# S1 — gated editors: shaped proposals for decision

**Date:** 2026-08-20 (stop-list framing corrected same day) · **Status:** shaped. **The
stop-list reading, corrected:** runtime editors are **not automatically** "live-tenant
configuration" in the V6-O1 sense — the stop-list item is *pointing configuration at a live
tenant*, and slices are **assessed individually when shaped** (the rule the `!105` presentation
write already shipped under). What that means per item:

- **g2 (IsActive offer toggle)** — proceeds through the **normal V6-O1 flow**: it configures
  which document types this application's own intake offers, in the application's own database;
  no live tenant is being configured. The slice's MR carries that assessment explicitly, as
  `!105`'s did.
- **g3 (routing columns)** — blocked on **O-1** (Luís), independent of the stop-list question.
- **h (DOCEFL editor)** — **formally deferred to S2**: by this document's own design the pattern
  tester has no DOCLOG/FDCHDR/FDCDTL documents to test against yet, and **O-4** (who may edit)
  remains Miguel's open decision.

Any future slice that *would* point configuration at a live tenant stops and asks Miguel — the
stop list itself is unchanged.

---

## 1 · DOCTYP routing-column write + the IsActive offer toggle (`S1-9g` remainder)

**What exists.** The read-only catalogue and verbal routing preview (`!72`) and the governed
presentation write (`!105`: LabelPt/LabelEn/SortOrder only, Administrator-only, `xmin`, audited,
fail-closed CHECK messages). `IsActive` and every routing column are read-only today.

**What it changes.** `IsActive` gates `DocumentTypeRoutingService` — flipping it changes which
document types this application's intake offers (`document_type_routing_inactive`). The routing
columns (`DocumentType`, `OriginClass`, `Treatment`, `ProcessingRoute`, `DocClass`,
`FiscalEligible`, `HeaderOnlyAllowed`) decide how documents are treated. Operational
configuration of the application itself — assessed per slice, per the corrected framing above.

**Proposed shape (when approved).**
- Same governed service as `!105`, extended field set — never a second write path.
- **Slice g2 — the offer toggle only**: `IsActive` writable by Administrator; turning it on
  requires the full presentation (already a DB CHECK, `CK_DOCTYP_Offer_Requires_Labels`, mapped
  to a PT/EN message); turning it off requires a typed confirmation naming the type, because
  intake stops offering it immediately. Same-transaction audit records before/after.
- **Slice g3 — routing columns**: blocked additionally by **O-1** (`Payables`/`Receivable`
  spelling — **Luís's call**, fixed at source or preserved verbatim). Each change shows the
  routing preview diff (the `!72` renderer) before save; `Treatment`/`ProcessingRoute` values
  validated against the closed sets the CHECKs enforce.
- Rollout guard: both slices ship behind the existing admin policy; no seeder involvement
  (DOCTYP routing is target-owned).

**Decisions:** g2 proceeds through the normal flow under the corrected framing (its MR states
the assessment; the review is the check). g3 waits on **O-1** (Luís). No Miguel gate applies to
either unless a slice would point configuration at a live tenant.

---

## 2 · DOCEFL editor (`S1-9h` remainder)

**What exists.** The read-only flag-rules catalogue (`!104`, EF-mapped columns only). The deeper
rule fields (DetectionPattern, ReviewOwnerRole, ReviewPriority, BlockingLevel,
ResolutionEvidenceRequired, …) are not EF-mapped yet.

**Why it waits.** **Formally deferred to S2** (2026-08-20): the pattern tester has no
DOCLOG/FDCHDR/FDCDTL documents to test against until S2 builds them, and **O-4** (who may edit
DOCEFL at all) is **Miguel's open decision**. The standing rule holds: **the editor never ships
without the pattern tester and the impact count.**

**Proposed shape (when approved).**
- **Prerequisite that cannot be faked:** the pattern tester needs real documents to test
  against, which arrive with **S2** (DOCLOG/FDCHDR/FDCDTL). Building the editor before S2 would
  ship a tester with nothing to test — recommendation: **defer the editor until S2 documents
  exist**, whatever O-4 decides.
- When built: map the remaining DOCEFL columns (model-alignment migration, columns
  mapped-not-created); one governed write service (role per O-4, `xmin`, same-transaction
  audit); every rule edit previews (a) the pattern tester result against a chosen document set
  and (b) the impact count — how many existing DOCFLG instances the changed rule would have
  matched; `RuleVersion` bumps on every change; the `RequireRunnableActiveDecisionDOCEFL` CHECK
  maps to a fail-closed PT/EN message.

**Decision needed from Miguel:** O-4 (the editing role), and confirmation that the editor waits
for S2 documents.

---

## 3 · S1 exit — the "CTT" demonstration script

The exit is human: **a real CTT row in ENTMST, actually shown to a real person, with the date
and the witness recorded.** Nothing to build; a 10-minute session:

1. `/{c}/master/entities` → search "CTT" → open the entity.
2. Show the tabs in order: Identity (canonical data), **Aliases** (including scope), **Banking**
   (methods and accounts per scope), **Items** (the usual items and the accounts they post to),
   Documents / Balances / Audit.
3. Cross-check one account on the SNC tree (`/{c}/master/accounts/snc`) — the item's account and
   its usage counts.
4. Re-run the seeder on a disposable copy beforehand and show that a replay **changes nothing**
   (steady-state claim).
5. Record in `docs/STATE.md` and the backlog: the date, who was shown, and who witnessed.

If no real CTT row exists in ENTMST, the demonstration cannot be claimed — that fact would
itself be the finding to record.
