Close out INFO-WP-0030; record second Emission Cadence declaration
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

INFO-WP-0030: register practice-pattern/explicit-unsafe-diagnostic-mode
(adapted from coordination-engine's OrwellLoggingDiagnostics candidate,
INFO-DEC-2026-003) at canon 0.13.0, close the assimilation, and notify
coordination-engine for COORDINATION-WP-0004-T02. Workplan finished.

INFO-WP-0029: record activity-core's source-owned declaration (T03/T04
done) with its expected-rate/calendar-schedule incompatibility as
demand/EmissionExpectedRateCalendar.md, and record audit-core's
structural-only observer evaluation of net-kingdom's declaration as a
steward note. No party has yet produced a real observer result against
traffic, so T05 and the workplan stay blocked on external action.

Updated artifact-count and practice-pattern-count assertions in
tests/test_cli.py and tests/test_service.py for the new artifact.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 317218@bnt-lap001
Assistant-Session: a8d6c0ab-c70f-4610-a288-576f44d747d4
This commit is contained in:
tegwick 2026-09-28 00:06:16 +02:00
parent 1778b00ca6
commit e0ca7de63b
26 changed files with 810 additions and 129 deletions

View file

@ -15,6 +15,36 @@ semantics.
---
## 0.13.0 — 2026-09-27
### Added — ExplicitUnsafeDiagnosticMode practice pattern
**Change.** Registered `practice-pattern/explicit-unsafe-diagnostic-mode`
(`infospace/patterns/ExplicitUnsafeDiagnosticMode.md`, `status: candidate`,
`version: 0.1`) in `infospace/artifacts/index.yaml`. It imports
`Log`/`LogRecord` from `model/observability`, `DataClassification`/
`Sensitivity` from `model/data`, and `EnvironmentPromotion` from
`model/devsecops` rather than restating them.
**Provenance.** Adapted from coordination-engine's `OrwellLoggingDiagnostics`
candidate (`INFO-DEC-2026-003`, `assimilation/orwell-logging-diagnostics`,
now `closed`). The pattern's one known use is tmux-amq `04de219`
(`src/tamq/diagnostics.py`, `src/tamq/cli.py`), naming the one observed test
and stating which invariants it does not cover, per `INFO-WP-0030`.
**Rationale.** The candidate resolved a recurring tension (diagnosability
versus sensitive-field omission) not covered by the Observability, Data, or
Security models, and had an implemented known use. `PracticePatternScheme`
is the existing shape for that.
**Breaking:** no. New candidate-status artifact; no existing concept renamed
or reassigned.
**Validation.** `make check` passes; `emission-review` and other prior
behavior unaffected by this change.
---
## 0.7.0 — 2026-09-04
### Added — ecosystem-wide EmissionCadenceDeclaration contract

View file

@ -1,7 +1,7 @@
repository: info-tech-canon
title: InfoTechCanon
status: service-baseline
version: 0.12.0
version: 0.13.0
description: >
An evolving, markdown-first canon for building interoperable, adaptable,
and extensible information-processing systems.
@ -210,9 +210,10 @@ assimilation:
- id: assimilation/orwell-logging-diagnostics
source: coordination-engine OrwellLoggingDiagnostics candidate
disposition: adapt
status: decided
status: closed
path: infospace/assimilation/orwell-logging-diagnostics/
workplan: INFO-WP-0030
produced: practice-pattern/explicit-unsafe-diagnostic-mode
first_proofs:
near_term:

View file

@ -0,0 +1,67 @@
# Demand: Emission Cadence expected-rate calendar scope — non-uniform scheduled activity
**Status:** proposed (change proposal to the Emission Cadence standard)
**Date:** 2026-09-22
**Source:** activity-core (source owner), domain `infotech`
**Owner:** InfoTechCanon Emission Cadence standard (`standards/emission-cadence`)
**Consumer evidence:** activity-core `docs/emission-cadence/activity-core-evidence.yaml` (commit `f20db47`)
**Feedback:** `feedback/2026-09-22-activity-core-emission-cadence-declaration.md`
**Workplan:** `INFO-WP-0029` (T04 records it; no design workplan exists yet)
---
## Demand signal
A source-owned `expected-rate` entry can express only a fixed wall-clock
window per event class. `activity-core`'s `sbom_catchup` activity runs on a
weekday-only cron (`15 9 * * 1-5 Europe/Berlin`). Neither wall-clock window
size is honest for that schedule:
- A window sized to the daily period plus run slack (`PT26H`) is quiet on
Saturday and Sunday mornings for a correct reason — the activity is not
scheduled then — and `expected-rate` has no way to say so. Every weekend
raises a false finding.
- A window wide enough to tolerate the weekend gap (`P4D`) can no longer
detect a genuine outage that starts and ends midweek, because it is now
wider than the real inter-run interval on weekdays.
The consumer fell back to `heartbeat-or-reconciliation`/`reconciliation`
against its own local activation count. That is correct and preserves
validity, but it moves a genuinely rate-shaped activity out of the form built
for rate expectations, and it depends on the source holding its own local
count to compare against — an observer with no access to that local count
cannot evaluate this stream at all.
## Relationship to the other open gap
`demand/EmissionActivityScope.md` (net-kingdom) describes a related but
distinct problem: a source that can emit only while an attended process runs,
where `expected_min: 0` is the only honest floor and silence carries no
information outside a session. This demand is different: activity-core's
source runs continuously and its schedule is fully known in advance — the
problem is that the schedule is calendar-shaped, not that the source is
intermittently absent. Both gaps point at the same root limitation (a single
wall-clock window cannot represent every real scheduling shape) but call for
different fixes, and a standard revision should look at both together before
committing to one.
## Options named by the consumer
1. Let an `expected-rate` entry name a calendar — a cron expression and
timezone — so the evaluation window counts scheduled slots rather than
wall-clock time. A finding fires on a missed scheduled slot, not on an
off-calendar quiet period.
## Constraints on a disposition
- A new field changes the wire schema (`0.1`). Under the `0.x` rules that is
allowed with migration guidance. Existing declarations stay valid only if
the field is additive and optional.
- Declarations pinned before the change stay pinned to their digest. Stable
promotion needs declarations against one fixed reading of the contract, so
a schema change before stable resets which pin later evidence should use.
- This demand is not accepted. Choosing a design (calendar-aware
`expected-rate`, a new form, or documenting the `reconciliation` fallback
as the intended answer for calendar-shaped schedules) is a canon-owner
decision, and should be made alongside a disposition on
`demand/EmissionActivityScope.md` rather than separately.

View file

@ -91,5 +91,22 @@ None.
independent of this repository. It also records an incompatibility, which is
the third element of the stable gate (standard §10). It is not a second
declaration and not an observer result. The standard stays at candidate.
- **Observer evaluation received, and it does not satisfy the gate.**
audit-core replied 2026-09-22 (State Hub message `266abb18-0a85-4d85-9ff2-0745949c9587`,
thread `368e54bf-6401-4184-a1d2-04f133945d40`), against its own AUDIT-WP-0009
implementation (audit-core `01468ff`, read at contract digest
`b08b4d95fc4b0bd3`): structurally, both entries in this declaration
validate. Operationally, audit-core registers no `local-identity` sender and
holds none of its events, so nothing sits behind `compare_observed` — by
audit-core's own account this is "not an observer result on the stream, and
it should not satisfy your section 10 stable gate." A second incompatibility
surfaced: the declaration's heartbeat block names an `event_class`, but
audit-core evaluates one heartbeat class (`audit-core.heartbeat`, carrying
the vouched-for class in `data.class`) driven by a separately registered
`heartbeat_classes` list — the two can drift apart, and neither side has
reconciled that yet. audit-core states a real observer result needs a
source with an expected-rate or reconciliation declaration registered there
and sending traffic — which is not this declaration. INFO-WP-0029-T05
(observer result) stays open on the strength of this reply alone.
- The NetKingdom security profile's rare-heartbeat MUST failure belongs to
NetKingdom's profile. It is not a defect of the generic contract.

View file

@ -0,0 +1,105 @@
---
id: feedback/2026-09-22-activity-core-emission-cadence-declaration
type: consumer-feedback
status: reviewed
date: "2026-09-22"
consumer: activity-core
consumer_domain: infotech
canon_version: "0.13.0"
artifacts:
- standard/emission-cadence
related_demand:
- demand/EmissionExpectedRateCalendar.md
related_workplan:
- INFO-WP-0029
spawned_demand:
- demand/EmissionExpectedRateCalendar.md
spawned_workplan: []
---
# Feedback: second source-owned Emission Cadence declaration (activity-core scheduled evidence)
**Consumer:** activity-core
**Canon version used:** contract digest `b08b4d95fc4b0bd3` (Emission Cadence
document 0.2.0, wire schema 0.1)
**Artifacts exercised:** `infospace/schemas/emission-cadence.schema.yaml`,
`standards/emission-cadence/InfoTechCanonEmissionCadenceStandard.md`
**Related demand:** `demand/EmissionExpectedRateCalendar.md`
Source: activity-core's reply to INFO-WP-0029-T03 (State Hub message
`161d5aa5-d2a9-4f6a-b833-3727e06007f8`, thread `f1687805-3153-47c2-9744-05a2b1a6b8c1`),
and the file it published at activity-core commit `f20db47`:
`docs/emission-cadence/activity-core-evidence.yaml`.
---
## Consumer purpose
Declare intended cadence for three scheduled activities emitted as State Hub
progress events — a daily backup, a weekly package prune, and a daily SBOM
catch-up — so an observer could evaluate silence against a fixed schedule.
## Hits
- `expected-rate` with a window sized to the schedule's period plus run slack
(`PT26H` for a daily cron, `P8D` for a weekly cron). Two of the three
entries expressed a fixed-time schedule cleanly this way.
- `heartbeat-or-reconciliation` with a `reconciliation` block, for the third
entry, once `expected-rate` proved unable to express its schedule (see
Gaps).
- `extensions`. `activity-core.definition` and `activity-core.schedule`
carried the activity's own identifiers and cron expression without
touching the generic contract shape.
- The declaration is `contract_valid`: canon-side `emission-review` returns
`ok: true`, `errors: []`, `operational_truth_assessed: false`.
## Friction
- `emission-review` could not be run by the consumer directly; the CLI needs
`infospace-bench`, which is not installable from a package index there. The
consumer worked around this by calling `contracts.py` directly. This is the
same packaging limitation the net-kingdom declaration hit
(`feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md`), now
observed by a second independent consumer.
## Gaps
- **`expected-rate` cannot express a weekday-only schedule.** The third
activity (`sbom_catchup`) runs `15 9 * * 1-5 Europe/Berlin` — weekdays
only. A wall-clock window sized to catch a daily run (`PT26H`) raises a
false finding every Saturday and Sunday morning. A window wide enough to
span the weekend (`P4D`) would hide a genuine three-day outage that starts
midweek. Neither window size is honest. The consumer declared this entry as
`heartbeat-or-reconciliation`/`reconciliation` against its own local
activation count instead, which is correct but sidesteps the form the
activity actually needs. Filed as
`demand/EmissionExpectedRateCalendar.md`.
## Drop candidates
None.
## Steward notes
- **This is the second source-owned declaration from an owner independent of
both net-kingdom and this repository** (INFO-WP-0029-T03). Its
incompatibility — a wall-clock window cannot express a calendar-shaped
schedule — is a different gap from net-kingdom's session-scoped silence.
Both are recorded, per the workplan's framing, as successful outcomes: they
show the contract is implementable and where its `expected-rate` form
currently falls short of a real production schedule.
- **What this counts toward.** Standard §10's stable gate asks for two
source-owned declarations from independent owners plus one observer result.
This declaration is the second. It also records a second, distinct
incompatibility. No observer result yet evaluates this stream specifically:
activity-core's periodic emission into issue-core is currently off in
production (`ISSUE_SINK_TYPE=state-hub`), so this declaration covers State
Hub progress evidence, and no third party has registered as an observer of
that stream. The standard stays at candidate; INFO-WP-0029-T05 (observer
result) stays open.
- Both known incompatibilities (this one, and net-kingdom's session-scoped
silence) point at the same underlying limitation of `expected-rate`: a
single wall-clock window cannot represent activity that is legitimately
bursty, calendar-shaped, or attended-only. A future standard revision
should weigh both before choosing a fix, rather than solving each in
isolation.

View file

@ -98,3 +98,25 @@ reports:
- demand/EmissionActivityScope.md
related_workplan:
- INFO-WP-0029
- id: feedback/2026-09-22-activity-core-emission-cadence-declaration
path: feedback/2026-09-22-activity-core-emission-cadence-declaration.md
date: "2026-09-22"
consumer: activity-core
consumer_domain: infotech
status: reviewed
canon_version: "0.13.0"
artifacts:
- standard/emission-cadence
hits:
- expected-rate (fixed-time schedule)
- heartbeat-or-reconciliation (reconciliation)
- extensions
friction:
- emission-review not runnable by adopter (infospace-bench not installable)
gaps:
- expected-rate cannot express a weekday-only (calendar-shaped) schedule
drop_candidates: []
related_demand:
- demand/EmissionExpectedRateCalendar.md
related_workplan:
- INFO-WP-0029

View file

@ -0,0 +1,33 @@
---
id: agent-brief/practice-pattern-explicit-unsafe-diagnostic-mode
artifact_id: practice-pattern/explicit-unsafe-diagnostic-mode
source_path: patterns/ExplicitUnsafeDiagnosticMode.md
source_kind: practice-pattern
generated: true
---
<!-- GENERATED by info_tech_canon; do not edit by hand. -->
# Agent Brief: ExplicitUnsafeDiagnosticMode
- Artifact ID: `practice-pattern/explicit-unsafe-diagnostic-mode`
- Kind: `practice-pattern`
- Canonical path: `patterns/ExplicitUnsafeDiagnosticMode.md`
- Full source: `patterns/ExplicitUnsafeDiagnosticMode.md`
- Summary: Reusable canon PracticePattern: ExplicitUnsafeDiagnosticMode.
## Retrieval Hints
Imports and anchors:
- `model/data`
- `model/devsecops`
- `model/observability`
- `scheme/practice-pattern`
## Owned Concepts
- `ExplicitUnsafeDiagnosticMode`
## Related Distinctions
No common distinction is anchored directly on this artifact.

View file

@ -5,8 +5,8 @@
This brief summarizes the current canon service surface for agents.
- Infospace slug: `canon`
- Artifact count: 82
- Retrieval index items: 82
- Artifact count: 83
- Retrieval index items: 83
- Primary confidence command: `make validate`
- Refresh generated indexes and views with: `make index`
- Refresh agent briefs and interface templates with: `make agent-briefs`

View file

@ -60,7 +60,7 @@
}
],
"infospace": "canon",
"item_count": 82,
"item_count": 83,
"items": [
{
"canonical_path": "assimilation/canon-federation/ASSIMILATION.md",
@ -2525,6 +2525,42 @@
"title": "AgenticDrivesFunctional",
"warnings": []
},
{
"canonical_path": "patterns/ExplicitUnsafeDiagnosticMode.md",
"id": "practice-pattern/explicit-unsafe-diagnostic-mode",
"imports": [
"model/data",
"model/devsecops",
"model/observability",
"scheme/practice-pattern"
],
"kind": "practice-pattern",
"owned_concepts": [
"ExplicitUnsafeDiagnosticMode"
],
"relationships": [
{
"target": "scheme/practice-pattern",
"type": "conforms_to"
},
{
"target": "model/observability",
"type": "uses"
},
{
"target": "model/data",
"type": "uses"
},
{
"target": "model/devsecops",
"type": "uses"
}
],
"source_path": "patterns/ExplicitUnsafeDiagnosticMode.md",
"summary": "Reusable canon PracticePattern: ExplicitUnsafeDiagnosticMode.",
"title": "ExplicitUnsafeDiagnosticMode",
"warnings": []
},
{
"canonical_path": "patterns/InterfaceDeprecationStrangler.md",
"id": "practice-pattern/interface-deprecation-strangler",

View file

@ -4,7 +4,7 @@
Schema: `info-tech-canon.retrieval-index.v1`
Infospace: `canon`
Items: **82**
Items: **83**
## Common Distinctions
@ -557,6 +557,16 @@ Items: **82**
- Imports and anchors: `model/capability`, `model/governance`, `model/observability`, `model/task`, `scheme/practice-pattern`
- Owned concepts: `AgenticDrivesFunctional`, `AgenticFallback`, `DemandSignature`, `FunctionalInterfaceCandidate`
### ExplicitUnsafeDiagnosticMode
- ID: `practice-pattern/explicit-unsafe-diagnostic-mode`
- Kind: `practice-pattern`
- Canonical path: `patterns/ExplicitUnsafeDiagnosticMode.md`
- Source path: `patterns/ExplicitUnsafeDiagnosticMode.md`
- Summary: Reusable canon PracticePattern: ExplicitUnsafeDiagnosticMode.
- Imports and anchors: `model/data`, `model/devsecops`, `model/observability`, `scheme/practice-pattern`
- Owned concepts: `ExplicitUnsafeDiagnosticMode`
### InterfaceDeprecationStrangler
- ID: `practice-pattern/interface-deprecation-strangler`

View file

@ -1,6 +1,6 @@
schema: info-tech-canon.retrieval-index.v1
infospace: canon
item_count: 82
item_count: 83
items:
- id: assimilation/canon-federation
kind: assimilation
@ -1823,6 +1823,29 @@ items:
- type: related_to
target: practice-pattern/interface-deprecation-strangler
warnings: []
- id: practice-pattern/explicit-unsafe-diagnostic-mode
kind: practice-pattern
title: ExplicitUnsafeDiagnosticMode
canonical_path: patterns/ExplicitUnsafeDiagnosticMode.md
source_path: patterns/ExplicitUnsafeDiagnosticMode.md
summary: 'Reusable canon PracticePattern: ExplicitUnsafeDiagnosticMode.'
owned_concepts:
- ExplicitUnsafeDiagnosticMode
imports:
- model/data
- model/devsecops
- model/observability
- scheme/practice-pattern
relationships:
- type: conforms_to
target: scheme/practice-pattern
- type: uses
target: model/observability
- type: uses
target: model/data
- type: uses
target: model/devsecops
warnings: []
- id: practice-pattern/interface-deprecation-strangler
kind: practice-pattern
title: InterfaceDeprecationStrangler

View file

@ -768,6 +768,24 @@ artifacts:
target: model/observability
- type: uses
target: model/devsecops
- id: practice-pattern/explicit-unsafe-diagnostic-mode
path: patterns/ExplicitUnsafeDiagnosticMode.md
kind: practice-pattern
title: ExplicitUnsafeDiagnosticMode
provenance:
placement: adapted
placement_workplan: INFO-WP-0030
assimilation: assimilation/orwell-logging-diagnostics
known_use: tmux-amq/src/tamq/diagnostics.py
relationships:
- type: conforms_to
target: scheme/practice-pattern
- type: uses
target: model/observability
- type: uses
target: model/data
- type: uses
target: model/devsecops
- id: mapping/purpose-demand-governance-candidates
path: mappings/purpose-demand-governance-candidates.yaml
kind: mapping

View file

@ -1,6 +1,8 @@
# Assimilation — OrwellLoggingDiagnostics
**Status:** Decided. Canon placement is pending under INFO-WP-0030.
**Status:** Closed. Placed under INFO-WP-0030 as
`practice-pattern/explicit-unsafe-diagnostic-mode`
(`infospace/patterns/ExplicitUnsafeDiagnosticMode.md`), canon version 0.13.0.
**Disposition:** Adapt
**Source:** coordination-engine candidate
`docs/orwell-logging-diagnostics-candidate.md` at `628f984`, preserved
@ -65,3 +67,17 @@ pattern's Known Uses.
INFO-WP-0030.
- This disposition does not authorize unsafe logging in any runtime. The
pattern describes a practice, and its adoption stays with each consumer.
## Closure — 2026-09-27
INFO-WP-0030 registered `practice-pattern/explicit-unsafe-diagnostic-mode`
(`infospace/patterns/ExplicitUnsafeDiagnosticMode.md`, `status: candidate`,
`version: 0.1`) in `infospace/artifacts/index.yaml` and `canon.yaml`, at canon
version 0.13.0 (`CHANGELOG.md`). It imports `Log`/`LogRecord` from
`model/observability`, `DataClassification`/`Sensitivity` from `model/data`,
and `EnvironmentPromotion` from `model/devsecops`. Its Known Uses section
cites tmux-amq `04de219` and names the one observed test
(`tests/test_diagnostics.py::test_orwell_log_is_private`), stating plainly
which invariants that test does and does not cover — tmux-amq has no
production/non-production distinction, so invariant 2 (production refusal)
is not demonstrated by this known use. This assimilation is closed.

View file

@ -1,5 +1,5 @@
root: infospace
file_count: 301
file_count: 303
files:
- path: README.md
directory: .
@ -148,6 +148,9 @@ files:
- path: agent/briefs/practice-pattern-agentic-drives-functional.md
directory: agent/briefs
name: practice-pattern-agentic-drives-functional.md
- path: agent/briefs/practice-pattern-explicit-unsafe-diagnostic-mode.md
directory: agent/briefs
name: practice-pattern-explicit-unsafe-diagnostic-mode.md
- path: agent/briefs/practice-pattern-interface-deprecation-strangler.md
directory: agent/briefs
name: practice-pattern-interface-deprecation-strangler.md
@ -718,6 +721,9 @@ files:
- path: patterns/AgenticDrivesFunctional.md
directory: patterns
name: AgenticDrivesFunctional.md
- path: patterns/ExplicitUnsafeDiagnosticMode.md
directory: patterns
name: ExplicitUnsafeDiagnosticMode.md
- path: patterns/InterfaceDeprecationStrangler.md
directory: patterns
name: InterfaceDeprecationStrangler.md

View file

@ -1,4 +1,4 @@
concept_count: 770
concept_count: 771
concepts:
- concept: Canon federation research provenance
owner: assimilation/canon-federation
@ -2754,6 +2754,10 @@ concepts:
owner: practice-pattern/agentic-drives-functional
path: patterns/AgenticDrivesFunctional.md
source: frontmatter.owned_concepts
- concept: ExplicitUnsafeDiagnosticMode
owner: practice-pattern/explicit-unsafe-diagnostic-mode
path: patterns/ExplicitUnsafeDiagnosticMode.md
source: artifact_title
- concept: InterfaceDeprecationStrangler
owner: practice-pattern/interface-deprecation-strangler
path: patterns/InterfaceDeprecationStrangler.md

View file

@ -53,6 +53,7 @@ artifacts:
- model/task
- pattern/intent-scope-purposes
- practice-pattern/agentic-drives-functional
- practice-pattern/explicit-unsafe-diagnostic-mode
- practice-pattern/interface-deprecation-strangler
- practice/intake-and-assimilation
- profile/small-saas
@ -620,6 +621,16 @@ rows:
- related_to
scheme/practice-pattern:
- conforms_to
- artifact: practice-pattern/explicit-unsafe-diagnostic-mode
targets:
model/data:
- uses
model/devsecops:
- uses
model/observability:
- uses
scheme/practice-pattern:
- conforms_to
- artifact: practice-pattern/interface-deprecation-strangler
targets:
model/devsecops:

View file

@ -0,0 +1,235 @@
---
id: practice-pattern/explicit-unsafe-diagnostic-mode
title: ExplicitUnsafeDiagnosticMode
type: practice-pattern
scheme: practice-pattern/0.1
status: candidate
version: "0.1"
summary: Keep an unsafe, field-revealing diagnostic capture opt-in per invocation, refused in production, and confined to a local owner-controlled sink.
aliases:
- OrwellLoggingDiagnostics
uses:
- model/observability
- model/data
- model/devsecops
related_patterns: []
known_uses:
- tmux-amq-orwell-flag
---
# ExplicitUnsafeDiagnosticMode
## Intent
Let a rare local debugging session capture fields that normal logging must
omit, without turning that capture into a standing capability: it is
selectable only per invocation, refused wherever a production policy applies,
written only to a sink the invoking owner controls, and never projected to any
remote or shared destination.
## Context
Use this pattern where a component's normal `Log`/`LogRecord` output
(`model/observability`) must omit fields carrying credentials, message
bodies, or other data a `DataClassification`/`Sensitivity` policy restricts
(`model/data`), but an engineer diagnosing a specific local failure
occasionally needs exactly those fields to see what happened. The component
runs, or can run, in more than one `EnvironmentPromotion` stage
(`model/devsecops`), and at least one of those stages is production or
production-adjacent.
## Problem
Sensitive-field omission and diagnosability compete. Omitting the fields by
default protects them, but it can also hide the one detail that explains a
transport or protocol failure. Relaxing omission to help diagnosis risks
either leaving the relaxed mode enabled by default, letting it run in
production, or letting the captured fields leave the local machine through
normal telemetry, log shipping, or shared CI artifacts — at which point the
exception has become a standing disclosure.
## Forces
- Diagnosis needs the exact fields normal policy omits, not a summary of them.
- The unsafe mode must never become the default; defaults drift toward
whatever is easiest to leave on.
- A production environment cannot honor a request to disclose these fields
regardless of who or what asks for it.
- Local-only retention is only useful if it is still discoverable and
removable by the person who created it.
- Any path that projects general logs, metrics, or CI artifacts elsewhere
becomes a path this data must not travel, even accidentally.
- A warning that is easy to miss does not function as a control.
## Solution
Therefore, provide a single opt-in diagnostic switch with these properties:
1. Safe logging is the default at every verbosity. Raising verbosity alone
must not disclose fields the classification policy restricts.
2. An explicit per-invocation option selects the unsafe mode. Configuration
files, inherited profile defaults, and background startup must not enable
it silently — it is asked for anew, in the invocation, every time.
3. The production `EnvironmentPromotion` stage refuses the option outright.
Wherever it is accepted, emit a visible warning before any additional
field is captured.
4. The mode writes only to a sink the invoking owner controls, at a
permission level that excludes other accounts (for example, a
owner-only-readable local file). It is never added to a `LogStream`,
metrics pipeline, State Hub event, or shared CI artifact.
5. Document precisely which fields the mode can capture. Prefer synthetic
reproduction data over live captures. The invoking owner keeps the
smallest useful capture and removes it after diagnosis, using whatever
procedure that sink's owner defines.
6. Tests verify default omission, the per-invocation opt-in, refusal or
absence of the option in production, sink permissions, and separation
from any remote projection.
## Structure
```text
Invocation
-> unsafe-mode option (explicit, per-call)
-> EnvironmentPromotion check: production? -> refused
-> visible warning
-> Logger (model/observability)
-> default path: LogStream, filtered by DataClassification
-> unsafe path: local owner-only sink, never a LogStream sink
```
The environment check and the routing decision happen at the same
configuration point the normal logger is built from; there is no second place
the unsafe path could be reintroduced.
## Dynamics
An operator invokes the component with the unsafe-mode option because a
specific failure needs fields normal logs omit. The component checks the
current `EnvironmentPromotion` stage; in production the option is rejected or
ignored with an explicit error, and diagnosis proceeds without it. Elsewhere,
the component warns, opens the local sink at a restrictive permission mode,
and logs at full detail for the remainder of that invocation only — the
option does not persist to the next invocation. After diagnosis, the operator
reads the local sink directly and removes it; nothing from this path reaches
any aggregated or shared destination.
## Invariants
1. The unsafe mode is off by default and cannot be enabled by configuration
inheritance, only by an explicit per-invocation option.
2. A production `EnvironmentPromotion` stage refuses the option.
3. Enabling the option always produces a visible warning before capture.
4. The sink is local, owner-controlled, and restricted to the owner's account
(for example, mode `0600`).
5. Nothing captured under the unsafe mode reaches a `LogStream`, metrics
pipeline, State Hub projection, or shared CI artifact.
6. The captured field set is documented, not open-ended.
## Evidence
The practice should produce:
- a test that the default path omits the restricted fields;
- a test that the option is per-invocation and does not persist or inherit;
- a test — or, where the component has no production/non-production
distinction at all, an explicit statement of that absence — that the
option is refused in production;
- a test that the sink is created at a restrictive permission mode; and
- a test or code-path review confirming no remote or shared sink can receive
the unsafe-mode output.
A known use that verifies only some of these should say plainly which ones,
rather than implying full coverage.
## Consequences
Diagnosis gets access to fields it otherwise could not see, without turning
that access into a standing capability or a silent default. The cost is one
more configuration branch to test, a local file an operator must remember to
remove, and — for components with no existing environment distinction — the
need to add one before the production refusal invariant can be verified at
all.
## Failure Modes
- **QuietDefault:** the option is honored from a config file or an inherited
profile instead of being asked for at each invocation.
- **NoProductionCheck:** the component has no way to refuse the option in
production because it has no environment distinction to check against.
- **SharedSink:** captured output lands in the same file, stream, or
aggregator the default logs use.
- **UnboundedCapture:** the mode is undocumented as to which fields it
reveals, so it grows to cover more than diagnosis needs.
- **SilentWarning:** the mode activates without a visible notice, so an
operator can leave it running without noticing.
## When Not to Use
Do not use this pattern to justify collecting sensitive fields the component
could avoid needing in the first place, and do not use it where a
component has no local, owner-controlled place to write a sink at all — in
that case the safer answer is to improve error messages and structured
non-sensitive diagnostics, not to add an unsafe capture mode with nowhere
safe to put it.
## Known Uses
### tmux-amq `--orwell` flag
tmux-amq implements the option at commit `04de219`, in
`src/tamq/diagnostics.py` (the `configure()` entry point) and
`src/tamq/cli.py` (the global `--orwell` flag, plumbed through the CLI's
`configure(args.orwell, ...)` call and a matching `purge --orwell` cleanup
subcommand).
`tests/test_diagnostics.py::test_orwell_log_is_private` observes two of the
invariants directly: enabling the option prints a warning containing
`--orwell`, and the resulting log file is created at permission mode `0600`
(invariant 3 and invariant 4). The per-invocation opt-in (invariant 1) is
observed by construction — `configure()` takes `orwell` as a call argument
with no persisted state — but has no dedicated negative test.
This known use does **not** demonstrate invariant 2. tmux-amq has no
production/non-production `EnvironmentPromotion` distinction to refuse the
option against; it is a local CLI tool run directly by its operator, and
`configure()` accepts `orwell=True` unconditionally. Invariant 5 (no remote
projection) holds by tmux-amq's general architecture — it has no telemetry
export path at all — rather than by a check specific to this mode. Invariant
6 (documented field scope) is not enforced in code; the flag raises the
overall log level to `DEBUG` and adds a file handler rather than gating a
named field list.
Because one known use verifies a subset of the invariants and the pattern has
not yet been observed in a component with a real production stage to refuse,
this pattern stays at `candidate`. A second known use in a component with an
`EnvironmentPromotion` distinction is the evidence that would test invariant
2 and could support promotion to `active`.
## Related Patterns
None yet. A future pattern for field-level redaction policy (which fields a
`DataClassification` restricts, independent of capture mode) would be a
natural neighbor once more than one component needs it stated generically.
## Adoption Checklist
- [ ] Confirm the component has, or can meaningfully check, a
production/non-production distinction.
- [ ] Add the per-invocation option; do not wire it to configuration files.
- [ ] Refuse the option outright when the production stage is detected.
- [ ] Emit a visible warning before capturing any additional field.
- [ ] Route unsafe-mode output only to a local, owner-restricted sink.
- [ ] Document the captured field set.
- [ ] Give the operator a removal procedure for the sink.
- [ ] Test default omission, opt-in scope, production refusal, sink
permissions, and absence of remote projection.
## Evolution
Version 0.1 generalizes the practice coordination-engine prepared as
`OrwellLoggingDiagnostics` (`INFO-DEC-2026-003`, disposition adapt) from its
one known use in tmux-amq. The name, canon-shape sections, and imports from
`model/observability`, `model/data`, and `model/devsecops` are new in this
version; the six practice points and the consumer boundary are carried over
from the candidate. The next useful evidence is a known use in a component
that actually has a production stage to refuse the option against.

View file

@ -2,7 +2,7 @@
# By Concept
Concept count: **770**
Concept count: **771**
| Concept | Owner | Source |
| --- | --- | --- |
@ -694,6 +694,7 @@ Concept count: **770**
| AgenticFallback | `practice-pattern/agentic-drives-functional` | `frontmatter.owned_concepts` |
| DemandSignature | `practice-pattern/agentic-drives-functional` | `frontmatter.owned_concepts` |
| FunctionalInterfaceCandidate | `practice-pattern/agentic-drives-functional` | `frontmatter.owned_concepts` |
| ExplicitUnsafeDiagnosticMode | `practice-pattern/explicit-unsafe-diagnostic-mode` | `artifact_title` |
| InterfaceDeprecationStrangler | `practice-pattern/interface-deprecation-strangler` | `artifact_title` |
| Intake and Assimilation Practice | `practice/intake-and-assimilation` | `artifact_title` |
| Small SaaS System Profile | `profile/small-saas` | `artifact_title` |

View file

@ -139,6 +139,7 @@
- `evaluation/user-engine` via `uses`
- `evaluation/user-engine/questions` via `uses`
- `kernel/itc-kernel-map` via `maps`
- `practice-pattern/explicit-unsafe-diagnostic-mode` via `uses`
- `profile/small-saas` via `requires`
- `review-kit/alignment/model-selection-guide` via `uses`
- `small-saas/dataset/subscription-ledger` via `uses`
@ -152,6 +153,7 @@
- `conformance/railiance-fabric/entity-edge-capture-criteria` via `uses`
- `conformance/railiance-fabric/mapping-expectations` via `maps`
- `kernel/itc-kernel-map` via `maps`
- `practice-pattern/explicit-unsafe-diagnostic-mode` via `uses`
- `practice-pattern/interface-deprecation-strangler` via `uses`
- `profile/small-saas` via `requires`
- `review-kit/alignment/model-selection-guide` via `uses`
@ -268,6 +270,7 @@
- `mapping/emission-cadence-handover` via `maps`
- `model/capability` via `uses`
- `practice-pattern/agentic-drives-functional` via `uses`
- `practice-pattern/explicit-unsafe-diagnostic-mode` via `uses`
- `practice-pattern/interface-deprecation-strangler` via `uses`
- `profile/small-saas` via `requires`
- `review-kit/alignment/model-selection-guide` via `uses`
@ -408,6 +411,7 @@
- `assimilation/orwell-logging-diagnostics` via `related_to`
- `practice-pattern/agentic-drives-functional` via `conforms_to`
- `practice-pattern/explicit-unsafe-diagnostic-mode` via `conforms_to`
- `practice-pattern/interface-deprecation-strangler` via `conforms_to`
## `small-saas/control/namespace-per-tenant`

View file

@ -2,87 +2,88 @@
# Import Matrix
| Artifact | `assimilation/canon-federation` | `assimilation/emission-cadence` | `assimilation/it-capability-canon` | `assimilation/orwell-logging-diagnostics` | `benchmark/caring/kubernetes-rbac` | `benchmark/caring/kubernetes-rbac/access-descriptors` | `benchmark/caring/kubernetes-rbac/caring-mapping` | `benchmark/caring/kubernetes-rbac/findings` | `benchmark/caring/kubernetes-rbac/native-concepts` | `capability-catalog/itc-cap` | `catalog/attribute-value-types` | `catalog/evidence-basis` | `comparison/repo-scoping/canon-benefit-analysis` | `comparison/repo-scoping/consumer-workplan-brief` | `comparison/repo-scoping/extension-candidates` | `comparison/repo-scoping/frame` | `comparison/repo-scoping/report` | `concept-area/family` | `concept-catalog/purpose-demand` | `conformance/railiance-fabric` | `conformance/railiance-fabric/consumer-workplan-brief` | `conformance/railiance-fabric/entity-edge-capture-criteria` | `conformance/railiance-fabric/mapping-expectations` | `conformance/railiance-fabric/visualization-examples` | `evaluation/user-engine` | `evaluation/user-engine/consumer-workplan-brief` | `evaluation/user-engine/interface-card-expectations` | `evaluation/user-engine/questions` | `evaluation/user-engine/small-saas-alignment` | `example/consumer-purpose-portfolio` | `example/emission-cadence/qonto-assistant` | `interface-card/canon-federation` | `kernel/itc-core` | `kernel/itc-kernel-map` | `mapping/capability-anchors` | `mapping/emission-cadence-handover` | `mapping/purpose-demand-governance-candidates` | `model/access-control` | `model/capability` | `model/data` | `model/devsecops` | `model/evidence` | `model/governance` | `model/identity` | `model/information-space` | `model/landscape` | `model/network` | `model/observability` | `model/organization` | `model/purpose-demand-extension` | `model/security` | `model/task` | `pattern/intent-scope-purposes` | `practice-pattern/agentic-drives-functional` | `practice-pattern/interface-deprecation-strangler` | `practice/intake-and-assimilation` | `profile/small-saas` | `review-kit/alignment` | `review-kit/alignment/model-selection-guide` | `review-kit/alignment/schema` | `review-kit/alignment/scorecard` | `review-kit/alignment/workflow` | `review-kit/alignment/workplan-template` | `scheme/practice-pattern` | `small-saas/capability-requirements/production` | `small-saas/control/namespace-per-tenant` | `small-saas/dataset/subscription-ledger` | `small-saas/deployment/production` | `small-saas/evidence/access-review-2026-05` | `small-saas/incident/cross-tenant-access-attempt` | `small-saas/policy/tenant-isolation` | `small-saas/service/billing-portal` | `small-saas/system/billing-system` | `small-saas/task/onboard-tenant` | `small-saas/team/platform` | `small-saas/tenant/acme` | `small-saas/tenant/globex` | `small-saas/user/ada-admin` | `standard/caring` | `standard/emission-cadence` | `standard/repository-layout` | `standard/tagging` |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| `assimilation/canon-federation` | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | `uses` | | | | `uses` | | `uses` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `assimilation/emission-cadence` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `assimilation/it-capability-canon` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `assimilation/orwell-logging-diagnostics` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | `related_to` | | | | | | | | | | | | | | | | `related_to` | | | | | | | | | | | | | | | | | | |
| `benchmark/caring/kubernetes-rbac` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `stress_tests` | | | `stress_tests` | | `stress_tests` | | | | `stress_tests` | `stress_tests` | | | `stress_tests` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | `uses` |
| `benchmark/caring/kubernetes-rbac/access-descriptors` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | `uses` | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `benchmark/caring/kubernetes-rbac/caring-mapping` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | `maps` | | | | | | | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | |
| `benchmark/caring/kubernetes-rbac/findings` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `proposes` | | | | | | | | `proposes` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `proposes` | | | |
| `benchmark/caring/kubernetes-rbac/native-concepts` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | | | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | |
| `capability-catalog/itc-cap` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `catalog/attribute-value-types` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `catalog/evidence-basis` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/canon-benefit-analysis` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | `maps` | | | | | `maps` | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` |
| `comparison/repo-scoping/consumer-workplan-brief` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/extension-candidates` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | `proposes` | | `proposes` | | | | | `proposes` | | `proposes` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/frame` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/report` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | | | `compares` | | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `concept-area/family` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `concept-catalog/purpose-demand` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | `uses` | | `uses` | | | `uses` | `uses` | `uses` | | `uses` | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` |
| `conformance/railiance-fabric/consumer-workplan-brief` | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric/entity-edge-capture-criteria` | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | `uses` | `uses` | | `uses` | | | `uses` | `uses` | `uses` | | `uses` | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric/mapping-expectations` | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | `maps` | `maps` | | `maps` | | | `maps` | `maps` | `maps` | | `maps` | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric/visualization-examples` | | | | | | | | | | | | | | | | | | | | `part_of` | | `illustrates` | `illustrates` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `evaluation/user-engine` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | `uses` | | | | | | `uses` | `uses` | `uses` | `uses` | | | | | `evaluates` | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `evaluation/user-engine/consumer-workplan-brief` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `evaluation/user-engine/interface-card-expectations` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `evaluation/user-engine/questions` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | `uses` | | `uses` | | | `uses` | | | | | | `uses` | `uses` | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `evaluation/user-engine/small-saas-alignment` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | `uses` | | | | | `uses` | | | | | | `uses` | | | | | | | | `evaluates` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `example/consumer-purpose-portfolio` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `illustrates` | | | `illustrates` | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `example/emission-cadence/qonto-assistant` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | |
| `interface-card/canon-federation` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `kernel/itc-core` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `kernel/itc-kernel-map` | | | | | | | | | | | | | | | | | | `maps` | | | | | | | | | | | | | | | `maps` | | | | | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | | `maps` | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | `maps` |
| `mapping/capability-anchors` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `mapping/emission-cadence-handover` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | |
| `mapping/purpose-demand-governance-candidates` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | | | `maps` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/access-control` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | `uses` | `uses` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/capability` | | | `derived_from` | | | | | | | `introduces` | | `uses` | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | `introduces` | | | | | | | `uses` | `uses` | | | `uses` | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/data` | | | | | | | | | | | `introduces` | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/devsecops` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/evidence` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/governance` | | | | | | | | | | | | `introduces` | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/identity` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `uses` | | | | `uses` | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/information-space` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/landscape` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/network` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/observability` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/organization` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/purpose-demand-extension` | | | | | | | | | | | | | | | | | | | `introduces` | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `extends` | | `uses` | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/security` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `uses` | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/task` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `pattern/intent-scope-purposes` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `implements` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `practice-pattern/agentic-drives-functional` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | `uses` | | | | | `uses` | | | | `uses` | | | `related_to` | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | |
| `practice-pattern/interface-deprecation-strangler` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | | | `uses` | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | |
| `practice/intake-and-assimilation` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `profile/small-saas` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `requires` | | `requires` | `requires` | | `requires` | | | `requires` | `requires` | `requires` | `requires` | | `requires` | `requires` | | | | | | | | | | | | | | | | | | | | | | | | | | | `requires` | | | `requires` |
| `review-kit/alignment` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `uses` | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `review-kit/alignment/model-selection-guide` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | `uses` | | `uses` | | | `uses` | `uses` | `uses` | `uses` | `uses` | `uses` | `uses` | | | | | `uses` | `part_of` | | | | | | | | | | | | | | | | | | | | | `uses` | | | `uses` |
| `review-kit/alignment/schema` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `review-kit/alignment/scorecard` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `review-kit/alignment/workflow` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `uses` | | `uses` | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `review-kit/alignment/workplan-template` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `scheme/practice-pattern` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `small-saas/capability-requirements/production` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | `applies_to` | | | | | | | | | | |
| `small-saas/control/namespace-per-tenant` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | `instantiates` | | | | | | | | | | | | `evidenced_by` | | | | | | | | | | `uses` | | | |
| `small-saas/dataset/subscription-ledger` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | `governed_by` | `owned_by` | | | | `partitioned_for` | `partitioned_for` | | | | | |
| `small-saas/deployment/production` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | `uses` | | | | | | | | | | `instantiates` | | | | | | | | | `implements` | | | | | | `deploys` | | | | `separates` | `separates` | | | | | |
| `small-saas/evidence/access-review-2026-05` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `small-saas/incident/cross-tenant-access-attempt` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | `instantiates` | | | | | | | | | `constrained_by` | | | `evidenced_by` | | | | | | | | | | | | | |
| `small-saas/policy/tenant-isolation` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | `instantiates` | | | | | | | | | `requires` | | | `evidenced_by` | | | | | | | | | | | | | |
| `small-saas/service/billing-portal` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | `part_of` | | `owned_by` | | | | | | | |
| `small-saas/system/billing-system` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | | | | `serves` | `serves` | | | | | |
| `small-saas/task/onboard-tenant` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | `instantiates` | | | | | | | | | | | | | | `governed_by` | | | | `owned_by` | `changes` | | | | | | |
| `small-saas/team/platform` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `small-saas/tenant/acme` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | `instantiates` | | | | | | | | | `isolated_by` | | | | | | | | | | | | `represented_by` | | | | |
| `small-saas/tenant/globex` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | `instantiates` | | | | | | | | | `isolated_by` | | | | | | | | | | | | | | | | |
| `small-saas/user/ada-admin` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | `uses` | | | | | | | | `instantiates` | | | | | | | | | | | | `access_evidenced_by` | | `has_access_under` | | | | `member_of` | | | | | | | |
| `standard/caring` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `imports` | | `imports` | `imports` | `uses` | `imports` | | | | `imports` | `imports` | `imports` | | `imports` | `imports` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `imports` |
| `standard/emission-cadence` | | `derived_from` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `imports` | | | | | `imports` | | | `related_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `standard/repository-layout` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `imports` | | `imports` | | | | | | | `imports` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `standard/tagging` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | `imports` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Artifact | `assimilation/canon-federation` | `assimilation/emission-cadence` | `assimilation/it-capability-canon` | `assimilation/orwell-logging-diagnostics` | `benchmark/caring/kubernetes-rbac` | `benchmark/caring/kubernetes-rbac/access-descriptors` | `benchmark/caring/kubernetes-rbac/caring-mapping` | `benchmark/caring/kubernetes-rbac/findings` | `benchmark/caring/kubernetes-rbac/native-concepts` | `capability-catalog/itc-cap` | `catalog/attribute-value-types` | `catalog/evidence-basis` | `comparison/repo-scoping/canon-benefit-analysis` | `comparison/repo-scoping/consumer-workplan-brief` | `comparison/repo-scoping/extension-candidates` | `comparison/repo-scoping/frame` | `comparison/repo-scoping/report` | `concept-area/family` | `concept-catalog/purpose-demand` | `conformance/railiance-fabric` | `conformance/railiance-fabric/consumer-workplan-brief` | `conformance/railiance-fabric/entity-edge-capture-criteria` | `conformance/railiance-fabric/mapping-expectations` | `conformance/railiance-fabric/visualization-examples` | `evaluation/user-engine` | `evaluation/user-engine/consumer-workplan-brief` | `evaluation/user-engine/interface-card-expectations` | `evaluation/user-engine/questions` | `evaluation/user-engine/small-saas-alignment` | `example/consumer-purpose-portfolio` | `example/emission-cadence/qonto-assistant` | `interface-card/canon-federation` | `kernel/itc-core` | `kernel/itc-kernel-map` | `mapping/capability-anchors` | `mapping/emission-cadence-handover` | `mapping/purpose-demand-governance-candidates` | `model/access-control` | `model/capability` | `model/data` | `model/devsecops` | `model/evidence` | `model/governance` | `model/identity` | `model/information-space` | `model/landscape` | `model/network` | `model/observability` | `model/organization` | `model/purpose-demand-extension` | `model/security` | `model/task` | `pattern/intent-scope-purposes` | `practice-pattern/agentic-drives-functional` | `practice-pattern/explicit-unsafe-diagnostic-mode` | `practice-pattern/interface-deprecation-strangler` | `practice/intake-and-assimilation` | `profile/small-saas` | `review-kit/alignment` | `review-kit/alignment/model-selection-guide` | `review-kit/alignment/schema` | `review-kit/alignment/scorecard` | `review-kit/alignment/workflow` | `review-kit/alignment/workplan-template` | `scheme/practice-pattern` | `small-saas/capability-requirements/production` | `small-saas/control/namespace-per-tenant` | `small-saas/dataset/subscription-ledger` | `small-saas/deployment/production` | `small-saas/evidence/access-review-2026-05` | `small-saas/incident/cross-tenant-access-attempt` | `small-saas/policy/tenant-isolation` | `small-saas/service/billing-portal` | `small-saas/system/billing-system` | `small-saas/task/onboard-tenant` | `small-saas/team/platform` | `small-saas/tenant/acme` | `small-saas/tenant/globex` | `small-saas/user/ada-admin` | `standard/caring` | `standard/emission-cadence` | `standard/repository-layout` | `standard/tagging` |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| `assimilation/canon-federation` | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | `uses` | | | | `uses` | | `uses` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `assimilation/emission-cadence` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `assimilation/it-capability-canon` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `assimilation/orwell-logging-diagnostics` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | `related_to` | | | | | | | | | | | | | | | | | `related_to` | | | | | | | | | | | | | | | | | | |
| `benchmark/caring/kubernetes-rbac` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `stress_tests` | | | `stress_tests` | | `stress_tests` | | | | `stress_tests` | `stress_tests` | | | `stress_tests` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | `uses` |
| `benchmark/caring/kubernetes-rbac/access-descriptors` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | `uses` | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `benchmark/caring/kubernetes-rbac/caring-mapping` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | `maps` | | | | | | | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | |
| `benchmark/caring/kubernetes-rbac/findings` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `proposes` | | | | | | | | `proposes` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `proposes` | | | |
| `benchmark/caring/kubernetes-rbac/native-concepts` | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | | | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | |
| `capability-catalog/itc-cap` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `catalog/attribute-value-types` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `catalog/evidence-basis` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/canon-benefit-analysis` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | `maps` | | | | | `maps` | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` |
| `comparison/repo-scoping/consumer-workplan-brief` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/extension-candidates` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | `proposes` | | `proposes` | | | | | `proposes` | | `proposes` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/frame` | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `comparison/repo-scoping/report` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | | | `compares` | | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `concept-area/family` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `concept-catalog/purpose-demand` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | `uses` | | `uses` | | | `uses` | `uses` | `uses` | | `uses` | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` |
| `conformance/railiance-fabric/consumer-workplan-brief` | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric/entity-edge-capture-criteria` | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | `uses` | `uses` | | `uses` | | | `uses` | `uses` | `uses` | | `uses` | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric/mapping-expectations` | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | `maps` | `maps` | | `maps` | | | `maps` | `maps` | `maps` | | `maps` | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `conformance/railiance-fabric/visualization-examples` | | | | | | | | | | | | | | | | | | | | `part_of` | | `illustrates` | `illustrates` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `evaluation/user-engine` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | `uses` | | | | | | `uses` | `uses` | `uses` | `uses` | | | | | | `evaluates` | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `evaluation/user-engine/consumer-workplan-brief` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `evaluation/user-engine/interface-card-expectations` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `evaluation/user-engine/questions` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | `uses` | | `uses` | | | `uses` | | | | | | `uses` | `uses` | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `evaluation/user-engine/small-saas-alignment` | | | | | | | | | | | | | | | | | | | | | | | | | `part_of` | | | | | | | | | | | | | `uses` | | | | | `uses` | | | | | | `uses` | | | | | | | | | `evaluates` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `example/consumer-purpose-portfolio` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `illustrates` | | | `illustrates` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `example/emission-cadence/qonto-assistant` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | |
| `interface-card/canon-federation` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `kernel/itc-core` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `kernel/itc-kernel-map` | | | | | | | | | | | | | | | | | | `maps` | | | | | | | | | | | | | | | `maps` | | | | | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | `maps` | | `maps` | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | `maps` |
| `mapping/capability-anchors` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `mapping/emission-cadence-handover` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | `maps` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | |
| `mapping/purpose-demand-governance-candidates` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `maps` | | | | | | | `maps` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/access-control` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | `uses` | `uses` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/capability` | | | `derived_from` | | | | | | | `introduces` | | `uses` | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | `introduces` | | | | | | | `uses` | `uses` | | | `uses` | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/data` | | | | | | | | | | | `introduces` | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/devsecops` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/evidence` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/governance` | | | | | | | | | | | | `introduces` | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/identity` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `uses` | | | | `uses` | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/information-space` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/landscape` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/network` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/observability` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/organization` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/purpose-demand-extension` | | | | | | | | | | | | | | | | | | | `introduces` | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `extends` | | `uses` | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/security` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `uses` | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `model/task` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `pattern/intent-scope-purposes` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `implements` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `practice-pattern/agentic-drives-functional` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | `uses` | | | | | `uses` | | | | `uses` | | | | `related_to` | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | |
| `practice-pattern/explicit-unsafe-diagnostic-mode` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | `uses` | | | | | | | `uses` | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | |
| `practice-pattern/interface-deprecation-strangler` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | | | `uses` | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | |
| `practice/intake-and-assimilation` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `profile/small-saas` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `requires` | | `requires` | `requires` | | `requires` | | | `requires` | `requires` | `requires` | `requires` | | `requires` | `requires` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `requires` | | | `requires` |
| `review-kit/alignment` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `uses` | | | | | | | `uses` | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | |
| `review-kit/alignment/model-selection-guide` | | | | | `uses` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | `uses` | | `uses` | | | `uses` | `uses` | `uses` | `uses` | `uses` | `uses` | `uses` | | | | | | `uses` | `part_of` | | | | | | | | | | | | | | | | | | | | | `uses` | | | `uses` |
| `review-kit/alignment/schema` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `review-kit/alignment/scorecard` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `uses` | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `review-kit/alignment/workflow` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `uses` | | `uses` | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `review-kit/alignment/workplan-template` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | `uses` | | | | | | | `part_of` | | | | | | | | | | | | | | | | | | | | | | | | |
| `scheme/practice-pattern` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `small-saas/capability-requirements/production` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | `applies_to` | | | | | | | | | | |
| `small-saas/control/namespace-per-tenant` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `instantiates` | | | | | | | | | | | | `evidenced_by` | | | | | | | | | | `uses` | | | |
| `small-saas/dataset/subscription-ledger` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | `governed_by` | `owned_by` | | | | `partitioned_for` | `partitioned_for` | | | | | |
| `small-saas/deployment/production` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | `uses` | | | | | | | | | | | `instantiates` | | | | | | | | | `implements` | | | | | | `deploys` | | | | `separates` | `separates` | | | | | |
| `small-saas/evidence/access-review-2026-05` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `small-saas/incident/cross-tenant-access-attempt` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | `instantiates` | | | | | | | | | `constrained_by` | | | `evidenced_by` | | | | | | | | | | | | | |
| `small-saas/policy/tenant-isolation` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | | | | `instantiates` | | | | | | | | | `requires` | | | `evidenced_by` | | | | | | | | | | | | | |
| `small-saas/service/billing-portal` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | `part_of` | | `owned_by` | | | | | | | |
| `small-saas/system/billing-system` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | | | | `serves` | `serves` | | | | | |
| `small-saas/task/onboard-tenant` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | `instantiates` | | | | | | | | | | | | | | `governed_by` | | | | `owned_by` | `changes` | | | | | | |
| `small-saas/team/platform` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `instantiates` | | | | | | | | | | | | | | | | | | | | | | | | | |
| `small-saas/tenant/acme` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `instantiates` | | | | | | | | | `isolated_by` | | | | | | | | | | | | `represented_by` | | | | |
| `small-saas/tenant/globex` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | `instantiates` | | | | | | | | | `isolated_by` | | | | | | | | | | | | | | | | |
| `small-saas/user/ada-admin` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `uses` | | | | | | | | | | | `uses` | | | | | | | | | `instantiates` | | | | | | | | | | | | `access_evidenced_by` | | `has_access_under` | | | | `member_of` | | | | | | | |
| `standard/caring` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | `imports` | | `imports` | `imports` | `uses` | `imports` | | | | `imports` | `imports` | `imports` | | `imports` | `imports` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `imports` |
| `standard/emission-cadence` | | `derived_from` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `imports` | | | | | `imports` | | | `related_to` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `standard/repository-layout` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | | `imports` | | `imports` | | | | | | | `imports` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `standard/tagging` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `conforms_to` | | | | | | | | | `uses` | | | | | | | | | | `imports` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

View file

@ -3,7 +3,7 @@
# Kernel Overview
- Infospace: `canon`
- Artifacts: 82
- Artifacts: 83
## Artifact Kinds
@ -41,7 +41,7 @@
- `native-concept-map`: 1
- `pattern`: 1
- `practice`: 1
- `practice-pattern`: 2
- `practice-pattern`: 3
- `practice-pattern-scheme`: 1
- `profile`: 1
- `profile-alignment`: 1
@ -55,7 +55,7 @@
- `applies_to`: 1
- `changes`: 1
- `compares`: 1
- `conforms_to`: 33
- `conforms_to`: 34
- `constrained_by`: 1
- `deploys`: 1
- `derived_from`: 2
@ -82,4 +82,4 @@
- `separates`: 2
- `serves`: 2
- `stress_tests`: 6
- `uses`: 152
- `uses`: 155

View file

@ -2,7 +2,7 @@
# Repository Tree
File count: **301**
File count: **303**
- `README.md`
- `agent/README.md`
@ -53,6 +53,7 @@ File count: **301**
- `agent/briefs/model-task.md`
- `agent/briefs/pattern-intent-scope-purposes.md`
- `agent/briefs/practice-pattern-agentic-drives-functional.md`
- `agent/briefs/practice-pattern-explicit-unsafe-diagnostic-mode.md`
- `agent/briefs/practice-pattern-interface-deprecation-strangler.md`
- `agent/briefs/profile-small-saas.md`
- `agent/briefs/review-kit-alignment-model-selection-guide.md`
@ -243,6 +244,7 @@ File count: **301**
- `models/task/InfoTechCanonTaskModel.md`
- `models/task/boundary-review.md`
- `patterns/AgenticDrivesFunctional.md`
- `patterns/ExplicitUnsafeDiagnosticMode.md`
- `patterns/InterfaceDeprecationStrangler.md`
- `patterns/PracticePatternScheme.md`
- `patterns/README.md`

View file

@ -11,7 +11,7 @@ def test_cli_inspect_emits_json(capsys) -> None:
assert exit_code == 0
payload = json.loads(capsys.readouterr().out)
assert payload["ok"] is True
assert payload["infospace"]["artifact_count"] == 82
assert payload["infospace"]["artifact_count"] == 83
def test_cli_missing_profile_uses_structured_error(capsys) -> None:

View file

@ -25,7 +25,7 @@ def test_inspect_canon_counts_artifact_kinds() -> None:
assert payload["ok"] is True
assert payload["infospace"]["slug"] == "canon"
assert payload["infospace"]["artifact_count"] == 82
assert payload["infospace"]["artifact_count"] == 83
assert payload["infospace"]["kinds"] == {
"access-descriptor-set": 1,
"alignment-review-kit": 1,
@ -61,7 +61,7 @@ def test_inspect_canon_counts_artifact_kinds() -> None:
"native-concept-map": 1,
"pattern": 1,
"practice": 1,
"practice-pattern": 2,
"practice-pattern": 3,
"practice-pattern-scheme": 1,
"profile-alignment": 1,
"profile": 1,
@ -101,21 +101,21 @@ def test_validate_canon_passes_scaffold() -> None:
assert payload["ok"] is True
assert payload["errors"] == []
assert "warnings" in payload
assert payload["details"]["artifact_count"] == 82
assert payload["details"]["artifact_count"] == 83
def test_graph_exports_relationship_summary() -> None:
payload = artifact_graph()
assert payload["ok"] is True
assert payload["graph"]["node_count"] == 82
assert payload["graph"]["node_count"] == 83
assert payload["graph"]["edge_count"] > 15
def test_practice_patterns_are_registered() -> None:
payload = list_artifacts(kind="practice-pattern")
assert payload["count"] == 2
assert payload["count"] == 3
patterns = {pattern["id"]: pattern for pattern in payload["artifacts"]}
agentic = patterns["practice-pattern/agentic-drives-functional"]
assert agentic["title"] == "AgenticDrivesFunctional"

View file

@ -4,11 +4,11 @@ type: workplan
title: "Seek independent Emission Cadence adoption evidence"
domain: infotech
repo: info-tech-canon
status: active
status: blocked
owner: claude
topic_slug: canon-optimization
created: "2026-09-21"
updated: "2026-09-22"
updated: "2026-09-27"
flavor: coordination
state_hub_workstream_id: "d743e220-9d2d-52d8-8df3-880805269639"
---
@ -70,7 +70,7 @@ incompatibility finding. It is recorded under T04.
```task
id: INFO-WP-0029-T03
status: progress
status: done
priority: high
state_hub_task_id: "bb74cce9-12d8-58e2-ad44-c4aeb7b72f37"
```
@ -84,6 +84,10 @@ Sent 2026-09-21 as State Hub message `f1687805-3153-47c2-9744-05a2b1a6b8c1`.
Both messages name the brief rather than restating the ask, and both say that a
recorded incompatibility is a successful outcome.
Answered 2026-09-22 (`161d5aa5`): a declaration was published at activity-core
`f20db47`, `docs/emission-cadence/activity-core-evidence.yaml`, together with
an incompatibility finding. It is recorded under T04.
## Recheck — 2026-09-21
No reply, and none should be expected yet. Both requests are unread. Neither
@ -103,7 +107,7 @@ of section 10 and defeat its purpose.
```task
id: INFO-WP-0029-T04
status: progress
status: done
priority: medium
state_hub_task_id: "4771ff59-264e-5917-a49d-8989b361b8ed"
```
@ -131,8 +135,28 @@ version from the standard. A test pins that behaviour, and the brief names the
candidate digest `b08b4d95fc4b0bd3`. The wire schema did not change, so the
declaration stays valid.
This task stays in progress until activity-core's declaration (T03) arrives or
the ask is withdrawn.
### Recorded — 2026-09-27
activity-core's declaration passes `emission-review` (`ok: true`, `errors: []`).
It is recorded as
`feedback/2026-09-22-activity-core-emission-cadence-declaration.md`. Its
incompatibility is that `expected-rate`'s wall-clock window cannot express a
weekday-only (calendar-shaped) schedule; the consumer used `reconciliation`
instead for that entry. That finding goes to the standard as
`demand/EmissionExpectedRateCalendar.md` and was not worked around in the
declaration.
audit-core also replied (unread until this session) with a structural-only
observer evaluation of net-kingdom's declaration, explicitly stating it does
not satisfy the stable gate because audit-core holds no `local-identity`
traffic to evaluate against. Recorded as a steward note on
`feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md`. It found a
second incompatibility (heartbeat `event_class` vs. `heartbeat_classes`
drift), noted there rather than duplicated here.
Both declarations now arrived and are recorded. This task is done. T05
(observer result) stays open: no observer has evaluated a source with
registered traffic against either declaration.
## Observer result
@ -144,8 +168,17 @@ state_hub_task_id: "0486fcba-3609-50c5-b347-e7ee84f9f548"
```
One result from a party other than the declaring source, evaluating a declared
cadence against observed events. Blocked until at least one declaration exists,
since there is nothing to evaluate before then.
cadence against observed events. Two declarations now exist (net-kingdom,
activity-core), so the earlier blocker is cleared, but no result exists yet:
audit-core's 2026-09-22 reply evaluated net-kingdom's declaration structurally
only and said plainly that this does not satisfy the gate, since audit-core
holds no traffic from that source. A real result needs a source with an
`expected-rate` or `reconciliation` declaration registered at an observer and
sending it traffic — neither net-kingdom nor activity-core currently sends
traffic that any known observer holds (activity-core's periodic emission into
issue-core is off in production). This is now blocked on an external party
(a source and an observer both taking action this repository does not
control), so the workplan status moves to `blocked` pending that.
## Honest limit on what this can prove

View file

@ -4,11 +4,11 @@ type: workplan
title: "Place the adapted OrwellLoggingDiagnostics practice pattern"
domain: infotech
repo: info-tech-canon
status: proposed
status: finished
owner: claude
topic_slug: canon-optimization
created: "2026-09-22"
updated: "2026-09-22"
updated: "2026-09-27"
flavor: planning
state_hub_workstream_id: "75e5efe7-03b0-5492-8244-42851709423d"
---
@ -26,29 +26,35 @@ artifact ID, path, and version.
```task
id: INFO-WP-0030-T01
status: todo
status: done
priority: medium
state_hub_task_id: "13d9ccbe-8136-5fc9-b8ae-4307b4eec773"
```
Write the pattern under `infospace/patterns/` following `PracticePatternScheme`,
with `status: candidate`, a neutral name, and all scheme sections. Import
Log/LogRecord (observability), sensitive-data classification (data), and
production/non-production environment concepts (security/devsecops) from
their owners rather than restating them. Known Uses cites tmux-amq at the
revision recorded in the assimilation, naming the observed tests.
Written as `practice-pattern/explicit-unsafe-diagnostic-mode`
(`infospace/patterns/ExplicitUnsafeDiagnosticMode.md`), `status: candidate`,
`version: "0.1"`. Imports `Log`/`LogRecord` from `model/observability`,
`DataClassification`/`Sensitivity` from `model/data`, and
`EnvironmentPromotion` from `model/devsecops`. Alias `OrwellLoggingDiagnostics`
is kept. Known Uses cites tmux-amq `04de219` and names the one observed test
(`tests/test_diagnostics.py::test_orwell_log_is_private`), stating plainly
that it does not demonstrate the production-refusal invariant — tmux-amq has
no production/non-production distinction to check against.
## Register, version, and close the assimilation
```task
id: INFO-WP-0030-T02
status: todo
status: done
priority: medium
state_hub_task_id: "4c9a3fa1-e870-53e0-a43f-4831b7d7529c"
```
Register the artifact in `canon.yaml`, `infospace/artifacts/index.yaml` and
`infospace/infospace.yaml`. Regenerate indexes and briefs, pass `make check`,
and record a minor canon version with change notes. Set the assimilation to
`closed`, and send coordination-engine the artifact ID, path, and version for
COORDINATION-WP-0004-T02.
Registered in `canon.yaml` (assimilation record + `version: 0.13.0`) and
`infospace/artifacts/index.yaml`. `infospace/infospace.yaml` needed no change:
it does not carry a separate pattern catalog. Indexes and briefs regenerated;
`make check` passes (60 tests; 0 validation errors/warnings; count-based
tests updated for the new artifact). `CHANGELOG.md` records canon 0.13.0.
`infospace/assimilation/orwell-logging-diagnostics/ASSIMILATION.md` is set to
`closed`. Sent coordination-engine the artifact ID, path, and version for
COORDINATION-WP-0004-T02 (State Hub message `37bf8ae5-5fdd-44d9-b58c-296f9973c2cf`).