routine` rows import verbatim after implementation; this is a CHECK reconciliation, not one of the four completeness findings. |
| **O9-D5 — terminal DOCFLG `ResolutionEvidence`** | The terminal non-blank CHECK is re-scoped to non-imported rows using the existing `Imported` marker. Every Sibyla-era terminal transition still requires non-blank evidence. Historical enrichment may occur only through a governed audited append command and never rewrites history. | `DOCFLG terminal without ResolutionEvidence`: **221**; imported terminal rows are SQL `NULL` / `absent`, never empty string or copied notes. |

These are expected baselines from the stopped read-only check, not import measurements. Import has
not run; if later measured values differ, the status record must state the measured values and
flag the deltas as findings rather than silently replacing the baselines.

O9 is closed by the recorded policy and five decisions. This is a records decision only: the
additive `P11bImportContractAlignment` migration, three nullability relaxations, CHECK changes,
governed command surfaces, validator scoping/findings, fixture update, importer, and tests have not
been implemented or run. Scope 1 has not restarted; Scopes 2–8 remain unstarted. The accepted
P1-1a migration is untouched. No import, database, container, deployment, live action, or
prototype write occurred. O5 remains the project's only open item.

## 2026-08-06 Scope 1 restart — mandatory schema/source stop (O9)

The ordered Scope 1 preflight was restarted from pushed records commit
`ca9942ba4731f1d3ac83646b21a081b30e3112e7`. Before any edit, Sibyla local `HEAD`, its upstream,
and the live remote branch were exact at that commit and the worktree was clean. After a metadata
fetch, prototype local `HEAD`, local `origin/main`, and live `refs/heads/main` were exact at immutable
pin `b91768513fc638381fbde91f0b576b08220a98f6`; its worktree was clean. Prototype blobs were read
only with `git show` at the pin. There was no prototype checkout, edit, commit, or push.

The governed count controls all pass:

| Control | Initial | Expected change | Result |
|---|---:|---:|---:|
| Unique roster paths | 49 | 0 | 49 |
| Roster blob mismatches | 0 | 0 | 0 |
| Direct rostered JSON paths | 48 | 0 | 48 |
| Direct-surface delta | 0 | 0 | 0 |
| ENTBNK rows / distinct keys | 43 / 43 | 0 / 0 | 43 / 43 |
| ENTBNK duplicate groups / rows | 0 / 0 | 0 / 0 | 0 / 0 |
| DOCEFL source rows / unique codes | 52 / 52 | 0 / 0 | 52 / 52 |
| EF references above the source manifest, ledger / instances | 0 / 0 | 0 / 0 | 0 / 0 |
| DOCTYP source / excluded uncoded / import manifest | 20 / 1 / 19 | 0 / 0 / 0 | 20 / 1 / 19 |
| DOCFLG source rows | 2,787 | 0 | 2,787 |
| Distinct four-field C13 keys | 2,780 | 0 | 2,780 |
| Four-field collision surplus requiring `DetectedAt` | 7 | 0 | 7 |
| Distinct complete C13 keys / collisions | 2,787 / 0 | 0 / 0 | 2,787 / 0 |

The next fail-closed import-contract check found five independent contradictions between the pinned
source, the normative field provenance, and the accepted P1-1a schema:

| Control | Initial | Expected change | Result |
|---|---:|---:|---:|
| ENTMST rows lacking the declared source, non-null `DirectDebit` field | 119 | 0 | 119 |
| ENTMST rows with no governed value for production, non-null `TaxIdVerificationStatus` | 119 | 0 | 119 |
| DOCEFL rows lacking a governed target-only `ItemClass` value | 52 | 0 | 52 |
| DOCEFL rows rejected by the accepted `ReviewPriority` CHECK despite using an annex-listed literal | 2 | 0 | 2 |
| Terminal DOCFLG rows | 2,644 | 0 | 2,644 |
| Terminal DOCFLG rows rejected by the accepted non-blank `ResolutionEvidence` CHECK | 221 | 0 | 221 |

The provenance register in `docs/p1-0-schema-mapping.md` declares `ENTMST.DirectDebit` a source
column, while the rostered source shape has no such property on any of 119 rows; the accepted schema
makes it non-null with no default. The same schema makes production
`TaxIdVerificationStatus` non-null without a default or a governed import value. The O8-amended
DOCEFL transcription honestly covers the 20 source fields but explicitly leaves target-only
`ItemClass` governed elsewhere; no field-level 52-row assignment exists, while the schema requires
the column non-null. Separately, the stopped evidence found that the generated vocabulary annex
internally contradicted itself: its table contained six exact `ReviewPriority` literals —
`Before Posting`, `High`, `Immediate`, `Informational`, `Periodic Review`, and `Routine` — while
its explanatory prose named five and omitted `Routine`. This independent-review records correction
fixes that prose, but the accepted schema CHECK independently contains five and still rejects the
table-derived sixth literal on two pinned rows. Finally, 221
terminal DOCFLG rows honestly lack `ResolutionEvidence`, but the accepted terminal-state CHECK
requires that field to be non-blank.

Supplying false/default values, deriving an ungoverned `ItemClass`, translating the governed
literal, or copying notes into missing resolution evidence would invent or normalize data. Editing
the accepted P1-1a migration or adding a corrective migration would be adaptation after the
assignment's explicit schema-contradiction stop. Scope 1 therefore stopped before TDD, importer
implementation, migration application, or database/container work. Ordered Scopes 2–6 did not
start; no parity or join result is claimed. Resolution requires a governed schema/import decision
and, where applicable, exact per-field values or nullability changes. This records-only correction
does not close O9; the Scope 1 stop remains in force.

### Verification of the stopped records stage

| Verification | Result |
|---|---:|
| `dotnet build GOTT.Sibyla.slnx --no-incremental` | succeeded; 0 warnings, 0 errors |
| Focused registry validation tests | 28 passed, 0 failed, 0 skipped |
| Ordinary test suite | 629 passed, 0 failed, 0 skipped |
| `git diff --check` | clean |
| Added-line common-secret scan | 0 matches |
| Added-line destructive-command scan | 0 matches |
| Required local documentation links | 0 missing |
| `sibyla-p11*` residual containers | 0 |

The disposable P1-1b suite did not run because database creation is downstream of the mandatory
schema/source stop. No Scope 3 warnings or failures were measured: no imported disposable set
exists. Scope 5 parity and Scope 6 join evidence likewise do not exist and are not claimed.

## O8 records amendment — O8-D1 and O8-D2

Miguel's O8 amendment prompt is already present in history at the records-amendment base above:
`docs/AGENT-PROMPT-v5-P1-1b-o8-amendment.md` was committed as part of `dabf3288…`. This governed
records commit applies it; the prompt is not duplicated or rewritten.

### Read-only preflight evidence

The preflight was repeated before any edit. Sibyla was clean on `feature/p1-1b`; local `HEAD`, its
upstream, and live `refs/heads/feature/p1-1b` were all exactly
`dabf3288ed86ce7c4c42d3e4b7099d13ff740cc1`. The prototype was clean on
`c8-entbnk-five-pair-merge`; after `git fetch --prune origin`, local `HEAD`, local `origin/main`,
and live `refs/heads/main` were all exactly the immutable pin
`b91768513fc638381fbde91f0b576b08220a98f6`.

The complete roster contains **49 unique paths**; all 49 resolve to their recorded blobs with zero
mismatches. The direct `Editor/Data` surface is exactly **48 JSON files**, all rostered, with zero
surface delta. The checks used metadata and `git show` against rostered paths only. There was no
prototype checkout, edit, commit, push, or other write.

`flag_evaluation.json` has exactly **52 rows and 52 unique EF codes**, consecutively
`EF0000001`–`EF0000052`. `permanent_code_ledger.json` and `flag_instances.json` each contain
**zero** EF codes above `EF0000052`; neither contains `EF0000053`. The lowest code verified free on
both sides is therefore `EF0000053`. C8 remains exact at **43 rows / 43 distinct keys / 0 duplicate
groups / 0 duplicate rows**.

### O8-D1 — governed DOCEFL manifest and authored code

The governed source import manifest is extended from 45 to all **52** source rows,
`EF0000001`–`EF0000052`, from rostered `Editor/Data/flag_evaluation.json` blob
`22252b90a52b2a114cfbd74de0d6bd0272fc5b0e`. Every present source field is recorded as
`extracted`; an absent source field remains honestly absent and no value is inferred. This includes
source `EF0000046`, the visual-read rule; its source identity and values are unchanged.

The authored sentinel remains `EF0000000` unchanged. The target-authored Monthly-gap rule is
re-authored once from `EF0000046` to **`EF0000053`**. Every other field and every
`authored|absent` provenance marker is unchanged. It still seeds `Active=No` behind the
`RequireRunnableActiveDecisionDOCEFL` CHECK; `ActivateDOCEFLRule` must still supply the five
governed values atomically before it can emit findings. The row has never been imported,
activated, or first-used, so C3 immutability had not attached.

### O8-D2 — explicit DOCTYP exclusion

The first 19 rows of rostered `Editor/Data/document_type_rules.json` blob
`b7560e9ea0c403e608b73ed3a3a4f6b53ce956cb` are identical to the governed 19-row transcription.
Its twentieth source row, `Bank Statement | External | Exclude`, has blank `DTCode` and is
explicitly excluded from import: importing it would require inventing a permanent code. The
DOCTYP import manifest remains exactly **19**. The accepted authored target rule
`Bank Statement | External | Include | ArchiveOnly` remains unchanged; it is not a translation of
the excluded source row.

O8 is closed. Scope 1 is ready to restart from its preflight against unchanged pin `b917685…`.
No importer, source, fixture, or test code was changed; no import, migration, container, or
disposable/shared/live/production database work ran. Scopes 2–8 remain unstarted and ordered.

## Scope 1 resumed preflight — mandatory governed-manifest stop

Scope 1 restarted from preflight at the immutable pin without changing the prototype. Sibyla was
clean on `feature/p1-1b` at pushed commit
`6a17e83bc8d115000ce731f95b141c593234e1da`. The prototype worktree was clean on
`c8-entbnk-five-pair-merge`; local `HEAD`, local `origin/main`, and the live remote
`refs/heads/main` were all exactly
`b91768513fc638381fbde91f0b576b08220a98f6`.

The complete roster check resolved all **49 of 49** recorded paths to their expected blob. The
direct `Editor/Data` surface contains exactly **48 JSON files**, all rostered, with zero added,
missing, or unrostered paths. Blob contents were read only through `git show <pin>:<rostered-path>`;
there was no prototype fetch, checkout, branch, edit, commit, or push.

### C8 and C13 controls

| Control | Initial | Expected change | Result |
|---|---:|---:|---:|
| ENTBNK source rows | 43 | 0 | 43 |
| Distinct `(CodeName, Company)` keys | 43 | 0 | 43 |
| Duplicate key groups | 0 | 0 | 0 |
| Rows participating in duplicate groups | 0 | 0 | 0 |
| DOCFLG source rows | 2,787 | 0 | 2,787 |
| Distinct `(EFCode, RelatedRecordType, RelatedRecordID, SourceTextHash)` | 2,780 | 0 | 2,780 |
| Residual four-field collisions requiring `DetectedAt` | 7 | 0 | 7 |
| Distinct complete C13 keys including `DetectedAt` | 2,787 | 0 | 2,787 |

C8 therefore passes exactly. The historical C13 residual count was three at the older P1-0 pin;
it is seven at the new pin, but the decided rule is unchanged and works as intended: all seven
remain visible and the complete five-field natural key has zero collisions.

### Stop evidence

The accepted Scope 1 contract requires the imported DOCEFL source manifest to be exactly
`EF0000001`–`EF0000045`, with target-authored rows retaining their governed
`authored`/`absent` provenance. The rostered `Editor/Data/flag_evaluation.json` blob
`22252b90a52b2a114cfbd74de0d6bd0272fc5b0e` instead contains **52** rows:

- source `EF0000046` is `Source read visually - no extractable text layer`;
- accepted P1-0 already authors permanent `EF0000046` as `Expected monthly invoice gap`;
- source `EF0000047`–`EF0000052` have no accepted P1-0 import-manifest, `ItemClass`, or per-field
  `extracted|authored|absent` decision in this repository.

This is a direct permanent-code conflict, not a count drift an importer may absorb. Reassigning
either `EF0000046`, dropping a source rule, or inventing provenance would violate the frozen code
identity and fail-closed import rules.

A second independent conflict exists in rostered
`Editor/Data/document_type_rules.json` blob
`b7560e9ea0c403e608b73ed3a3a4f6b53ce956cb`. It contains **20** rows. The twentieth is
`Bank Statement | External | Exclude`, has `DocClass=Bank`, and has a blank `DTCode`. The accepted
target taxonomy instead declares `Bank Statement | External | Include` routed `ArchiveOnly`.
Preserving the blank code violates permanent-code import; copying `Exclude` contradicts the
accepted target semantics; translating it to `Include` would silently normalize source data and
break exact parity.

The prompt requires stop-and-report on a source conflict, unknown governed row, or schema
contradiction. Scope 1 therefore stopped before importer/TDD work. Scope 1 did not complete and
Scopes 2–6 did not start. No source or test code was created, no migration was changed or applied,
and no disposable, shared, live, or production database or container was created. O8 in
`docs/PROJECT-STATE.md` records the Miguel-owned decision required to resume.

### Verification of this stopped records stage

| Verification | Result |
|---|---:|
| `dotnet build GOTT.Sibyla.slnx --no-incremental` | succeeded; 0 warnings, 0 errors |
| `dotnet test tests\Sibyla.Tests\Sibyla.Tests.csproj --no-build` | 629 passed, 0 failed, 0 skipped |
| `git diff --check` | clean |
| Added-line common-secret scan | 0 matches |
| Added-line destructive-command scan | 0 matches |
| Required local documentation links | 0 missing |
| `sibyla-p11*` residual containers | 0 |

The disposable P1-1b end-to-end rehearsal was not run: it is dependent database work after a
mandatory Scope 1 source-manifest failure. No parity result, validator warning count, or Scope 6
join-test number exists, and none is claimed.

## C8 records amendment — authorized on-behalf source merge

Miguel's `docs/AGENT-PROMPT-v5-P1-1b-c8-amendment.md`, dated 2026-08-06, authorized
the five-pair ENTBNK source merge while Luís was unavailable. The prototype change was made on
Luís's behalf under that authorization and remains flagged for Luís's review on return. The
stability basis for the resulting pin is **Miguel's authorization plus the complete
roster-unchanged verification below, not a new confirmation from Luís**.

The source action is committed and pushed as prototype commit
**`b91768513fc638381fbde91f0b576b08220a98f6`**, authored and committed by
`Sibyla <sibyla@gottsolutions.net>` with subject `Merge five duplicate ENTBNK pairs`. Its clean
multi-line body states that it executes C8, was performed on Luís's behalf under Miguel's
2026-08-06 authorization while Luís was unavailable, retains both `Flag` notes for every pair,
and invites Luís's review on return. The commit changes exactly one path:
`Editor/Data/entbnk.json`. It was pushed normally to `origin/main`; there was no force push or
history rewrite.

The immutable P1-1b source pin is now
**`b91768513fc638381fbde91f0b576b08220a98f6`**. Read-only verification found the prototype
worktree clean on branch `c8-entbnk-five-pair-merge`, with local `HEAD`, the local
`origin/main` tracking ref, and the live remote `refs/heads/main` all equal to that SHA.

### Before / expected / result control

The exact precondition was re-measured at pin
`06825b54ec3855a96b5c49b352e2879b11971e39`, blob
`864cb41740dec04517f3903d3f3b16e8251a2ead`. It contains 48 rows, 43 distinct
`(CodeName, Company)` keys, five duplicate groups and ten rows in duplicate groups. Every group
has exactly two rows; `PayAccount` and `PayMethod` each have one distinct value, `Flag` has two
distinct values, and every other field is identical within its pair.

| Control | Initial | Expected change | Result |
|---|---:|---:|---:|
| ENTBNK source rows | 48 | -5 | 43 |
| Distinct `(CodeName, Company)` keys | 43 | 0 | 43 |
| Duplicate key groups | 5 | -5 | 0 |
| Rows participating in duplicate groups | 10 | -10 | 0 |

The result re-parses at the new pin and has blob
**`70d418f6023bff68f0d642b4aff26c1ead1298be`**. All five merged rows preserve the natural key,
the single `PayAccount` and `PayMethod` values, every other field, and both full `Flag` notes.
The old and new blobs both have no trailing newline. Serialization style is preserved; the
one-path diff is five insertions and forty deletions, representing exactly the five merges.

### Complete 49-entry blob-roster amendment

The complete 49-entry roster recorded below for the 2026-08-05 pin remains authoritative at the
new pin with exactly this one substitution:

| Pinned path | Old blob at `06825b54…` | New blob at `b917685…` |
|---|---|---|
| `Editor/Data/entbnk.json` | `864cb41740dec04517f3903d3f3b16e8251a2ead` | `70d418f6023bff68f0d642b4aff26c1ead1298be` |

All other **48 of 49** roster entries are byte-identical between the two pins, including all
other direct `Editor/Data/*.json` files and `Backups/Control Log.md`. A complete `git ls-tree`
comparison over those 49 recorded paths found one changed entry and no added, removed, or
unrecorded entry. This is an unambiguous complete-roster amendment: take every path/blob pair in
the table under **Fresh read-only prototype pin** below, replace only the `entbnk.json` blob as
shown above, and retain every other pair verbatim.

### Resume disposition

C8's source-data gate is closed by the authorized on-behalf source merge. Scope 1 is ready to
restart at its source preflight against immutable pin `b91768513fc638381fbde91f0b576b08220a98f6`
under the standing P1-1b prompt. **No importer or source code has been implemented, no import has
run, and no disposable, shared, live, or production database or container has been created or
touched in this records pass.** Scopes 2–8 remain unstarted and ordered behind Scope 1 and their
own stated gates.

## Historical gate confirmation — 2026-08-05

Luís confirmed the prototype is stable and the queued documents are ingested; Miguel relayed
this confirmation on 2026-08-05.

The confirmation above was recorded before taking the fresh prototype pin. No prototype source
contents had been opened or read for P1-1b, and no live database had been touched.

## Fresh read-only prototype pin

Prototype clone: `D:\fileStorage\repos\invoice-skill-build`

- Before fetch, `git status --short --branch` reported `## HEAD (no branch)` with no changed or
  untracked paths. Both `git diff --quiet` and `git diff --cached --quiet` succeeded.
- `git fetch --prune origin` advanced `origin/main` from `6146004` to
  `06825b54ec3855a96b5c49b352e2879b11971e39`.
- Fresh P1-1b pin: **`06825b54ec3855a96b5c49b352e2879b11971e39`** (`origin/main`).
- The clone remained detached at historical commit
  `9359c67c4ef0101218d7e0ffff1986114ba5cc7a`; no checkout was used to inspect the pin.
- Only `git status`, `git diff --quiet`, `git fetch --prune`, `git rev-parse`, and `git ls-tree`
  metadata operations were used. There were no prototype edits, checkouts, branches, commits, or
  pushes, and no blob contents were opened before or while fixing this roster.

The path named `Invoice Skill Build/Editor/Data/*.json` in the assignment resolves from the clone
root to `Editor/Data/*.json`. The complete direct-file JSON surface is pinned below so later P1-1b
access fails closed on any unrecorded source. This is a source-control roster, not an import list:
in particular, `Editor/Data/document_gaps.json` is recorded only to prove the wildcard surface and
remains excluded from import by C12. Scope 1–8 implementation has not started.

| Pinned path | Git blob SHA |
|---|---|
| `Editor/Data/archive_filename_map.json` | `019110550151d3a86e3c8f7083ae6733e77786e1` |
| `Editor/Data/bnk_generated_documents.json` | `3346dca1e5f9828f469f7c7c43a041c50f96ac54` |
| `Editor/Data/bnkacc.json` | `5c2d95c4f6669f91d428a2ae21707db3697cac9d` |
| `Editor/Data/bnkchk.json` | `5bb7fa401d24e3e05ee75138a583b6e0b4dc81f0` |
| `Editor/Data/bnkchk_source_balances.json` | `84d84e993e030e610cc3350a8294306a5952bb92` |
| `Editor/Data/bnkmat.json` | `d34c1bba03fe6f1d6a23851f25c328029f57b161` |
| `Editor/Data/bnkmov.json` | `8d0c857552a3af604f56531005c646f479355607` |
| `Editor/Data/bnkrec.json` | `b70e82cd9b31ac6b984baaea1d611417cea1f055` |
| `Editor/Data/cocacc.json` | `ac5be35281b78cac6fd3de4f6ba2af01cb7e0d06` |
| `Editor/Data/control_holds.json` | `9e6de9f8cefe8688ed19290bdff0b117e27df46d` |
| `Editor/Data/data.json` | `b9d5242e91802a4bfe299d068fec813e15aa02cf` |
| `Editor/Data/docrqe.json` | `1f4312a2ffaec870b88dc490b657a5c31f0c7638` |
| `Editor/Data/document_gaps.json` | `3b0e0c79db0911a89c69e6a68ce85f4236181caf` |
| `Editor/Data/document_type_rules.json` | `b7560e9ea0c403e608b73ed3a3a4f6b53ce956cb` |
| `Editor/Data/duplicate_documents.json` | `ea3f9b49d39947ac0a1632ea85ee02e125559f42` |
| `Editor/Data/entals.json` | `72ec58fc49d4686c5313e13e96b55208d230ba12` |
| `Editor/Data/entblc.json` | `c73142f8068a3ad61ef5746f26630401e10e3261` |
| `Editor/Data/entblc_overrides.json` | `fe51488c7066f6687ef680d6bfaa4f7768ef205c` |
| `Editor/Data/entbnk.json` | `864cb41740dec04517f3903d3f3b16e8251a2ead` |
| `Editor/Data/entities.json` | `b990d56a400afa7ee3b041c9ff97136a5d70c247` |
| `Editor/Data/entity_products.json` | `004b180938de7646ef537cfd5175aeca0b8e31ed` |
| `Editor/Data/exchangerates.json` | `3854381347d0d9ad1bec28462d3407860fdba488` |
| `Editor/Data/file_hash_cache.json` | `c268f58876112de06d993dcd9a2cce435af79070` |
| `Editor/Data/flag_evaluation.json` | `22252b90a52b2a114cfbd74de0d6bd0272fc5b0e` |
| `Editor/Data/flag_instances.json` | `ab500dd1f989a1a6ec0cff8f4ecff2985097a987` |
| `Editor/Data/invhdr_chk_raw.json` | `6968ed5e329a647593c902a7ed2a50ab1c3f2b8c` |
| `Editor/Data/itemclass_mngacc.json` | `043b277f4739c19b3fb14d3b73a812b453dde5bf` |
| `Editor/Data/itemclass_taxonomy.json` | `6fcfcf1403b68c38583bb937f50767be0ed3d1ef` |
| `Editor/Data/itmals.json` | `cde83708f6959f2e0c315a68a172754f408dd1f2` |
| `Editor/Data/lgcode_identity_migration.json` | `896c914927fc24fb49edd57c2213ef3ccd4e1314` |
| `Editor/Data/payctr.json` | `80384d5f17c77d5e261216f8f1f05b580755d690` |
| `Editor/Data/payctr_overrides.json` | `b96403694d22e415c91b745cb131f3267e41f457` |
| `Editor/Data/payctrl_matches.json` | `f2039a3bf2d682983e3ccf2e6555315775036d9a` |
| `Editor/Data/payctrl_superseded_rows.json` | `34da4d8d5e9b2985ab01a21c7c563ff75e51d1c8` |
| `Editor/Data/paydtl.json` | `3755badd36d335ae9e1320f2b32a7b50806415df` |
| `Editor/Data/payroll.json` | `b047bda2719fc38beb54e89a27fadec0bb607bb9` |
| `Editor/Data/permanent_code_ledger.json` | `f19081ec9c13e022173d13aad4439605b3796cd1` |
| `Editor/Data/productmaster.json` | `f0ccc02ff726934e301046364dfd3fcb71152472` |
| `Editor/Data/rcvctr.json` | `7a825256e8d9b054dbe5ebcceb4fbf29a666937d` |
| `Editor/Data/rcvctr_overrides.json` | `75871a9b3d479fcc405149a5b55b2ea0ab346336` |
| `Editor/Data/rcvctrl_matches.json` | `0dd5e7983430971d45c6d6b7257978a52e71103f` |
| `Editor/Data/rcvdtl.json` | `013510b0653309b18db1eeaf4c967e123066f308` |
| `Editor/Data/recrev.json` | `ee5878b8a1f7c2d00094a634abbe56119953e3c0` |
| `Editor/Data/reference_only_documents.json` | `717686c438be521ca6b3f72c508bf1130e6e45e9` |
| `Editor/Data/retired_duplicate_documents.json` | `0b44b74220f058743a14f61d80c4657d757507d3` |
| `Editor/Data/sncacc.json` | `1c64747cafd9e89681f2bd533eeb1724c936a701` |
| `Editor/Data/stage10_round6_alias_candidates.json` | `7b6deb939b8af5f6ab10aa7c135bae4615d56f12` |
| `Editor/Data/user_observations.json` | `32c30e62eaf82d59f36f563ecbe79c231e3b89d0` |
| `Backups/Control Log.md` | `b6b89fbae83163a85a0b0831452855ccd9367ca1` |

## Consistency note

The records-stage commit initially brought in the byte-exact `docs/project-evolution.html` version
from `b793970`, which described the pre-authorization moment in places. The later independent-review
documentation correction updates that current-facing page while preserving statements clearly
framed as historical at the time. `docs/PROJECT-STATE.md` remains the higher-precedence state source.

## Records-stage boundary

This commit only establishes P1-1b authority, closes O7 prospectively, and fixes the read-only
source pin and blob roster. It performs none of P1-1b Scopes 1–8, reads no prototype source blob,
and touches no disposable, shared, live, or production database.

## Scope 1 execution — mandatory C8 stop

Scope 1 began with the required fail-closed source preflight. The only prototype source blob read
was the already-rostered `Editor/Data/entbnk.json` at exact commit
`06825b54ec3855a96b5c49b352e2879b11971e39` (blob
`864cb41740dec04517f3903d3f3b16e8251a2ead`). It was read with `git show`; the prototype worktree
was not checked out, edited, committed, branched, or pushed.

Measured result:

| Control | Initial | Expected | Result |
|---|---:|---:|---:|
| ENTBNK source rows | 48 | 48 | 48 |
| Distinct `(CodeName, Company)` keys | 43 | 48 | 43 |
| Duplicate key groups | 5 | 0 | 5 |
| Rows participating in duplicate groups | 10 | 0 | 10 |

All five duplicate groups have two rows. Within every pair, `PayAccount` has one distinct value,
`PayMethod` has one distinct value, and `Flag` has two distinct values. No real key or field value
was copied into this repository or emitted in the command output.

This is exactly C8's known source-data defect. C8 keeps `(CodeName, Company)` as the natural key,
requires the five pairs to be merged at source while retaining both review notes, and literally
mandates that import and downstream progression **fail closed until that is done**. C8 does not
explicitly prohibit writing synthetic importer tests. Stopping before TDD or synthetic importer
tests was the conservative execution choice recorded by current state; the P1-1b prompt and current
assignment separately forbid coercing, silently normalizing, or absorbing the duplicates. Scope 1
therefore stopped before importer implementation, migration application, or any database/container
creation.

## Ordered-scope disposition

| Scope | Result |
|---:|---|
| 1 — reference layer | **Stopped at C8 preflight; not imported.** No per-table import controls exist beyond the failing ENTBNK source control above because no disposable database was created. |
| 2 — 2026 history | Not started; ordered dependency on completed Scope 1. |
| 3 — validation | Not started; no imported disposable set exists. Failures/warnings were not measured. |
| 4 — backlog count remeasurement | Not started; it depends on the accepted import source set. No indicative count was replaced. |
| 5 — render parity | Not started; no seeded set exists. No parity is claimed and no deferral proposal is needed before its ordered scope is reached. |
| 6 — overlapping-statement join test | Not started; no seeded set exists. Re-anchor, duplicate, aggregate, and uniqueness numbers were not measured. |

Scopes 7 and 8 were explicitly outside this run and were not started. There was no shared/live
database write, deployment, backup/live pass, hash-index swap, or BRCode issuance.

## Evidence and exact command

The C8 measurement was performed from the repository worktree with this PowerShell shape (the
rostered pin/path are literal; output contains counts only):

```powershell
$raw = git -C D:\fileStorage\repos\invoice-skill-build show 06825b54ec3855a96b5c49b352e2879b11971e39:Editor/Data/entbnk.json
$rows = $raw | ConvertFrom-Json
$groups = $rows | Group-Object CodeName,Company | Where-Object Count -gt 1
```

The preflight command completed in under one second. No disposable rehearsal was started because
the ordered C8 stop occurred before database work. The unchanged production baseline was still
verified after the final documentation edits:

| Verification | Result | Measured duration |
|---|---|---:|
| `dotnet build GOTT.Sibyla.slnx` | Succeeded; 0 warnings, 0 errors | 30.45 s |
| `dotnet test tests\Sibyla.Tests\Sibyla.Tests.csproj` | 629 passed, 0 failed, 0 skipped | 30.56 s wall clock; 17 s test duration |
| `dotnet test tests\Sibyla.Tests\Sibyla.Tests.csproj --filter FullyQualifiedName~RegistryValidationServiceTests` | 28 passed, 0 failed, 0 skipped | 8.83 s wall clock; 137 ms test duration |
| `git diff --check` | Clean | under 1 s |
| Diff-only common-secret-pattern scan | 0 matches | under 1 s |
| `docker ps -a --filter "name=sibyla-p11" --format "{{.Names}}"` | 0 residual containers | under 1 s |

The disposable end-to-end rehearsal is intentionally not run: it would be dependent Scope 1
database work after a mandatory source preflight failure. Documentation scope, remote push, and
final worktree hygiene are verified for the focused blocker record.

## Historical requirement to resume — satisfied 2026-08-06

The source merge and records amendment required by the 2026-08-05 stop are now complete under
Miguel's 2026-08-06 on-behalf authorization. Luís did not provide a new confirmation because he
was unavailable; the amendment explicitly substitutes Miguel's authorization plus proof that the
other 48 roster entries are byte-identical, and flags the source commit for Luís's review on
return. Scope 1 may now restart its source preflight at the new pin. Scopes 2–6 remain ordered
behind a genuinely completed Scope 1; Scopes 7–8 retain their separate review gates.
