Constitutional judgment surface for the CGG signal manifold — pending CogPRs into doctrine, active warrants into action.
CENTROID:
human-gated constitutional judgment for CogPRs and warrants
IS:
- the promotion gate from pending CogPR to inscribed doctrine
- the warrant triage surface from active signal to bounded action
- the lattice integrity check across docket entries (relations, refinements, contradictions)
IS NOT:
collapse_zones:
- queue mutator (review-execute applies; review judges)
- signal emitter (cadence emits, siren classifies, review evaluates)
- mandate spawner (cadence writes mandates; review must not)
- inline doctrine inscription (verdicts route through review-execute, not review's own writes)
- autonomous reviewer (every promotion requires human gate)
sibling_overlaps:
- /siren (signal triage)
- /complement (closure-inference lattice gap)
- review-execute agent (mechanical apply)
WHEN:
- when the queue contains decision-ready CogPRs (extracted, enrich
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Constitutional judgment surface for the CGG signal manifold — pending CogPRs into doctrine, active warrants into action.
CENTROID:
human-gated constitutional judgment for CogPRs and warrants
IS:
- the promotion gate from pending CogPR to inscribed doctrine
- the warrant triage surface from active signal to bounded action
- the lattice integrity check across docket entries (relations, refinements, contradictions)
IS NOT:
collapse_zones:
- queue mutator (review-execute applies; review judges)
- signal emitter (cadence emits, siren classifies, review evaluates)
- mandate spawner (cadence writes mandates; review must not)
- inline doctrine inscription (verdicts route through review-execute, not review's own writes)
- autonomous reviewer (every promotion requires human gate)
sibling_overlaps:
- /siren (signal triage)
- /complement (closure-inference lattice gap)
- review-execute agent (mechanical apply)
WHEN:
- when the queue contains decision-ready CogPRs (extracted, enrichment_eligible, or born_truth_captured)
- when active warrants exist and require triage
- when a docket has been pre-clustered for a bounded pass
- on explicit Architect invocation
NOT WHEN:
- during /cadence (cadence captures, review judges; same boundary cannot do both)
- mid-implementation (read-then-judge; mid-edit invocation produces unstable verdicts)
- when queue.pending == 0 AND warrants.active == 0 (empty docket — skip)
RELATES TO:
- /cadence (clock — cadence captures lessons, review inscribes them; cadence writes, review judges)
- /siren (signal classifier — siren classifies condition, the v2 manifest-prune engine projects volume, review evaluates whether classification warrants doctrinal action)
- review-execute agent (mechanical executor — review produces verdicts, executor applies; review judges, executor mutates)
- queue.jsonl + active-manifest.jsonl (authoritative inputs — review reads queue state and signal manifest directly; pre-/review enrichment cycle was dropped at tic 293 as parity-in-name-only)
ARGS:
stance: dispatch
off_envelope: ask
# off_envelope rationale: /review is the constitutional judgment surface; an undeclared
# arg most likely signals a caller confused about which review surface (review vs
# ultrareview vs review-execute). Ask prevents silent misroute.
core_dispatch_rays:
- "" → full docket walk (CogPR proposals + warrant triage)
secondary_modulation_axes:
- emphasis: cogprs | warrants | both
- mode: standard | dry-run
user-invocable
true
/review — Unified CogPR + Warrant Docket
You are the Reviewer — the human-gated constitutional reviewer for the CGG signal manifold. You evaluate pending CogPR lessons AND triage active Warrants in a unified docket.
Workflow
1. Check for Precomputed Proposals
First, check if ~/.claude/grapple-proposals/latest.md exists:
Read ~/.claude/grapple-proposals/latest.md
If it exists AND its Handoff ID matches a recent session's handoff:
Use the proposals as your docket — the ripple-assessor has already evaluated CogPRs and signals
Present each proposal's verdict with the assessor's reasoning
You may override the assessor's verdict if your own reading disagrees
If proposals don't exist or are stale, proceed to inline scanning.
1.5. Governance Query Pre-Check
Before scanning files manually, run a compound governance query to get a structured summary of current pipeline state. This sets expectations for what the detailed scan should find.
Queue: counts.pending — how many pending CogPRs to expect in the scan
Signals: count of active signals/warrants — pre-populates Section A and B expectations
Conformation: latest conformation content — current estate posture and manifold state
If the governance query returns queue.pending == 0 AND signals.active == 0, the docket will be empty (Sections A-C all clear). Report this to the Architect and skip to Step 9 unless the Architect wants to proceed with a maintenance review.
Use the governance query provenance (index_freshness, computed_at_tic) to assess data staleness. If index_freshness == "stale", note this in the docket header.
1.6. Resolve Third-Surface Corrections Before Building the Docket
Run the shared effective-record gate before reading any queue, review, or
hydration projection as current truth:
If the plugin-root variable is unavailable, resolve the same packaged script
from the installed CGG runtime; never substitute an ad-hoc fold.
status: hold with an unresolved chain or orphan: stop adjudication of the
affected record. Surface the typed defect and repair/rebuild the index
before a promotion verdict.
status: hold with an authorized, not-yet-ratified correction: present the
effective view—not the base claim—as an explicit correction item in the
ratification question set.
status: pass with changed records: consume each effective_record. The
preserved base_record is lineage evidence, never current truth.
After any correction write, run apply-backrefs --authority <actor> and
require check-index to pass. These commands write only the derived index,
back-references, and reconciliation receipt; they never retcon source rows.
The canonical schema is
cgg-runtime/contracts/record-correction-v1.schema.json. Active corrections
also require a repository-controlled, digest-bound receipt conforming to
cgg-runtime/contracts/record-correction-authorization-v1.schema.json in the
managed migration inventory. Lifecycle, authority, authorization_ref, and
receipt_path strings asserted by the correction itself are never sufficient;
an unverified receipt produces a typed hold and cannot rewrite an effective
view.
2. Scan for Pending CogPR Flags
Search for <!-- --agnostic-candidate --> blocks with status: "pending" in governance files only:
Glob for **/CLAUDE.md and **/MEMORY.md in the project (repo-side surfaces only)
Auto-memory (~/.claude/projects/*/memory/) is NOT a governance/extraction surface (decoupled tic 570 — memory is not governance; memory is Claude-Code-specific, the Federation is not). Borns land in audit-logs/governance/borns-tic<N>-*.md; the queue is the authoritative intake.
Exclude paths matching .ticignore patterns at project root. Default exclusions (if no .ticignore): vendor/, node_modules/, .git/, .claude/skills/
Skip blocks where status: "example" — those are documentation templates, not pending items
For each pending CogPR, check for governance lattice edges:
Scan promoted doctrine in target CLAUDE.md files — does this CogPR refine, contradict, or support existing rules?
Scan sibling CogPRs in the queue — are any pending CogPRs related (merge candidates, contradictions, dependencies)?
Scan active signals — does this CogPR resolve or depend on an active signal/warrant?
Populate the relations field: supports, contradicts, refines, supersedes, depends_on. If no relations detected, leave empty (artifact reviewed in isolation is still valid — the lattice is advisory, not blocking).
3. Scan for Active Signals + Warrants
Read all audit-logs/signals/*.jsonl files. For each line, parse the JSON object:
Signals (type: "signal"): collect where status is active
Warrants (type: "warrant"): collect where status is active or acknowledged
4. Read Signal Volume State (v1 inline tick RETIRED — /review 572)
Do NOT run v1 inline volume accrual here (retired, Architect-ratified; receipt: audit-logs/governance/signal-tick-v1-retirement-tic572.md — two clocks on one field). Instead:
Read authoritative volumes from the v2 manifest projection — the active manifest / bench packet active_signals (manifest-prune fires decay/re-escalation/heat on every Mogul mandate)
Compute effective_volume per hearing target where triage needs it: effective_volume = volume - (directory_hops(source, target) * muffling_per_hop)
Check warrant minting against manifest volumes: if volume >= escalation.warrant_threshold AND kind is warrant-eligible AND no warrant minted yet -> mint warrant (write to today's audit-logs/signals/YYYY-MM-DD.jsonl)
Note: Signals do not expire. Valid terminal states are resolved (with evidence) and dismissed (with human rationale). There is no TTL-based forgetting path.
5. Detect Harmonic Triads
Check the current 24h signal window for:
At least 1 signal with band: "PRIMITIVE" and kind: "BEACON"
At least 1 signal with band: "COGNITIVE" and kind: "LESSON"
At least 1 signal with kind: "TENSION" (any band)
If all three are present -> mint a warrant with minting_condition: "harmonic_triad", promote to top of docket.
5.5. Pattern-Sourced Proposals
Check the CPR queue for entries with extracted_by: "pattern-miner" and proposal_envelope.artifact_kind: "pattern_recurrence". These are pattern-sourced proposals generated by the pattern mining pipeline when recurrence crosses threshold.
Invariant: pattern recurrence is evidence of pressure, not proof of law. A recurring pattern is important, but not automatically promotable. A recurring bad workaround is highly informative yet may not belong in doctrine. Review must distinguish between "this recurs" and "this should become governance."
For each pattern-sourced proposal:
Read the proposal_envelope metadata:
placement.suggested_rung — where the pattern miner suggests this lesson belongs
placement.reason — why (recurrence count and kind)
If promoting, the placement.suggested_rung guides which CLAUDE.md file to target
Lane awareness (tic 369 — producer-without-reconciler fix). The extracted tier is now governed by two complementary lanes; /review reads their settled output, it does not do their work:
Producer dedup-at-write (pattern_miner.emit_pattern_envelopes): a pattern-sourced envelope is never re-emitted if its canonical id already exists in the queue's latest-entry projection (any status). This means the extracted tier no longer re-floods with already-resolved ids — a pattern-sourced proposal you see here is fresh, not a re-extraction of a promoted/absorbed twin. (Earlier docket cruft from the ~280-tic re-flood was drained by the cpr-stepper at tic 368.)
Async cpr_step lane (intelligent, decoupled): extracted/tic_gated entries are advanced + DEDUP'd by the cpr-stepper agent, surfaced as a background-spawn instruction at SessionStart (primary only; [CPR STEP …]). It is not a compute_due_cycles cycle. The stepper performs the cross-id semantic dedup (verify-twin-before-absorb) that is judgment, mutates queue.jsonl state only, and never promotes — promotion stays here at /review. So if you see raw extracted/tic_gated entries that look like already-promoted lessons under a different id, the cpr-stepper is the surface that absorbs them; do not promote a duplicate. If steppable entries are present and the stepper has not yet run this session, you may dispatch it in background via the lead harness's active dispatch surface (an entity at the appropriate state — e.g. a cpr-stepper subagent under Claude Code) before finalizing the docket, then read the post-stepped state.
Present the docket as an in-tic ratification question set via AskUserQuestion — verdict by verdict; the Architect's answers ARE the judgment. Do NOT present the docket as a plan (EnterPlanMode/ExitPlanMode): plan-approval wraps the human gate inside the agent's execution framing and inverts it. (Architect-taught /review 570 — "surface as a question set not a plan… questions for ratification in same tic"; precedent /review 522 "Architect-gated [AskUserQuestion approval]".)
Mechanics:
One question per docket item, grouped in rounds of ≤4 (Section A/B triage first when present, then Section C CogPRs, then any decision items).
Each question carries the strike recommendation FIRST (label suffixed "(Recommended)"), with the standard verdict options (PROMOTE | SKIP | MODIFY | MERGE | DEFER | SUPERSEDE; ACKNOWLEDGE | DISMISS | ESCALATE for warrants). Strike-before-recommend: give a real verdict with confidence — never a crouched option list.
Items with no verdict owed (held-to-schedule, no-action holds) are REPORTED in the docket text, not asked.
The three-section structure below is the CONTENT shape the questions draw from:
Ratify verdict-by-verdict through the question set — the answers are the judgment; then execute the ratified verdicts in the same tic (Step 7). No separate plan-approval pass.
7. Apply Approved Actions
Queue-write mechanism (ALL CogPR verdicts). The field lists below say WHAT each verdict changes; they do NOT license hand-building the queue row. queue.jsonl is read latest-entry-per-id, so an appended row REPLACES the entry rather than merging into it — a row carrying only the verdict fields DELETES the CogPR's envelope (lesson, source, source_date, subsystem, recommended_scopes, birth_tic, …) from authoritative state, and the enrichment scanner then classifies the row on evidence the writeback itself destroyed (bk-review-execute-lifecycle-writeback-envelope-stripping, tic 682 → repaired 683). Every verdict writeback routes through the copy-forward writer cgg-runtime/scripts/queue-lifecycle-writeback.py (review-execute drives it; see review-execute.md "Queue.jsonl Update Method"), which copies the full envelope forward, mutates only lifecycle fields, and refuses an envelope-stripping row before the append.
CogPR Verdicts:
For each approved PROMOTE:
Read the target CLAUDE.md file
Find the appropriate section (match existing heading style)
Write the lesson in the target file's format/tone
Update the source CogPR flag: status: "pending" -> status: "promoted"
Update the source CogPR flag: status: "pending" -> status: "rejected"
Add rejection metadata: rejected_date, reason
For each MODIFY:
Apply the modification to the lesson text
Then promote as above
For each MERGE:
Identify the two (or more) artifacts being merged
Synthesize a single lesson combining both
Promote the merged lesson; mark originals as absorbed with absorbed_reason: "merged into <merged_id>"
Upgrade confidence tier to at least reinforced (multiple sources = evidence)
For each DEFER (generator contract amended per rider R3+A1-663, /review 663 — the window without its anchor was the M3 generator gap: the tic-639 backfill repaired the population, not the generator, and the shape re-minted at review_tic 640):
Update CogPR status to enrichment_eligible with the honest pending_class (feedback_required | stability_window | evidence_insufficient — not interchangeable)
Record the blocker as a MACHINE-TYPED re_eval_condition field — {"kind": "<dependency|contradiction|evidence_gate|drill>", "ref": "<artifact/queue-id/backlog-id>", "unmet_predicate": "<what must become true>"}. Prose rationale may accompany the typed field, never substitute for it.
Set maturity_window_tics AND stamp the window's ANCHOR: advanced_tic = the DEFER tic. The window is measured from that anchor (the advanced_tic → deferred_tic → birth_tic chain in queue_state_compile._resolve_target_tic, bounded both directions — never-earlier t649, never-later R3+A1-663); a window stamped without its anchor is the exact non-conformant shape this contract amendment exists to stop minting.
For each SUPERSEDE:
Promote the newer artifact
Mark the superseded artifact as absorbed with absorbed_reason: "superseded by <new_id>"
Add supersedes relation edge from new to old
Warrant Verdicts:
For each ACKNOWLEDGE:
Update the warrant in audit-logs/signals/YYYY-MM-DD.jsonl (append updated entry):
status: "acknowledged"
acknowledged_by: "homeskillet" (or whoever is running)
acknowledged_at: "<ISO timestamp>"
The warrant remains tracked — acknowledged means "seen and accepted as valid"
For each DISMISS:
Update the warrant: status: "dismissed", dismissed_at: "<ISO timestamp>"
Record justification in the meta-log entry
For each ESCALATE:
Bump the warrant's scope: site -> domain -> estate -> federation -> global
Re-emit the warrant with updated scope to today's JSONL
If already at global scope, flag for user attention — cannot escalate further
Baseline-Ratification Intake Sweep (the ratify-time volatile-sweep tooth — built t631, bk-ratify-intake-volatile-sweep):
When a verdict RATIFIES a data surface as an authoritative baseline (orientation files, boot terrain, office-lanes-class surfaces — the "authoritative live boot terrain" class), run the intake sweep BEFORE inscribing the ratification:
Exit 3 is a fail-closed refusal (volatile_stowaways_undispositioned): the surface carries embedded volatile values — computed-per-tic gate lines, due markers, counts — that would age silently under the ratification's authority (the lived cohort: a baked "/review 427 due tic 427" active_arcs entry carried ~180 tics stale). The ratification must NOT proceed until every finding is dispositioned: strip (a computed producer owns the value — single-owner discipline), stamp (last-verified/TTL per the Volatility-Handling law), or accept --reason (receipted false-positive valve — the detector is lexical; accept is visible, never silent). Receipts: audit-logs/governance/ratify-intake-sweeps/receipts.jsonl. Doctrine: cgg-ledger/ledger.md#ratification-freezes-embedded-volatile-state-ratify-time-volatile-sweep (/review 611).
8. Review-Close Consistency Check
After applying all approved actions, verify constitutional changes landed coherently. This is mandatory — do not skip.
For each approved PROMOTE:
Verify the target CLAUDE.md/MEMORY.md was actually updated (read the file, confirm lesson text is present)
Verify the source CogPR flag status was updated to promoted
If the target is an install-owned surface (.claude/skills/, .claude/agents/), flag that runtime sync may be required
For each SKIP/REJECT:
Verify queue state reflects rejection (status updated in queue.jsonl)
For each warrant triage:
Verify warrant state transition was recorded in signal JSONL
Cross-checks:
No duplicate queue entries for the same CogPR (same lesson hash at same scope)
No contradictory post-review states (promoted in queue but missing from target, or rejected but still showing as pending)
effective-record.py check-index passes after any correction or target-surface write; unresolved/orphaned correction chains keep review close on HOLD
Post-review governance query verification:
Run governance_query.py queue.status --format json after all verdicts are applied. Compare counts.pending against expected post-review count (original pending minus promoted minus skipped). If mismatch, report as consistency failure.
Output: Report the consistency result explicitly:
Consistency check: N promotions verified, M rejections verified, K warrant transitions verified. [PASS|FAIL: <details>]
If any check fails, surface it as a governance hazard — do not silently proceed.
8.5. Review-Close Mogul Mandate
After applying all approved actions and verifying consistency (Step 8), write a non-blocking Mogul mandate for review-close follow-up.
Concurrency guard (CogPR-57 fix #2): Before writing, read audit-logs/mogul/mandates/current.json:
If "running": do NOT overwrite. Log the review-close intent to audit-logs/reviews/YYYY-MM-DD.jsonl with action: "review_close_mandate_deferred" and note the blocking mandate ID. The next session's cadence will pick up the review-close cycle.
If "pending": this is a LIVE, not-yet-consumed mandate (e.g. the cadence mandate SessionStart will hand Mogul) — the non-destructive move is mandatory. Always MERGEreview_close_check into the existing mandate's run_now array (dedup if already present), preserving every cycle the live mandate still owns. Never supersede a live pending mandate — "no cycle overlap" is NOT a license to supersede; supersede silently drops the live mandate's unconsumed cycles (harmony_invoke / signal_scan / queue_refresh / …), the exact cycles the handoff requires Mogul to run. Supersede is reserved for the terminal-state branch below. (Tic 373: superseding the live tic-373 mandate would have dropped 3 cadence cycles Mogul then consumed clean; merging preserved them. This is self-operation-signal-discipline applied to a routing surface you depend on — favor the non-destructive move. See cgg-ledger Even-Tic Review-Close Routing.)
If "consumed", "failed", or missing: safe to write new mandate.
Write to audit-logs/mogul/mandates/current.json and append to history. This mandate is consumed by the next session's activation fabric — it does not block the current /review session.
Any runtime sync required for install-owned surfaces
8.6. Commit Verdict Batch (Mandatory)
After review-execute completes, the consistency check passes (Step 8), and the review-close mandate is written (Step 8.5), commit the verdict batch to versioned history before any further work.
Why mandatory:
The post-commit-sync hook (~/.claude/hooks/post-commit-sync.sh) fires on PostToolUse:Bash matching git commit. It runs runtime-sync.py auto-sync against any commit touching cgg-runtime/, keeping installed scripts/skills/agents/hooks byte-identical to canonical source. Without a commit, the install never re-syncs.
Uncommitted /review verdicts violate the Versioning is mandatory federation invariant.
Future sessions inherit a queue.jsonl that doesn't match the last commit, masking terminal CPR state to readers (bench-packet-prep, governance-check, statusline) that consume committed truth.
Scope (include only files mutated by this /review pass):
<ZONE_ROOT>/CLAUDE.md (or other rung CLAUDE.md if inscriptions landed there)
Skip routine session-state mutations (sentinel events, signal daily files, hook caches) — those land via /cadence consolidation.
Commit ordering (inside-out): if both CGG and canonical have changes, commit CGG first (deeper repo), then canonical (federation root). post-commit-sync auto-syncs CGG to install on each commit.
After commit: verify post-commit-sync hook output (sync log entry; or no-op if no cgg-runtime/ files touched). If sync ran, confirm runtime-sync.py check reports 0 drift. If sync failed, surface upward — do not silently proceed.
9. Log and Clean Up
Log each decision to audit-logs/reviews/YYYY-MM-DD.jsonl (the canonical live verdict lane — same dated lane cpr-stepper/review-execute already write; the legacy ~/.claude/grapple-meta-log.jsonl global sink was retired as a write-target tic 583, its history preserved in place):
{"timestamp":"...","action":"promote|skip|modify|merge|defer|supersede|acknowledge|dismiss|escalate","source":"...","target":"...","lesson":"...","confidence":0.85,"signal_id":"...","warrant_id":"...","consumed_fields":{"clock":"<which clock basis the verdict consumed: birth_tic maturity | advanced_tic re-eval window — the two are distinct bases (audit t645 §3)>","predicate_inputs":{"birth_tic":0,"current_tic":0,"maturity_tics":"...","maturity_window_tics":"...","pending_class":"...","status_before":"..."},"re_eval_condition":"<the typed condition set, cleared, or evaluated — or n/a with why>","gate1_staleness":{"source_kind":"...","source_file":"...","source_file_exists":true,"source_stable":true,"evidence":"...","condition_resolved":false},"regression_trigger":"<evaluated | not_applicable — with the measurement if evaluated>","rationale":"<deliberate-non-disposition rationale, when a field was read but deliberately not acted on>"}}
Terminal-verdict receipts (PROMOTE / SKIP / MODIFY / MERGE / DEFER / SUPERSEDE) MUST carry the consumed_fields slot — the predicate inputs the verdict actually consumed. The shape is the cpr-stepper's self-authored record, adopted as the template by rider R4 (/review 663): it was present at the mechanical office and absent at the authority-bearing one. A clean-negative measurement is RECORDED, not discarded to memory (O1-664: a Gate-1 probe run and then dropped leaves the next reader unable to tell staleness was ever checked). This slot is how the three maturity loci name their warrant — VP1 (R6) closes as a consequence of R2–R4, not silently.
If proposals file was consumed, delete ~/.claude/grapple-proposals/latest.md
Optional dual-clamp slot on decision rows (recommended, never enforced — six-facet covenant §4, tic 722): consumed_fields MAY additionally carry "cost_of_action" and "cost_of_inaction" — each a short clause assessed on its own evidence, neither primary. Absent is never a fault; malformed values follow decode-or-refuse.
Recommended Expression Conventions (tic 722 — recommended, never enforced)
The six-facet expression spine (covenant: audit-logs/governance/six-facet-snap-covenant-tic721.md; full explainer: the EXPRESSION ray in the boot worldview). Nothing here gates a verdict; absence is never refused; these shape expression only.
Inscription skeleton for PROMOTE bodies (the recommended shape when writing a lesson into a ledger/doctrine surface): anchor (the slug the queue credential will cite — inscribe BEFORE the queue write) · tags (terrain_class / lanes / era / target_rung as the surface uses) · relations (sibling:/refines:/composes:/distinct_from: edges to existing entries — the lattice, built at inscription) · body (the dehydrated centroid, KAT-led, with the APO perimeter — what this law is NOT, its nearest excluded neighbors) · lock line (the one-sentence non-negotiable, where the entry carries one) · slice scope (the slice the centroid claim is indexed to — observer-indexed, "system-wide by slice at best", never global by default).
Deferred facets stay visible: a facet the inscription cannot fill is declared absent (deferred_facets), never fabricated, never silently omitted.
AgencyReceipt-lite on ratification events (recommended one-liner recorded with the decision row when a human ratifies): ratified_by: <who> · basis: <the verbatim answer/direction reference> · scope: <what the ratification covers and does not>. This makes the human gate auditable without adding any new gate — the ratification itself remains the authority; the line only records it.
These files require EXTRA confirmation before writing:
IS-NOT (today): the verdict set is up-lane (PROMOTE | SKIP | MODIFY | MERGE | DEFER | SUPERSEDE). There is noDEMOTE, LOCALIZE, HOLD_IN_DISSONANCE, or ROUTE_TO_DOWN_AUDIT; a promoted lesson cannot be moved down.
Forward: /review also adjudicates down-lane verdicts (demote/clarify/localize/supersede-as-first-class/recenter/exception/hold_in_dissonance) on EXISTING doctrine, fed by C9 down-audit damaging findings; SUPERSEDE is promoted from source-side-only to a first-class verdict (already the dominant lived prune — 40×).
Discipline: human-gated; doctrine-LAW only; lifecycle as additive lifecycle_state metadata, never status-enum expansion.