references/reviewer-subagent-guidance.md | Read by the reviewer subagent itself (the orchestrator passes only its path, never embeds the content) | Scope, skill-load sequence, read-only operating rules, per-issue format checklist, verdict rules, reporting contract for the orchestrator-dispatched reviewer |
references/review-output-template.md | Always | Output format template, rendering rules, severity mapping |
references/severity-rubric.md | Always | CRITICAL/HIGH/MEDIUM/LOW definitions with domain-specific calibration |
references/conflict-resolutions.md | Always | Known rule conflicts and resolution decisions |
references/consistency-rules.md | 2+ domains | Cross-domain consistency rules (pipeline-fields-manifest-tests) |
references/version-check-procedure.md | CEL in scope | 5-step systematic version verification procedure |
references/beats-mito-version-matrix.md | CEL in scope | Full beats-to-mito version mapping (160+ entries) |
references/config-options-by-version.md | CEL in scope | CEL config option introduction by beats version |
references/extensions-per-version.md | CEL in scope | Registered mito extensions per beats version |
references/cel-validator-procedure.md | CEL in scope | celfmt authority, type conversion audit, error shape validation |
references/api-conformance-methodology.md | CEL/HTTPJSON + API docs | Cross-referencing implementation vs vendor API documentation |
references/input-review-orchestration.md | Any input templates | Review depth routing by input type |
references/transform-guide.md | Transform in scope | Transform types, config, fields, sync, review checklist |
references/cdr-transform-requirements.md | CDR transforms | CDR latest transform requirements, destination naming, keys, retention |
references/repo-conventions.md | Always | elastic/integrations repo conventions: group field, Elastic Managed rename + agentless release, owner.type, changelog/backport automation, version-constraint hygiene (dated reference) |
references/entity-analytics-provider-matrix.md | entity-analytics in scope | Provider capability matrix (azure-ad, okta, activedirectory, jamf), legacy vs minimal-state sync/marker/deletion semantics |
checklists/pipeline-review-checklist.md | Pipeline in scope | Severity-tagged pipeline review checklist |
checklists/field-review-checklist.md | Fields in scope | Severity-tagged field mapping review checklist |
checklists/cel-review-checklist.md | CEL in scope | Severity-tagged CEL review checklist |
checklists/httpjson-review-checklist.md | HTTPJSON in scope | Severity-tagged HTTPJSON review checklist |
entity-mappings/references/entity-field-catalog.md | Entity data stream in scope (see entity detection rule) | ECS availability matrix, Must Have / Should Have field tables, disambiguation guide, field definition examples, entity field review checklist |
entity-mappings/references/entity-pipeline-patterns.md | Entity data stream in scope (see entity detection rule) | Categorization processors, entity.id mirroring, boolean coercion, relationship object patterns, anti-patterns, entity pipeline review checklist |
checklists/entity-analytics-review-checklist.md | entity-analytics in scope | Severity-tagged entity-analytics package review checklist |