Objective
Qualify the exact final policy against the authoritative physical runbook before enforcement.
Finish Line
Two distinct signed shadow trains complete with every disagreement resolved and none unresolved or legacy-correct.
Current Status
Parked at Chris's request (2026-09-08): No active execution is underway for this plan. Resume only when this workstream is explicitly selected again; the evidence, remaining gates, dependencies, and next steps below remain authoritative.
Signed shadow qualification remains incomplete. Preserve retained Train 1 evidence and Train 2 artifacts without upgrading partial evidence to an approved ledger.
The migration workstream #681 has prepared and internally distributed signed 1.0.66 build 202609072309 from d7eac129ecb30efa42d04fb18b2c8e830a57b6b6 on all four platforms. Its corrected 1.0.65-to-1.0.66 beta comparison and bounded Mac app/widget runtime proof are recorded in #681. That beta slice does not satisfy a complete current-policy shadow train or the RC/release all-surface floor. Shared-view lineage and visual/placement approval remain incomplete.
The operational entry point is docs/validation-authority.md. Use current-policy shadow evaluation to classify disagreements while preserving the physical runbook as authoritative. The existing live submission evidence verifier remains enabled in enforce mode and must reject missing current-policy evidence; shadow evaluation is not authorization to bypass it. Two distinct signed trains with no unresolved or legacy-correct disagreement remain required before #612's canary/cutover work.
The bounded collection repair #680 is merged and independently approved by Opus and Gemini. Hosted retained Train 2 run34179639223 passed on merge8b2d7ba with 16 verified/agent-inspected PNGs and eight explicit Mac/tvOS unsupported records; exact inputs, bindings and visual limitations are recorded in #655. This is historical 1.0.63 shared-view collection evidence, not current 1.0.66 approval, human approval, or a completed signed shadow train. #655 remains open for Mac/tvOS adapter gaps and consolidated review. Unsupported capture must not become an unrequested signed-gallery walkthrough; existing Mac render tests remain diagnostic output rather than formal receipts.
Next: qualify the next applicable natural signed train against its complete authoritative comparison, manifests, current runtime evidence, shared-view and placement requirements, and approved lineage. Resolve every disagreement and retain fragile/reference-only replay classifications and residual risks. Documentation reconciliation approves no train, changes no policy or threshold, and does not manufacture another full-fleet ceremony.
Documentation and operator guidance reconciled in PR #691, merged as 3258d08ee36bd9f2c22470e4b1ccb23da6f482f5. Opus and Gemini approved the exact diff; local gates and PR CI/CodeQL passed. This is documentation and discovery metadata only.
Acceptance Criteria
Relationships
Objective
Qualify the exact final policy against the authoritative physical runbook before enforcement.
Finish Line
Two distinct signed shadow trains complete with every disagreement resolved and none unresolved or legacy-correct.
Current Status
Parked at Chris's request (2026-09-08): No active execution is underway for this plan. Resume only when this workstream is explicitly selected again; the evidence, remaining gates, dependencies, and next steps below remain authoritative.
Signed shadow qualification remains incomplete. Preserve retained Train 1 evidence and Train 2 artifacts without upgrading partial evidence to an approved ledger.
The migration workstream #681 has prepared and internally distributed signed 1.0.66 build
202609072309fromd7eac129ecb30efa42d04fb18b2c8e830a57b6b6on all four platforms. Its corrected 1.0.65-to-1.0.66 beta comparison and bounded Mac app/widget runtime proof are recorded in #681. That beta slice does not satisfy a complete current-policy shadow train or the RC/release all-surface floor. Shared-view lineage and visual/placement approval remain incomplete.The operational entry point is
docs/validation-authority.md. Use current-policy shadow evaluation to classify disagreements while preserving the physical runbook as authoritative. The existing live submission evidence verifier remains enabled inenforcemode and must reject missing current-policy evidence; shadow evaluation is not authorization to bypass it. Two distinct signed trains with no unresolved or legacy-correct disagreement remain required before #612's canary/cutover work.The bounded collection repair #680 is merged and independently approved by Opus and Gemini. Hosted retained Train 2 run34179639223 passed on merge8b2d7ba with 16 verified/agent-inspected PNGs and eight explicit Mac/tvOS unsupported records; exact inputs, bindings and visual limitations are recorded in #655. This is historical 1.0.63 shared-view collection evidence, not current 1.0.66 approval, human approval, or a completed signed shadow train. #655 remains open for Mac/tvOS adapter gaps and consolidated review. Unsupported capture must not become an unrequested signed-gallery walkthrough; existing Mac render tests remain diagnostic output rather than formal receipts.
Next: qualify the next applicable natural signed train against its complete authoritative comparison, manifests, current runtime evidence, shared-view and placement requirements, and approved lineage. Resolve every disagreement and retain fragile/reference-only replay classifications and residual risks. Documentation reconciliation approves no train, changes no policy or threshold, and does not manufacture another full-fleet ceremony.
Documentation and operator guidance reconciled in PR #691, merged as
3258d08ee36bd9f2c22470e4b1ccb23da6f482f5. Opus and Gemini approved the exact diff; local gates and PR CI/CodeQL passed. This is documentation and discovery metadata only.Acceptance Criteria
Relationships