{
  "schemaVersion": "eve-sota-gap-task-evidence-exit.v2",
  "initiativeId": "eve-sota-gap-closure-2026-09-01",
  "generatedOn": "2026-09-01",
  "source": {
    "repository": "GreyChimp/oshun",
    "ledger": "EVE_SOTA_GAP_CLOSURE_TODOS_2026-09-01.md",
    "taskRequirementsSha256": "3dcdbb8440a0691c66693b3db8472a6b151abd45cd5d6a38a41195b264d379cd"
  },
  "gaps": [
    { "id": "G1", "statement": "Governed planning, orchestration, and fleet throughput" },
    { "id": "G2", "statement": "Retrieval and knowledge quality" },
    { "id": "G3", "statement": "Second-brain fusion, watchers, and channels" },
    { "id": "G4", "statement": "Metis and future workbench seams" },
    { "id": "G5", "statement": "DCC and creative-suite agency" },
    { "id": "G6", "statement": "Native computer-use admission" },
    { "id": "G7", "statement": "Human-grounded judge validation" },
    { "id": "G8", "statement": "Release-scope evaluation activation" },
    { "id": "G9", "statement": "Interaction, trust, accessibility, and cross-client parity" },
    { "id": "G10", "statement": "Agentic security, authority, and injection resistance" },
    { "id": "G11", "statement": "Memory quality, provenance, and data rights" },
    { "id": "G12", "statement": "Goal-to-verified-delivery competence" },
    { "id": "G13", "statement": "Production reliability and recoverability" },
    { "id": "G14", "statement": "Evaluation completeness" },
    { "id": "G15", "statement": "Multimodal, document, and media competence" },
    { "id": "G16", "statement": "Privacy, data governance, and regulatory readiness" },
    { "id": "G17", "statement": "Protocol and ecosystem interoperability" },
    { "id": "G18", "statement": "Model and router lifecycle performance resilience" }
  ],
  "proofScopes": [
    {
      "id": "source-inspection",
      "boundary": "repository",
      "requiredEvidenceClassRefs": ["source-review"],
      "description": "Direct review of the authoritative source, generated artifacts, and ownership."
    },
    {
      "id": "static-contract",
      "boundary": "repository",
      "requiredEvidenceClassRefs": ["automated-static"],
      "description": "Machine validation of a schema, contract, registry, policy, or generated record."
    },
    {
      "id": "automated-behavior",
      "boundary": "logic",
      "requiredEvidenceClassRefs": ["automated-test"],
      "description": "Behavioral tests with an observed red control and green regression."
    },
    {
      "id": "service-integration",
      "boundary": "service",
      "requiredEvidenceClassRefs": ["service-integration"],
      "description": "Integration or contract proof across the real service/tool boundary."
    },
    {
      "id": "persistence-recovery",
      "boundary": "persistence",
      "requiredEvidenceClassRefs": ["service-integration"],
      "description": "Durable write/read, restart, migration, deletion, or restore behavior."
    },
    {
      "id": "authorization-isolation",
      "boundary": "authorization",
      "requiredEvidenceClassRefs": ["service-integration"],
      "description": "Positive and negative actor, tenant, object, purpose, and scope enforcement."
    },
    {
      "id": "real-model-provider",
      "boundary": "model-provider",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "A retained receipt from the resolved real model/provider route."
    },
    {
      "id": "real-agent-runtime",
      "boundary": "coding-agent",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "A real, version-preflighted coding-agent CLI executes the attributed work lane."
    },
    {
      "id": "real-database",
      "boundary": "database",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "Observation against the real database implementation rather than an in-memory substitute."
    },
    {
      "id": "real-vector-store",
      "boundary": "vector-store",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "Build, query, freshness, isolation, deletion, and recovery on the bound vector/index runtime."
    },
    {
      "id": "real-browser-ui",
      "boundary": "browser",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "A real browser journey through the user-facing surface and backing service."
    },
    {
      "id": "native-desktop-runtime",
      "boundary": "desktop",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "OS-level fixture proof with real app, window, input, permission, and end-state checks."
    },
    {
      "id": "mobile-runtime",
      "boundary": "mobile",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "Device or emulator automation through the actual mobile client boundary."
    },
    {
      "id": "real-dcc-runtime",
      "boundary": "dcc",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "A real DCC process with readback and independently checked editable artifacts."
    },
    {
      "id": "real-engine-runtime",
      "boundary": "engine",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "A real engine executable at the required host path with retained runtime evidence."
    },
    {
      "id": "external-channel-runtime",
      "boundary": "channel",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "A chosen, credentialed external channel with identity, delivery, safety, and kill proof."
    },
    {
      "id": "real-multimodal-runtime",
      "boundary": "media",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "Real document, image, audio, video, OCR, or generated-media fixtures cross their operating boundary."
    },
    {
      "id": "protocol-interop",
      "boundary": "protocol",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "Conformance against a real independent protocol implementation where adoption is claimed."
    },
    {
      "id": "host-capability-observation",
      "boundary": "host",
      "requiredEvidenceClassRefs": ["live-runtime"],
      "description": "Fresh host probe of the executable, permission, credential-name, or harness capability."
    },
    {
      "id": "operational-load-soak",
      "boundary": "operations",
      "requiredEvidenceClassRefs": ["operational-exercise"],
      "description": "Supervised load, soak, queue drain, or game-day evidence at the operating boundary."
    },
    {
      "id": "fault-recovery",
      "boundary": "recovery",
      "requiredEvidenceClassRefs": ["automated-test"],
      "description": "Injected timeout, cancellation, dependency loss, replay, partial result, or restart failure."
    },
    {
      "id": "security-adversarial",
      "boundary": "security",
      "requiredEvidenceClassRefs": ["security-exercise"],
      "description": "Adversarial and benign-paired tests through the authoritative prompt/tool/runtime seam."
    },
    {
      "id": "privacy-data-rights",
      "boundary": "privacy",
      "requiredEvidenceClassRefs": ["governance-review"],
      "description": "Classification, minimization, provider-use, retention, deletion, and rights evidence."
    },
    {
      "id": "performance-quality",
      "boundary": "measurement",
      "requiredEvidenceClassRefs": ["measurement"],
      "description": "Pre-registered quality, latency, reliability, resource, or cost measurement."
    },
    {
      "id": "governance-decision",
      "boundary": "governance",
      "requiredEvidenceClassRefs": ["governance-review"],
      "description": "An attributable ADR, risk acceptance, legal applicability, or operator decision record."
    },
    {
      "id": "human-outcomes",
      "boundary": "human-evaluation",
      "requiredEvidenceClassRefs": ["human-review"],
      "description": "Independent human labels, rubric results, or operator outcome evidence."
    },
    {
      "id": "manual-assistive-tech",
      "boundary": "assistive-technology",
      "requiredEvidenceClassRefs": ["human-review"],
      "description": "Named screen-reader or assistive-technology manual interoperability evidence."
    },
    {
      "id": "independent-verification",
      "boundary": "verification",
      "requiredEvidenceClassRefs": ["independent-verification"],
      "description": "A verifier independent of the implementer checks the actual end state or artifact."
    },
    {
      "id": "docs-render-integrity",
      "boundary": "documentation",
      "requiredEvidenceClassRefs": ["automated-static"],
      "description": "Markdown/rendered-HTML parity, freshness, links, and source-path integrity."
    }
  ],
  "matrixRows": [
    {
      "ownerTaskId": "0.1",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Correct the companion audit's G1/G3/G8/G9/G10/G11 statements and shortlist; link this ledger from its execution line; render `docs/audits/EVE_SOTA_GAP_AUDIT_2026-09-01.html`; verify Markdown and HTML carry the same corrected claims.",
      "gapRefs": ["G1", "G3", "G8", "G9", "G10", "G11"],
      "dependencyTaskIds": [],
      "dependencyRationales": [],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "docs-render-integrity"],
      "evidencePlan": {
        "id": "evidence-0-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "docs-render-integrity"],
        "evidenceClassRefs": ["source-review", "automated-static"],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_GAP_AUDIT_2026-09-01.md",
          "docs/audits/EVE_SOTA_GAP_AUDIT_2026-09-01.html",
          "EVE_SOTA_GAP_CLOSURE_TODOS_2026-09-01.md"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Correct the companion audit's G1/G3/G8/G9/G10/G11 statements and shortlist; link this ledger from its execution line; render `docs/audits/EVE_SOTA_GAP_AUDIT_2026-09-01.html`; verify Markdown and HTML carry the same corrected claims. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.2",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Write `docs/audits/EVE_SOTA_CLOSURE_BASELINE_2026-09.md`: tool and view counts per plane/seam; prompt hash/bytes; family case/run counts and Wilson floors; cost/cache/latency; queue and lease state; memory posture; invocation/tour/voice/selection surfaces; model legs; dependency/runtime availability. Every number names a reproducible source command and commit.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.1"],
      "dependencyRationales": [
        "Uses the corrected gap definitions rather than the superseded audit claims."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "host-capability-observation",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-0-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "host-capability-observation",
          "performance-quality"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "live-runtime", "measurement"],
        "artifactLocators": [
          "docs/audits/eve-sota-closure-baseline/2026-09-01.json",
          "docs/audits/EVE_SOTA_CLOSURE_BASELINE_2026-09.md",
          "docs/audits/EVE_SOTA_CLOSURE_BASELINE_2026-09.html",
          "tools/eve-everywhere/verify-closure-baseline.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Write `docs/audits/EVE_SOTA_CLOSURE_BASELINE_2026-09.md`: tool and view counts per plane/seam; prompt hash/bytes; family case/run counts and Wilson floors; cost/cache/latency; queue and lease state; memory posture; invocation/tour/voice/selection surfaces; model legs; dependency/runtime availability. Every number names a reproducible source command and commit. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.3",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Translate Eve's charter into a pre-registered outcome scorecard: verified task success, intervention/rollback/unauthorized-action rates, time and cost per verified result, retrieval/citation quality, TTFT/total latency, cancellation/recovery, memory usefulness, accessibility, and operator acceptance. Set target, minimum floor, sample unit, decision owner, and breach action for each; no `TBD` at phase exit.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.2"],
      "dependencyRationales": [
        "Uses the reproducible baseline and its actual capability boundary."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-0-3",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/eve-sota-outcome-scorecard/2026-09-01.json",
          "docs/audits/EVE_SOTA_OUTCOME_SCORECARD_2026-09.md",
          "docs/audits/EVE_SOTA_OUTCOME_SCORECARD_2026-09.html",
          "tools/eve-everywhere/verify-outcome-scorecard.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Translate Eve's charter into a pre-registered outcome scorecard: verified task success, intervention/rollback/unauthorized-action rates, time and cost per verified result, retrieval/citation quality, TTFT/total latency, cancellation/recovery, memory usefulness, accessibility, and operator acceptance. Set target, minimum floor, sample unit, decision owner, and breach action for each; no `TBD` at phase exit. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.4",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Build the dated NIST/OWASP/MCP/A2A/AG-UI/WCAG/OpenTelemetry crosswalk: requirement/risk → existing control → evidence → gap → phase/task. Record exact versions/hashes and distinguish normative MUSTs from optional compatibility choices.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.2"],
      "dependencyRationales": [
        "Uses the reproducible baseline and its actual capability boundary."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-0-4",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/eve-sota-external-crosswalk/2026-09-01.json",
          "docs/audits/EVE_SOTA_EXTERNAL_CROSSWALK_2026-09.md",
          "docs/audits/EVE_SOTA_EXTERNAL_CROSSWALK_2026-09.html",
          "tools/eve-everywhere/verify-external-crosswalk.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build the dated NIST/OWASP/MCP/A2A/AG-UI/WCAG/OpenTelemetry crosswalk: requirement/risk → existing control → evidence → gap → phase/task. Record exact versions/hashes and distinguish normative MUSTs from optional compatibility choices. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.5",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Add a machine-validated evidence-manifest schema for this initiative. It rejects missing commands/exit codes, unverifiable prose-only live claims, absent negative controls, absent model/runtime provenance, and phase closure with unowned gaps.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.3", "0.4"],
      "dependencyRationales": [
        "Consumes the preregistered outcome thresholds and decision rules.",
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
      "evidencePlan": {
        "id": "evidence-0-5",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
        "evidenceClassRefs": ["source-review", "automated-static", "automated-test"],
        "artifactLocators": [
          "docs/audits/eve-sota-evidence-manifest.schema.json",
          "docs/audits/EVE_SOTA_EVIDENCE_MANIFEST_SCHEMA_2026-09.md",
          "docs/audits/EVE_SOTA_EVIDENCE_MANIFEST_SCHEMA_2026-09.html",
          "tools/eve-everywhere/verify-evidence-manifest.mjs",
          "tools/eve-everywhere/verify-evidence-manifest.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Add a machine-validated evidence-manifest schema for this initiative. It rejects missing commands/exit codes, unverifiable prose-only live claims, absent negative controls, absent model/runtime provenance, and phase closure with unowned gaps. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.6",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Build the gap→task→evidence→exit matrix for G1–G18. Every task appears once as an owner and may appear elsewhere only as a dependency. The verifier fails on orphan gaps, circular admission, or a broad requirement \"proved\" only by a narrower test.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.5"],
      "dependencyRationales": [
        "Uses the admitted evidence format and negative-control requirements."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
      "evidencePlan": {
        "id": "evidence-0-6",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
        "evidenceClassRefs": ["source-review", "automated-static", "automated-test"],
        "artifactLocators": [
          "docs/audits/eve-sota-gap-task-evidence-exit/2026-09-01.json",
          "docs/audits/eve-sota-gap-task-evidence-exit.schema.json",
          "docs/audits/EVE_SOTA_GAP_TASK_EVIDENCE_EXIT_MATRIX_2026-09.md",
          "docs/audits/EVE_SOTA_GAP_TASK_EVIDENCE_EXIT_MATRIX_2026-09.html",
          "tools/eve-everywhere/generate-gap-task-evidence-exit.mjs",
          "tools/eve-everywhere/verify-gap-task-evidence-exit.mjs",
          "tools/eve-everywhere/verify-gap-task-evidence-exit.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build the gap→task→evidence→exit matrix for G1–G18. Every task appears once as an owner and may appear elsewhere only as a dependency. The verifier fails on orphan gaps, circular admission, or a broad requirement \"proved\" only by a narrower test. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.7",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "File the environment capability record: Blender executable/version; Unreal required-path check; native desktop permission posture; local DB, vector store, browsers, and mobile harness; external channel credentials by name only. Stale capability records expire and are re-probed, never copied forward as fact.",
      "gapRefs": ["G2", "G3", "G5", "G6", "G11", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["0.2", "0.6"],
      "dependencyRationales": [
        "Uses the reproducible baseline and its actual capability boundary.",
        "Uses the task ownership and direct proof-boundary contract."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "host-capability-observation"
      ],
      "evidencePlan": {
        "id": "evidence-0-7",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "host-capability-observation"],
        "evidenceClassRefs": ["source-review", "automated-static", "live-runtime"],
        "artifactLocators": [
          "docs/audits/eve-sota-environment-capabilities/2026-09-01.json",
          "docs/audits/eve-sota-environment-capabilities.schema.json",
          "docs/audits/EVE_SOTA_ENVIRONMENT_CAPABILITY_RECORD_2026-09.md",
          "docs/audits/EVE_SOTA_ENVIRONMENT_CAPABILITY_RECORD_2026-09.html",
          "tools/eve-everywhere/probe-environment-capabilities.mjs",
          "tools/eve-everywhere/verify-environment-capabilities.mjs",
          "tools/eve-everywhere/verify-environment-capabilities.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-7.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "File the environment capability record: Blender executable/version; Unreal required-path check; native desktop permission posture; local DB, vector store, browsers, and mobile harness; external channel credentials by name only. Stale capability records expire and are re-probed, never copied forward as fact. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "0.8",
      "phaseId": "0",
      "closureState": "completed",
      "requirement": "Expand and independently ratify the charter workflow inventory in `docs/audits/EVE_SOTA_CHARTER_COMPLETENESS_2026-09.md` against every canonical V1–V10 feature map, its linked detail pages, architecture, release scope, and product graph. Assign every substantive requirement a workflow/acceptance scenario or an explicit non-goal justified by its authoritative source; include all ruleset cells and declared platforms. Bind source revisions, capability/runtime requirements, task owners, evidence boundaries, quality targets, and review ownership. Fail on unmapped requirements, stale sources, optionalized required runtimes, or deletion of a blocked workflow. The starting matrix is a planning seed, not proof of complete coverage or delivered capability.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.3", "0.4", "0.5", "0.6", "0.7"],
      "dependencyRationales": [
        "Consumes the preregistered outcome thresholds and decision rules.",
        "Uses the versioned source/control crosswalk to define applicable obligations.",
        "Uses the admitted evidence format and negative-control requirements.",
        "Uses the task ownership and direct proof-boundary contract.",
        "Requires fresh observed host and runtime availability."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "governance-decision",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-0-8",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "governance-decision",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [
          "docs/audits/eve-sota-charter-workflows/2026-09-07.json",
          "docs/audits/eve-sota-charter-workflows.schema.json",
          "docs/audits/eve-sota-charter-workflows/reviews/confirmatory.json",
          "docs/audits/eve-sota-charter-workflows/reviews/adversarial.json",
          "docs/audits/EVE_SOTA_CHARTER_COMPLETENESS_2026-09.md",
          "tools/eve-everywhere/generate-charter-workflow-inventory.mjs",
          "tools/eve-everywhere/verify-charter-workflow-inventory.mjs",
          "tools/eve-everywhere/verify-charter-workflow-inventory.test.mjs",
          "tools/eve-everywhere/verify-charter-workflow-evidence.mjs",
          "tools/eve-everywhere/verify-charter-workflow-evidence.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-00/task-0-8.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Expand and independently ratify the charter workflow inventory in `docs/audits/EVE_SOTA_CHARTER_COMPLETENESS_2026-09.md` against every canonical V1–V10 feature map, its linked detail pages, architecture, release scope, and product graph. Assign every substantive requirement a workflow/acceptance scenario or an explicit non-goal justified by its authoritative source; include all ruleset cells and declared platforms. Bind source revisions, capability/runtime requirements, task owners, evidence boundaries, quality targets, and review ownership. Fail on unmapped requirements, stale sources, optionalized required runtimes, or deletion of a blocked workflow. The starting matrix is a planning seed, not proof of complete coverage or delivered capability. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.1",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Survey the current Metis OpenAPI, web routes, migrations/alembic heads, stores, and recent churn. Produce a page→route→store→authz→classification table. If the contract is still moving daily, record evidence and park implementation without pretending the seam closed.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "privacy-data-rights"],
      "evidencePlan": {
        "id": "evidence-1-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "privacy-data-rights"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/eve-sota-metis-seam-survey/2026-09-01.json",
          "docs/audits/eve-sota-metis-seam-survey.schema.json",
          "docs/audits/EVE_SOTA_METIS_SEAM_SURVEY_2026-09.md",
          "docs/audits/EVE_SOTA_METIS_SEAM_SURVEY_2026-09.html",
          "tools/eve-everywhere/generate-metis-seam-survey.mjs",
          "tools/eve-everywhere/verify-metis-seam-survey.mjs",
          "tools/eve-everywhere/verify-metis-seam-survey.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Survey the current Metis OpenAPI, web routes, migrations/alembic heads, stores, and recent churn. Produce a page→route→store→authz→classification table. If the contract is still moving daily, record evidence and park implementation without pretending the seam closed. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.2",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Decide direct-store vs HTTP transport through the decision lane. Default recommendation remains the Metis HTTP API because it is the authz-bearing Python-service boundary; specify timeouts, versioning, retries, identity propagation, and degraded behavior.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.1"],
      "dependencyRationales": [
        "Consumes the surveyed authoritative Metis API and stable surface inventory."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-1-2",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/eve-sota-metis-transport-decision/2026-09-01.json",
          "docs/audits/eve-sota-metis-transport-decision.schema.json",
          "docs/adr/ADR-0075-eve-metis-workbench-http-transport.md",
          "docs/adr/ADR-0075-eve-metis-workbench-http-transport.html",
          "docs/audits/eve-sota-evidence/phase-01/task-1-2.json",
          "tools/eve-everywhere/generate-metis-transport-decision.mjs",
          "tools/eve-everywhere/verify-metis-transport-decision.mjs",
          "tools/eve-everywhere/verify-metis-transport-decision.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Decide direct-store vs HTTP transport through the decision lane. Default recommendation remains the Metis HTTP API because it is the authz-bearing Python-service boundary; specify timeouts, versioning, retries, identity propagation, and degraded behavior. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.3",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Register the real Metis read views under `KitReadSeam` (or a renamed generic workbench seam if the abstraction no longer fits): item bank, clarity/readability/alignment gates, release readiness, import batches, and every other stable surface the survey proves. No candidate becomes a view merely because its name appears here.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.1", "1.2"],
      "dependencyRationales": [
        "Consumes the surveyed authoritative Metis API and stable surface inventory.",
        "Uses the approved transport, identity and failure semantics."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "service-integration"],
      "evidencePlan": {
        "id": "evidence-1-3",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "service-integration"],
        "evidenceClassRefs": ["source-review", "automated-static", "service-integration"],
        "artifactLocators": [
          "docs/audits/eve-sota-metis-view-admission/2026-09-01.json",
          "docs/audits/eve-sota-metis-view-admission.schema.json",
          "docs/audits/EVE_SOTA_METIS_VIEW_ADMISSION_2026-09.md",
          "docs/audits/EVE_SOTA_METIS_VIEW_ADMISSION_2026-09.html",
          "docs/audits/eve-sota-evidence/phase-01/task-1-3.json",
          "tools/eve-everywhere/generate-metis-view-admission.mjs",
          "tools/eve-everywhere/verify-metis-view-admission.mjs",
          "tools/eve-everywhere/verify-metis-view-admission.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Register the real Metis read views under `KitReadSeam` (or a renamed generic workbench seam if the abstraction no longer fits): item bank, clarity/readability/alignment gates, release readiness, import batches, and every other stable surface the survey proves. No candidate becomes a view merely because its name appears here. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.4",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Enforce subject/tenant/scope and data classification before query execution. For every refusal, a test must reach that exact guard rather than being masked by an earlier one; unknown views and service loss fail loud, never empty-success.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.3"],
      "dependencyRationales": ["Exercises the admitted read views and their actual bindings."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-1-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "fault-recovery"
        ],
        "evidenceClassRefs": ["source-review", "automated-test", "service-integration"],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/workbench-kit-read.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-read.spec.ts",
          "libs/oshun/workbench-kit/src/router.ts",
          "libs/oshun/workbench-kit/src/router.spec.ts",
          "docs/audits/eve-sota-metis-query-guard/2026-09-01.json",
          "docs/audits/eve-sota-metis-query-guard.schema.json",
          "docs/audits/EVE_SOTA_METIS_QUERY_GUARD_2026-09.md",
          "docs/audits/EVE_SOTA_METIS_QUERY_GUARD_2026-09.html",
          "docs/audits/eve-sota-evidence/phase-01/task-1-4.json",
          "tools/eve-everywhere/generate-metis-query-guard.mjs",
          "tools/eve-everywhere/verify-metis-query-guard.mjs",
          "tools/eve-everywhere/verify-metis-query-guard.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Enforce subject/tenant/scope and data classification before query execution. For every refusal, a test must reach that exact guard rather than being masked by an earlier one; unknown views and service loss fail loud, never empty-success. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.5",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Inventory safe Metis mutations supported by the authoritative API. Admit only real, reversible/card-gated operations with preview, idempotency, audit, and exact outcomes; otherwise file a zero-write verdict explaining why read-only is the correct boundary.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.1", "1.2", "1.4"],
      "dependencyRationales": [
        "Consumes the surveyed authoritative Metis API and stable surface inventory.",
        "Uses the approved transport, identity and failure semantics.",
        "Requires the subject, tenant and scope guards around those views."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-1-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration"
        ],
        "artifactLocators": [
          "apps/metis/service/openapi/metis.openapi.json",
          "apps/metis/service/src/metis/api/item_import.py",
          "apps/metis/service/src/metis/services/item_import_service.py",
          "apps/metis/service/tests/test_item_import_api_contract.py",
          "apps/metis/service/tests/test_item_import_service.py",
          "apps/metis/service/tests/test_item_import_postgres_integration.py",
          "docs/audits/eve-sota-metis-mutation-admission/2026-09-01.json",
          "docs/audits/eve-sota-metis-mutation-admission.schema.json",
          "docs/audits/EVE_SOTA_METIS_MUTATION_ADMISSION_2026-09.md",
          "docs/audits/EVE_SOTA_METIS_MUTATION_ADMISSION_2026-09.html",
          "docs/audits/eve-sota-evidence/phase-01/task-1-5.json",
          "tools/eve-everywhere/generate-metis-mutation-admission.mjs",
          "tools/eve-everywhere/verify-metis-mutation-admission.mjs",
          "tools/eve-everywhere/verify-metis-mutation-admission.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Inventory safe Metis mutations supported by the authoritative API. Admit only real, reversible/card-gated operations with preview, idempotency, audit, and exact outcomes; otherwise file a zero-write verdict explaining why read-only is the correct boundary. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.6",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Re-stamp the prompt/tool ratchet once; add diverse Metis read/write or correct-refusal deck cases; run the provider-free contracts and a k≥10 pinned live battery; record floors against Phase 0.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.3", "1.4", "1.5"],
      "dependencyRationales": [
        "Exercises the admitted read views and their actual bindings.",
        "Requires the subject, tenant and scope guards around those views.",
        "Uses the authoritative mutation or source-backed zero-write boundary."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-1-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/evals/deck-builder-cases.ts",
          "apps/oshun/bff/src/assistant/evals/deck-builder-cases.spec.ts",
          "apps/oshun/bff/src/assistant/evals/eval-harness.ts",
          "apps/oshun/bff/src/assistant/evals/eval-harness.spec.ts",
          "docs/audits/eve-smx-ratchet.json",
          "docs/audits/EVE_SMX_SCORECARD.md",
          "docs/audits/EVE_SMX_DECK_SOURCES.md",
          "docs/audits/eve-sota-metis-prompt-tool-ratchet.schema.json",
          "docs/audits/eve-sota-metis-prompt-tool-ratchet/2026-09-02-live.json",
          "docs/audits/eve-sota-evidence/phase-01/task-1-6.json",
          "tools/eve-everywhere/verify-metis-prompt-tool-ratchet.mjs",
          "tools/eve-everywhere/verify-metis-prompt-tool-ratchet.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Re-stamp the prompt/tool ratchet once; add diverse Metis read/write or correct-refusal deck cases; run the provider-free contracts and a k≥10 pinned live battery; record floors against Phase 0. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.7",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Negative controls: unknown view/command, cross-tenant, insufficient scope, service down/timeout, malformed upstream payload, replayed mutation, stale version, and an injected Metis record. Observe failures and lock regressions.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.3", "1.4", "1.5", "1.6"],
      "dependencyRationales": [
        "Exercises the admitted read views and their actual bindings.",
        "Requires the subject, tenant and scope guards around those views.",
        "Uses the authoritative mutation or source-backed zero-write boundary.",
        "Depends on the restamped tool contract and measured Metis battery."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-1-7",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/evals/eval-harness.spec.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-read.spec.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-write.spec.ts",
          "libs/oshun/workbench-kit/src/router.spec.ts",
          "docs/audits/eve-sota-metis-negative-controls/2026-09-02.json",
          "docs/audits/eve-sota-metis-negative-controls.schema.json",
          "docs/audits/EVE_SOTA_METIS_NEGATIVE_CONTROLS_2026-09.md",
          "docs/audits/EVE_SOTA_METIS_NEGATIVE_CONTROLS_2026-09.html",
          "docs/audits/eve-sota-evidence/phase-01/task-1-7.json",
          "tools/eve-everywhere/generate-metis-negative-controls.mjs",
          "tools/eve-everywhere/probe-metis-transport-failures.mjs",
          "tools/eve-everywhere/probe-metis-transport-failures.test.mjs",
          "tools/eve-everywhere/verify-metis-negative-controls.mjs",
          "tools/eve-everywhere/verify-metis-negative-controls.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-7.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Negative controls: unknown view/command, cross-tenant, insufficient scope, service down/timeout, malformed upstream payload, replayed mutation, stale version, and an injected Metis record. Observe failures and lock regressions. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.8",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Add \"Eve seam registered, zero-view/write verdict recorded, or explicit defer owner named\" to each future workbench phase exit (V/Y/E/A/B and any new domain). Add a totality verifier so a durable route/store can no longer become Eve-invisible silently.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["1.1", "1.7"],
      "dependencyRationales": [
        "Consumes the surveyed authoritative Metis API and stable surface inventory.",
        "Requires the observed Metis refusal, replay and outage controls."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration"
      ],
      "evidencePlan": {
        "id": "evidence-1-8",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration"
        ],
        "artifactLocators": [
          "V1_DOMAIN_WORKBENCHES_TODOS_2026-07-23.md",
          "docs/audits/eve-sota-workbench-seam-totality/2026-09-02.json",
          "docs/audits/eve-sota-workbench-seam-totality.schema.json",
          "docs/audits/EVE_SOTA_WORKBENCH_SEAM_TOTALITY_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-01/task-1-8.json",
          "tools/eve-everywhere/generate-workbench-seam-totality.mjs",
          "tools/eve-everywhere/verify-workbench-seam-totality.mjs",
          "tools/eve-everywhere/verify-workbench-seam-totality.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-8.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Add \"Eve seam registered, zero-view/write verdict recorded, or explicit defer owner named\" to each future workbench phase exit (V/Y/E/A/B and any new domain). Add a totality verifier so a durable route/store can no longer become Eve-invisible silently. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "1.9",
      "phaseId": "1",
      "closureState": "completed",
      "requirement": "Supersede the historical defer-as-registration option in task 1.8 for required workbench outcomes. Owner: Agentic AI PM; verifier: QA Lead. Extend the totality verifier and every future workbench exit to distinguish a source-justified zero- operation boundary from an unavailable required seam. An explicit defer owner preserves ownership but cannot pass completion. Exercise missing required reads/writes, a deferred required seam, a valid source-backed non-goal, and real admitted operations through the gate CLI; bind required workbenches from task 0.8.",
      "gapRefs": ["G4"],
      "dependencyTaskIds": ["0.8", "1.8"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Extends the existing workbench seam totality mechanism."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-1-9",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "governance-review"
        ],
        "artifactLocators": [
          "V1_DOMAIN_WORKBENCHES_TODOS_2026-07-23.md",
          "docs/audits/eve-sota-charter-workflows/2026-09-07.json",
          "docs/audits/eve-sota-workbench-seam-totality/2026-09-08.json",
          "docs/audits/eve-sota-workbench-seam-totality.schema.json",
          "docs/audits/EVE_SOTA_WORKBENCH_SEAM_TOTALITY_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-01/task-1-9.json",
          "tools/eve-everywhere/generate-workbench-seam-totality.mjs",
          "tools/eve-everywhere/verify-workbench-seam-totality.mjs",
          "tools/eve-everywhere/verify-workbench-seam-totality.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-01/task-1-9.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Supersede the historical defer-as-registration option in task 1.8 for required workbench outcomes. Owner: Agentic AI PM; verifier: QA Lead. Extend the totality verifier and every future workbench exit to distinguish a source-justified zero- operation boundary from an unavailable required seam. An explicit defer owner preserves ownership but cannot pass completion. Exercise missing required reads/writes, a deferred required seam, a valid source-backed non-goal, and real admitted operations through the gate CLI; bind required workbenches from task 0.8. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.1",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "ADR: define the goal→requirements→dependency DAG→verification plan→work items→leases→review→ship→verify lifecycle. Preserve human decisions, requirement traceability, reversible boundaries, and the invariant that drained and hand-leased items emit identical ledger states.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-2-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/adr/ADR-0076-eve-governed-delivery-lifecycle.md",
          "docs/audits/eve-sota-governed-delivery-lifecycle/2026-09-02.json",
          "docs/audits/eve-sota-governed-delivery-lifecycle.schema.json",
          "docs/audits/eve-sota-evidence/phase-02/task-2-1.json",
          "tools/eve-everywhere/generate-governed-delivery-lifecycle.mjs",
          "tools/eve-everywhere/verify-governed-delivery-lifecycle.mjs",
          "tools/eve-everywhere/verify-governed-delivery-lifecycle.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "ADR: define the goal→requirements→dependency DAG→verification plan→work items→leases→review→ship→verify lifecycle. Preserve human decisions, requirement traceability, reversible boundaries, and the invariant that drained and hand-leased items emit identical ledger states. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.2",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "Define queue semantics: local concurrency 1; cloud N only after spend approval; priority/fairness/starvation; lease TTL/renewal; monotonic fencing token; idempotency key; retry budget; poison-item quarantine; dependency readiness; orphan recovery; terminal-state ownership.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.1"],
      "dependencyRationales": ["Implements the adopted attributed delivery lifecycle."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-2-2",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "apps/oshun/bff/src/workbench/queue-semantics.ts",
          "apps/oshun/bff/src/workbench/queue-semantics.spec.ts",
          "apps/oshun/bff/src/workbench/queue-semantics.integration.spec.ts",
          "libs/oshun/persistence/prisma/migrations/20260904190000_workbench_queue_semantics/migration.sql",
          "docs/audits/eve-sota-queue-semantics/2026-09-04.json",
          "docs/audits/eve-sota-queue-semantics.schema.json",
          "docs/audits/EVE_SOTA_QUEUE_SEMANTICS_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-02/task-2-2.json",
          "tools/eve-everywhere/generate-queue-semantics.mjs",
          "tools/eve-everywhere/verify-queue-semantics.mjs",
          "tools/eve-everywhere/verify-queue-semantics.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Define queue semantics: local concurrency 1; cloud N only after spend approval; priority/fairness/starvation; lease TTL/renewal; monotonic fencing token; idempotency key; retry budget; poison-item quarantine; dependency readiness; orphan recovery; terminal-state ownership. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.3",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "Build `tools/eve-fleet-drain.mjs` (or a service if durability evidence requires one): `--dry-run`, `--limit`, resumable run id, PID/process-group tracking, clean termination, per-item resource checkpoint, version/capability preflight, and no unbounded loop.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.2"],
      "dependencyRationales": [
        "Consumes canonical readiness, lease, fencing and terminal-state semantics."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "host-capability-observation",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-2-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "host-capability-observation",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [
          "tools/eve-fleet-drain.mjs",
          "tools/eve-fleet-drain-lib.mjs",
          "tools/eve-fleet-drain.test.mjs",
          "tools/eve-everywhere/probe-fleet-drain.mjs",
          "docs/audits/eve-sota-fleet-drain/2026-09-04.json",
          "docs/audits/eve-sota-fleet-drain.schema.json",
          "docs/audits/EVE_SOTA_FLEET_DRAIN_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-02/task-2-3.json",
          "tools/eve-everywhere/generate-fleet-drain.mjs",
          "tools/eve-everywhere/verify-fleet-drain.mjs",
          "tools/eve-everywhere/verify-fleet-drain.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build `tools/eve-fleet-drain.mjs` (or a service if durability evidence requires one): `--dry-run`, `--limit`, resumable run id, PID/process-group tracking, clean termination, per-item resource checkpoint, version/capability preflight, and no unbounded loop. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.4",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "Add verifier-triaged retry. `ship-verify-gap`, test failure, conflict, ambiguous requirement, budget exhaustion, and agent refusal produce distinct triage records with evidence; never silent requeue or quiet close.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.2", "2.3"],
      "dependencyRationales": [
        "Consumes canonical readiness, lease, fencing and terminal-state semantics.",
        "Exercises the real resumable drain and its process supervision."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-2-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "fault-recovery"
        ],
        "evidenceClassRefs": ["source-review", "automated-test", "service-integration"],
        "artifactLocators": [
          "apps/oshun/bff/src/workbench/triage.ts",
          "apps/oshun/bff/src/workbench/triage.spec.ts",
          "apps/oshun/bff/src/workbench/triage.integration.spec.ts",
          "docs/audits/eve-sota-triage-contract/2026-09-05.json",
          "docs/audits/eve-sota-triage-contract.schema.json",
          "docs/audits/EVE_SOTA_TRIAGE_CONTRACT_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-02/task-2-4.json",
          "tools/eve-everywhere/generate-triage-contract.mjs",
          "tools/eve-everywhere/verify-triage-contract.mjs",
          "tools/eve-everywhere/verify-triage-contract.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Add verifier-triaged retry. `ship-verify-gap`, test failure, conflict, ambiguous requirement, budget exhaustion, and agent refusal produce distinct triage records with evidence; never silent requeue or quiet close. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.5",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "Expose an `admin_agent_fleet` read surface: queue/dependency depth, leases/ages/owners, triage, last drain, throughput, cost, intervention, verification/rollback rate, kill-switch state, and trace links. Keep the operator workspace restrained and scannable; no dashboard-card mosaic.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.2", "2.3", "2.4"],
      "dependencyRationales": [
        "Consumes canonical readiness, lease, fencing and terminal-state semantics.",
        "Exercises the real resumable drain and its process supervision.",
        "Requires evidence-linked retry and truthful triage behavior."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-browser-ui",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-2-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-browser-ui",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/workbench/fleet-read-model.ts",
          "apps/oshun/bff/src/workbench/fleet-read-model.spec.ts",
          "apps/oshun/bff/src/workbench/fleet-read-model.integration.spec.ts",
          "docs/audits/eve-sota-fleet-read/2026-09-05.json",
          "docs/audits/eve-sota-fleet-read.schema.json",
          "docs/audits/EVE_SOTA_FLEET_READ_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-02/task-2-5.json",
          "tools/eve-everywhere/generate-fleet-read.mjs",
          "tools/eve-everywhere/verify-fleet-read.mjs",
          "tools/eve-everywhere/verify-fleet-read.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Expose an `admin_agent_fleet` read surface: queue/dependency depth, leases/ages/owners, triage, last drain, throughput, cost, intervention, verification/rollback rate, kill-switch state, and trace links. Keep the operator workspace restrained and scannable; no dashboard-card mosaic. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.6",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "Add branch/worktree isolation, dirty-tree protection, remote-divergence handling, scoped credentials, allowed command roots, network/secret policy, artifact ceilings, and separate implementer/verifier identity.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.2", "2.3"],
      "dependencyRationales": [
        "Consumes canonical readiness, lease, fencing and terminal-state semantics.",
        "Exercises the real resumable drain and its process supervision."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "authorization-isolation",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-2-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "authorization-isolation",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "tools/eve-execution-isolation-lib.mjs",
          "tools/eve-execution-isolation.test.mjs",
          "tools/eve-fleet-drain.mjs",
          "tools/eve-fleet-drain.test.mjs",
          "docs/audits/eve-sota-execution-isolation/2026-09-05.json",
          "docs/audits/eve-sota-execution-isolation.schema.json",
          "docs/audits/EVE_SOTA_EXECUTION_ISOLATION_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-02/task-2-6.json",
          "tools/eve-everywhere/generate-execution-isolation.mjs",
          "tools/eve-everywhere/verify-execution-isolation.mjs",
          "tools/eve-everywhere/verify-execution-isolation.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Add branch/worktree isolation, dirty-tree protection, remote-divergence handling, scoped credentials, allowed command roots, network/secret policy, artifact ceilings, and separate implementer/verifier identity. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.7",
      "phaseId": "2",
      "closureState": "completed",
      "requirement": "Provider-free model of the orchestrator with property/fault tests for duplicate delivery, lease expiry/renewal races, stale fencing, crash between side effect and report, dependency cycles, poison items, cancellation, and restart from persisted state.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.1", "2.2", "2.3", "2.4", "2.5", "2.6"],
      "dependencyRationales": [
        "Implements the adopted attributed delivery lifecycle.",
        "Consumes canonical readiness, lease, fencing and terminal-state semantics.",
        "Exercises the real resumable drain and its process supervision.",
        "Requires evidence-linked retry and truthful triage behavior.",
        "Requires observable fleet state and operator kill controls.",
        "Requires isolated execution, preserved user work and independent identities."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-2-7",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/workbench/orchestrator-model.ts",
          "apps/oshun/bff/src/workbench/orchestrator-model.spec.ts",
          "docs/audits/eve-sota-orchestrator-model/2026-09-05.json",
          "docs/audits/eve-sota-orchestrator-model.schema.json",
          "docs/audits/EVE_SOTA_ORCHESTRATOR_MODEL_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-02/task-2-7.json",
          "tools/eve-everywhere/generate-orchestrator-model.mjs",
          "tools/eve-everywhere/verify-orchestrator-model.mjs",
          "tools/eve-everywhere/verify-orchestrator-model.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-7.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Provider-free model of the orchestrator with property/fault tests for duplicate delivery, lease expiry/renewal races, stale fencing, crash between side effect and report, dependency cycles, poison items, cancellation, and restart from persisted state. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "2.8",
      "phaseId": "2",
      "closureState": "open",
      "requirement": "After Security/Evaluation/Reliability gates: drain a diverse real backlog set end-to-end with no hand step between items, then run a longer supervised soak. Report success, intervention, retry, duplicate-action, time, cost, and verification rate; three happy items alone cannot close the phase.",
      "gapRefs": ["G1", "G12"],
      "dependencyTaskIds": ["2.7", "4.8", "12.7", "13.7"],
      "dependencyRationales": [
        "Consumes the fault-tested queue and hand-lease/drain parity contract.",
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "real-agent-runtime",
        "operational-load-soak",
        "fault-recovery",
        "security-adversarial",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-2-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "real-agent-runtime",
          "operational-load-soak",
          "fault-recovery",
          "security-adversarial",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "security-exercise",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-02/task-2-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "After Security/Evaluation/Reliability gates: drain a diverse real backlog set end-to-end with no hand step between items, then run a longer supervised soak. Report success, intervention, retry, duplicate-action, time, cost, and verification rate; three happy items alone cannot close the phase. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.1",
      "phaseId": "3",
      "closureState": "open",
      "requirement": "Create a versioned relevance set from real member/admin query classes: navigational, exact-id, conceptual, multi-hop, recency, contradictory, empty/unknown, tenant-sensitive, and injection-bearing. Human relevance labels remain separate from the system under evaluation.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "security-adversarial",
        "privacy-data-rights",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-3-1",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "security-adversarial",
          "privacy-data-rights",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "security-exercise",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-1.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Create a versioned relevance set from real member/admin query classes: navigational, exact-id, conceptual, multi-hop, recency, contradictory, empty/unknown, tenant-sensitive, and injection-bearing. Human relevance labels remain separate from the system under evaluation. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.2",
      "phaseId": "3",
      "closureState": "completed",
      "requirement": "Price candidate embedding models and an optional reranker at measured corpus/query volumes and cached billed cost. Record dimensions, context limits, provider data posture, latency, endpoint availability, and rollback env before binding the registry leg with `chosenBy` evidence.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["0.6", "15.1"],
      "dependencyRationales": [
        "Uses the task ownership and direct proof-boundary contract.",
        "Consumes priced, capability-correct, fail-loud model registry bindings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "real-model-provider",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-3-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "real-model-provider",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/retrieval/embedding-pricing.ts",
          "apps/oshun/bff/src/assistant/retrieval/embedding-pricing.spec.ts",
          "apps/oshun/bff/src/assistant/model-registry.ts",
          "docs/audits/eve-sota-embedding-pricing/2026-09-05.json",
          "docs/audits/eve-sota-embedding-pricing/2026-09-05.probe.json",
          "docs/audits/eve-sota-embedding-pricing.schema.json",
          "docs/audits/EVE_SOTA_EMBEDDING_PRICING_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-03/task-3-2.json",
          "tools/eve-everywhere/probe-embedding-pricing.mjs",
          "tools/eve-everywhere/generate-embedding-pricing.mjs",
          "tools/eve-everywhere/verify-embedding-pricing.mjs",
          "tools/eve-everywhere/verify-embedding-pricing.test.mjs",
          "tools/eve-everywhere/run-embedding-pricing-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Price candidate embedding models and an optional reranker at measured corpus/query volumes and cached billed cost. Record dimensions, context limits, provider data posture, latency, endpoint availability, and rollback env before binding the registry leg with `chosenBy` evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.3",
      "phaseId": "3",
      "closureState": "completed",
      "requirement": "Build the dense index over the exact lexical corpus boundary. Persist manifest/hash, source ACL/tenant/audience, chunker and embedding versions, deletion tombstones, freshness, and a `--check` mode. Admin overlay chunks must be filtered before retrieval, not merely hidden after ranking.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["3.2"],
      "dependencyRationales": [
        "Consumes the measured approved embedding route and provider boundary."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "persistence-recovery",
        "authorization-isolation",
        "real-vector-store",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-3-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "persistence-recovery",
          "authorization-isolation",
          "real-vector-store",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/retrieval/dense-index.ts",
          "apps/oshun/bff/src/assistant/retrieval/dense-index.spec.ts",
          "apps/oshun/bff/src/assistant/retrieval/embedding-client.ts",
          "apps/oshun/bff/src/assistant/retrieval/embedding-client.spec.ts",
          "apps/oshun/bff/scripts/build-docs-dense-index.ts",
          "apps/oshun/bff/src/assistant/generated/docs-dense-index.member.manifest.json",
          "apps/oshun/bff/src/assistant/generated/docs-dense-index.full.manifest.json",
          "docs/audits/eve-sota-dense-index/2026-09-05.json",
          "docs/audits/eve-sota-dense-index.schema.json",
          "docs/audits/EVE_SOTA_DENSE_INDEX_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-03/task-3-3.json",
          "tools/eve-everywhere/generate-dense-index.mjs",
          "tools/eve-everywhere/verify-dense-index.mjs",
          "tools/eve-everywhere/verify-dense-index.test.mjs",
          "tools/eve-everywhere/run-dense-index-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build the dense index over the exact lexical corpus boundary. Persist manifest/hash, source ACL/tenant/audience, chunker and embedding versions, deletion tombstones, freshness, and a `--check` mode. Admin overlay chunks must be filtered before retrieval, not merely hidden after ranking. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.4",
      "phaseId": "3",
      "closureState": "completed",
      "requirement": "Implement measured hybrid fusion (RRF or justified weighting) behind `search_docs`; optional reranking only if priced and beneficial. Define lexical-only and fail-loud modes for embedding/index/provider loss.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["3.3"],
      "dependencyRationales": ["Uses the versioned ACL-bearing dense index and deletion metadata."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-vector-store",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-3-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-vector-store",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/retrieval/hybrid-search.ts",
          "apps/oshun/bff/src/assistant/retrieval/hybrid-search.spec.ts",
          "apps/oshun/bff/src/assistant/agent-tools.ts",
          "apps/oshun/bff/src/routes/assistant.ts",
          "docs/audits/eve-sota-hybrid-retrieval/2026-09-16.json",
          "docs/audits/eve-sota-hybrid-retrieval.schema.json",
          "docs/audits/EVE_SOTA_HYBRID_RETRIEVAL_2026-09.md",
          "docs/audits/eve-sota-dense-index/2026-09-05.json",
          "docs/audits/EVE_SOTA_DENSE_INDEX_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-03/task-3-4.json",
          "tools/eve-everywhere/measure-hybrid-fusion.ts",
          "tools/eve-everywhere/probe-hybrid-docs-retrieval.ts",
          "tools/eve-everywhere/verify-hybrid-retrieval.mjs",
          "tools/eve-everywhere/verify-hybrid-retrieval.test.mjs",
          "tools/eve-everywhere/run-hybrid-retrieval-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Implement measured hybrid fusion (RRF or justified weighting) behind `search_docs`; optional reranking only if priced and beneficial. Define lexical-only and fail-loud modes for embedding/index/provider loss. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.5",
      "phaseId": "3",
      "closureState": "open",
      "requirement": "Measure Recall@k, nDCG/MRR where appropriate, citation precision/recall, answer support, abstention, latency, and cost. Compare arms on paired query/case units using a pre-registered paired test or bootstrap; do not treat repeated k-runs of the same case as independent Fisher samples.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["3.1", "3.4"],
      "dependencyRationales": [
        "Requires independently human-labelled relevance cases for quality claims.",
        "Exercises actual hybrid fusion, fallback and ranking behavior."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-vector-store",
        "performance-quality",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-3-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-vector-store",
          "performance-quality",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Measure Recall@k, nDCG/MRR where appropriate, citation precision/recall, answer support, abstention, latency, and cost. Compare arms on paired query/case units using a pre-registered paired test or bootstrap; do not treat repeated k-runs of the same case as independent Fisher samples. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.6",
      "phaseId": "3",
      "closureState": "completed",
      "requirement": "Test corpus/embedding poisoning, adversarial chunks, stale/conflicting sources, deleted documents, query leakage, cross-audience and cross-tenant retrieval, oversized content, unavailable index, and citation mismatch.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["3.3", "3.4"],
      "dependencyRationales": [
        "Uses the versioned ACL-bearing dense index and deletion metadata.",
        "Exercises actual hybrid fusion, fallback and ranking behavior."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-vector-store",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-3-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-vector-store",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/docs-search.ts",
          "apps/oshun/bff/src/assistant/agent-tools.ts",
          "apps/oshun/bff/src/assistant/citation-claim-check.ts",
          "apps/oshun/bff/src/assistant/retrieval/dense-index.ts",
          "apps/oshun/bff/src/assistant/retrieval/hybrid-search.ts",
          "apps/oshun/bff/src/assistant/retrieval/adversarial-retrieval.spec.ts",
          "docs/audits/eve-sota-retrieval-adversarial/2026-09-16.json",
          "docs/audits/eve-sota-retrieval-adversarial.schema.json",
          "docs/audits/EVE_SOTA_RETRIEVAL_ADVERSARIAL_2026-09.md",
          "docs/audits/eve-sota-dense-index/2026-09-05.json",
          "docs/audits/eve-sota-security-suite/2026-09-06.json",
          "docs/audits/eve-sota-evidence/phase-04/task-4-3.json",
          "docs/audits/eve-sota-evidence/phase-03/task-3-6.json",
          "tools/eve-everywhere/probe-retrieval-adversarial-index.ts",
          "tools/eve-everywhere/verify-retrieval-adversarial.mjs",
          "tools/eve-everywhere/verify-retrieval-adversarial.test.mjs",
          "tools/eve-everywhere/run-retrieval-adversarial-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Test corpus/embedding poisoning, adversarial chunks, stale/conflicting sources, deleted documents, query leakage, cross-audience and cross-tenant retrieval, oversized content, unavailable index, and citation mismatch. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.7",
      "phaseId": "3",
      "closureState": "open",
      "requirement": "Promote only on a measured task/relevance win without security or cost regression. A lexical-only verdict can be SOTA-for-this-corpus if evidence wins; record it as an evaluated design choice, not a dense implementation falsely shipped.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["3.5", "3.6"],
      "dependencyRationales": [
        "Requires paired independent retrieval quality and cost measurements.",
        "Requires adversarial corpus, tenancy and poisoning evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "security-adversarial",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-3-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "security-adversarial",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "security-exercise",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Promote only on a measured task/relevance win without security or cost regression. A lexical-only verdict can be SOTA-for-this-corpus if evidence wins; record it as an evaluated design choice, not a dense implementation falsely shipped. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "3.8",
      "phaseId": "3",
      "closureState": "open",
      "requirement": "On promotion, add incremental rebuild, migration/re-embedding, backup/ restore, staleness and drift alerts, route/price checks, deletion propagation, and production shadow/canary evidence.",
      "gapRefs": ["G2", "G18"],
      "dependencyTaskIds": ["3.7", "13.6", "14.4", "15.5"],
      "dependencyRationales": [
        "Consumes the measured retrieval promotion or lexical-only decision.",
        "Requires actual backup/restore, migration and deletion-preserving recovery proof.",
        "Requires deletion/export propagation through actual data stores and backups.",
        "Requires automated route canary, drift detection, quarantine and rollback."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-vector-store",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-3-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-vector-store",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-03/task-3-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "On promotion, add incremental rebuild, migration/re-embedding, backup/ restore, staleness and drift alerts, route/price checks, deletion propagation, and production shadow/canary evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.1",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "Threat-model every Eve plane and data flow against NIST AI 600-1, NIST AI 100-2e2025, OWASP Agentic Top 10 2026, and the current MCP security requirements. Include goal hijack, tool misuse, identity/privilege abuse, agent/tool supply chain, unexpected code execution, memory/context poisoning, insecure inter-agent communication, cascading failure, denial of wallet/service, exfiltration, and repudiation.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-4-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/security/threat-model.ts",
          "apps/oshun/bff/src/assistant/security/threat-model-inventory.ts",
          "apps/oshun/bff/src/assistant/security/threat-model.spec.ts",
          "docs/audits/eve-sota-threat-model/2026-09-05.json",
          "docs/audits/eve-sota-threat-model.schema.json",
          "docs/audits/EVE_SOTA_THREAT_MODEL_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-04/task-4-1.json"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Threat-model every Eve plane and data flow against NIST AI 600-1, NIST AI 100-2e2025, OWASP Agentic Top 10 2026, and the current MCP security requirements. Include goal hijack, tool misuse, identity/privilege abuse, agent/tool supply chain, unexpected code execution, memory/context poisoning, insecure inter-agent communication, cascading failure, denial of wallet/service, exfiltration, and repudiation. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.2",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "Define trust labels and provenance/taint propagation at prompt assembly for user text, page/a11y context, selections, docs/RAG chunks, tool results, workbench records, memory, agent messages, channel content, DCC output, screenshots/OCR, attachments, and generated UI. Untrusted content cannot mint authority or erase its label through summarization.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.1"],
      "dependencyRationales": ["Consumes the threat model and concrete attack boundaries."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-4-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/security/trust-labels.ts",
          "apps/oshun/bff/src/assistant/security/trust-labels.spec.ts",
          "tools/eve-everywhere/verify-trust-labels.mjs",
          "docs/audits/eve-sota-evidence/phase-04/task-4-2.json",
          "docs/audits/EVE_SOTA_THREAT_MODEL_2026-09.md"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Define trust labels and provenance/taint propagation at prompt assembly for user text, page/a11y context, selections, docs/RAG chunks, tool results, workbench records, memory, agent messages, channel content, DCC output, screenshots/OCR, attachments, and generated UI. Untrusted content cannot mint authority or erase its label through summarization. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.3",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "Promote/extend the existing eight injection cases into a dedicated injection/security family with sufficient independent cases per vector, multi-turn/adaptive attacks, attack-success rate, benign-utility controls, and k≥10 stochastic floors. Grade safe continuation and task success, not blanket refusal.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.1", "4.2"],
      "dependencyRationales": [
        "Consumes the threat model and concrete attack boundaries.",
        "Requires trust labels and provenance to survive prompt assembly."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-4-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/evals/deck-security-cases.ts",
          "apps/oshun/bff/src/assistant/evals/deck-security-cases.spec.ts",
          "tools/eve-everywhere/probe-security-suite.mjs",
          "docs/audits/eve-sota-security-suite/2026-09-06.json",
          "docs/audits/eve-sota-security-suite/2026-09-06.eval.log",
          "docs/audits/eve-sota-security-suite.schema.json",
          "docs/audits/EVE_SOTA_SECURITY_SUITE_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-04/task-4-3.json"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Promote/extend the existing eight injection cases into a dedicated injection/security family with sufficient independent cases per vector, multi-turn/adaptive attacks, attack-success rate, benign-utility controls, and k≥10 stochastic floors. Grade safe continuation and task success, not blanket refusal. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.4",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "Centralize effective authority: authenticated actor, tenant/workspace, task/lease, tool risk class, object/row, purpose, time, budget, network, app/window/path, and confirmation state. Tests prove denied authority cannot be recovered through another tool, subagent, channel, MCP server, replay, or prompt.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.1"],
      "dependencyRationales": ["Consumes the threat model and concrete attack boundaries."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-4-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/security/effective-authority.ts",
          "apps/oshun/bff/src/assistant/security/effective-authority.spec.ts",
          "tools/eve-everywhere/verify-effective-authority.mjs",
          "docs/audits/eve-sota-evidence/phase-04/task-4-4.json"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Centralize effective authority: authenticated actor, tenant/workspace, task/lease, tool risk class, object/row, purpose, time, budget, network, app/window/path, and confirmation state. Tests prove denied authority cannot be recovered through another tool, subagent, channel, MCP server, replay, or prompt. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.5",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "Build execution isolation for code, DCC, and computer use: scoped filesystem roots, process tree, network egress, environment, clipboard, device/app/window, artifact limits, time/cost, and cleanup. Secrets are redacted and brokered as short-lived purpose-bound credentials, never placed in model-visible context.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.1", "4.4"],
      "dependencyRationales": [
        "Consumes the threat model and concrete attack boundaries.",
        "Uses deterministic effective-authority enforcement."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "authorization-isolation",
        "native-desktop-runtime",
        "real-dcc-runtime",
        "host-capability-observation",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-4-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "authorization-isolation",
          "native-desktop-runtime",
          "real-dcc-runtime",
          "host-capability-observation",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/security/execution-isolation.ts",
          "apps/oshun/bff/src/assistant/security/execution-isolation.spec.ts",
          "libs/bellona/blender-agent/src/blender-execution-isolation.ts",
          "libs/bellona/blender-agent/src/blender-execution-isolation.test.ts",
          "libs/bellona/blender-agent/src/blender-execution-isolation.integration.spec.ts",
          "docs/audits/EVE_SOTA_EXECUTION_ISOLATION_2026-09.md",
          "docs/audits/eve-sota-cross-surface-execution-isolation.blender-live.schema.json",
          "docs/audits/eve-sota-cross-surface-execution-isolation/2026-09-16.blender-live.json",
          "docs/audits/eve-sota-cross-surface-execution-isolation/2026-09-16.native-live.json",
          "docs/audits/eve-sota-evidence/phase-04/task-4-5.json",
          "tools/eve-everywhere/probe-governed-blender-isolation.ts",
          "tools/eve-everywhere/verify-cross-surface-execution-isolation.mjs",
          "tools/eve-everywhere/verify-cross-surface-execution-isolation.test.mjs",
          "tools/eve-everywhere/run-cross-surface-execution-isolation-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build execution isolation for code, DCC, and computer use: scoped filesystem roots, process tree, network egress, environment, clipboard, device/app/window, artifact limits, time/cost, and cleanup. Secrets are redacted and brokered as short-lived purpose-bound credentials, never placed in model-visible context. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.6",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "MCP/external-tool trust: inventory owner/version/source/hash, capability/risk annotations treated as untrusted until policy admits them, tool-definition change quarantine, protocol negotiation, token audience validation for HTTP, no token passthrough/confused deputy, and explicit consent/step-up. Stdio credentials stay environment-scoped.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.1", "4.4"],
      "dependencyRationales": [
        "Consumes the threat model and concrete attack boundaries.",
        "Uses deterministic effective-authority enforcement."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "protocol-interop",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-4-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "protocol-interop",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "tools/workbench-mcp/trust.mjs",
          "tools/workbench-mcp/trust.test.mjs",
          "tools/workbench-mcp/server.mjs",
          "tools/workbench-mcp/interop.test.mjs",
          "apps/oshun/bff/src/workbench/publish-consent.ts",
          "apps/oshun/bff/src/workbench/publish-consent.spec.ts",
          "apps/oshun/bff/src/workbench/agent-auth.ts",
          "apps/oshun/bff/src/workbench/agent-auth.spec.ts",
          "apps/oshun/bff/src/routes/workbench.ts",
          "apps/oshun/bff/src/routes/workbench-publish-consent.spec.ts",
          "apps/oshun/bff/src/routes/workbench-publish-consent.integration.spec.ts",
          "libs/bellona/mcp-gateway/src/protected-http-auth.ts",
          "libs/bellona/mcp-gateway/src/protected-http-auth.test.ts",
          "libs/bellona/mcp-gateway/src/protected-http-peer.ts",
          "libs/bellona/mcp-gateway/src/protected-http-peer.integration.spec.ts",
          "docs/adr/ADR-0092-external-integration-registry.md",
          "docs/audits/eve-sota-evidence/phase-04/task-4-6.json",
          "tools/eve-everywhere/verify-mcp-trust.mjs",
          "tools/eve-everywhere/verify-mcp-trust-typecheck.mjs",
          "tools/eve-everywhere/run-mcp-trust-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "MCP/external-tool trust: inventory owner/version/source/hash, capability/risk annotations treated as untrusted until policy admits them, tool-definition change quarantine, protocol negotiation, token audience validation for HTTP, no token passthrough/confused deputy, and explicit consent/step-up. Stdio credentials stay environment-scoped. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.7",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "High-impact actions get deterministic validation, dry-run/impact diff, precise confirmation, immediate interrupt/kill, idempotency, and a tested undo/compensation or explicit irreversibility warning. The model never decides that its own action succeeded.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.4", "4.5"],
      "dependencyRationales": [
        "Uses deterministic effective-authority enforcement.",
        "Requires execution isolation and scoped credentials."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-4-7",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "independent-verification"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/action-confirm.ts",
          "apps/oshun/bff/src/assistant/action-confirm.spec.ts",
          "apps/oshun/bff/src/assistant/admin-agent-tools.ts",
          "apps/oshun/bff/src/assistant/agent-tools.ts",
          "apps/oshun/bff/src/assistant/security/high-impact-actions.ts",
          "apps/oshun/bff/src/assistant/security/high-impact-actions.spec.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-commands.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-read.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-write.ts",
          "apps/oshun/bff/src/assistant/workbench-kit-write.spec.ts",
          "docs/audits/eve-sota-evidence/phase-04/task-4-7.json",
          "tools/eve-everywhere/verify-high-impact-actions.mjs",
          "tools/eve-everywhere/verify-high-impact-typecheck.mjs",
          "tools/eve-everywhere/run-high-impact-actions-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-7.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "High-impact actions get deterministic validation, dry-run/impact diff, precise confirmation, immediate interrupt/kill, idempotency, and a tested undo/compensation or explicit irreversibility warning. The model never decides that its own action succeeded. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "4.8",
      "phaseId": "4",
      "closureState": "completed",
      "requirement": "Run an adversarial red-team matrix through real prompt/tool/runtime seams with benign paired controls and retained sanitized traces. Write the resulting floor/manifest hash into the cross-phase Security gate; live admissions remain blocked until it passes.",
      "gapRefs": ["G10", "G16", "G17"],
      "dependencyTaskIds": ["4.1", "4.2", "4.3", "4.4", "4.5", "4.6", "4.7"],
      "dependencyRationales": [
        "Consumes the threat model and concrete attack boundaries.",
        "Requires trust labels and provenance to survive prompt assembly.",
        "Requires paired attack and benign-utility cases.",
        "Uses deterministic effective-authority enforcement.",
        "Requires execution isolation and scoped credentials.",
        "Consumes external-tool trust and credential boundary controls.",
        "Requires confirmation, cancellation and reversal at high-impact boundaries."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-4-8",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/security/red-team-cases.ts",
          "apps/oshun/bff/src/assistant/security/red-team-matrix.ts",
          "apps/oshun/bff/src/assistant/security/red-team-matrix.spec.ts",
          "apps/oshun/bff/src/assistant/security/security-gate.ts",
          "apps/oshun/bff/src/assistant/security/model-leg-measurements.ts",
          "docs/audits/eve-sota-red-team-matrix/2026-09-06.json",
          "docs/audits/eve-sota-red-team-matrix/2026-09-06.matrix.json",
          "docs/audits/eve-sota-security-suite/model-leg-measurements.json",
          "docs/audits/eve-sota-security-suite/2026-09-06.eval.log",
          "docs/audits/eve-sota-security-suite/2026-09-06.escalation.eval.log",
          "docs/audits/EVE_SOTA_RED_TEAM_MATRIX_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-04/task-4-8.json",
          "tools/eve-everywhere/generate-red-team-matrix.mjs",
          "tools/eve-everywhere/generate-model-leg-measurements.mjs",
          "tools/eve-everywhere/verify-red-team-matrix.mjs",
          "tools/eve-everywhere/probe-security-gate-binding.mjs",
          "tools/eve-everywhere/probe-security-suite.mjs",
          "tools/eve-everywhere/verify-red-team-typecheck.mjs",
          "tools/eve-everywhere/run-red-team-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-04/task-4-8.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Run an adversarial red-team matrix through real prompt/tool/runtime seams with benign paired controls and retained sanitized traces. Write the resulting floor/manifest hash into the cross-phase Security gate; live admissions remain blocked until it passes. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.1",
      "phaseId": "5",
      "closureState": "completed",
      "requirement": "Two-pass fabrication/security audit of the actual Bellona wiring path: `blender-agent`, `mcp-gateway`, `bridge-core`, required adapters, and every delegated method. Read tests for semantic correctness; record per-library verdicts in `docs/audits/BELLONA_WIRING_PATH_AUDIT_2026-09.md`.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract"],
      "evidencePlan": {
        "id": "evidence-5-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract"],
        "evidenceClassRefs": ["source-review", "automated-static"],
        "artifactLocators": [
          "docs/audits/BELLONA_WIRING_PATH_AUDIT_2026-09.md",
          "libs/bellona/blender-agent/src/blender-rpc-bridge.ts",
          "libs/bellona/blender-agent/src/blender-rpc-bridge.test.ts",
          "libs/bellona/adapters/src/bridge/base-bridge.spec.ts"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Two-pass fabrication/security audit of the actual Bellona wiring path: `blender-agent`, `mcp-gateway`, `bridge-core`, required adapters, and every delegated method. Read tests for semantic correctness; record per-library verdicts in `docs/audits/BELLONA_WIRING_PATH_AUDIT_2026-09.md`. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.2",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Rebind direct frontier SDK/model paths Eve would exercise through the approved provider registry. Fail loud when a capability-specific model (vision, planning, generation) is unbound; do not force incompatible media operations through a text-only interface.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.1", "15.1"],
      "dependencyRationales": [
        "Consumes the audited real Bellona delegation path.",
        "Consumes priced, capability-correct, fail-loud model registry bindings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-5-2",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-2.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Rebind direct frontier SDK/model paths Eve would exercise through the approved provider registry. Fail loud when a capability-specific model (vision, planning, generation) is unbound; do not force incompatible media operations through a text-only interface. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.3",
      "phaseId": "5",
      "closureState": "completed",
      "requirement": "Pin and smoke the actual Blender executable outside the agent loop: probe the current host and configured path (including /Applications/Blender.app on macOS), then handshake→health→safe `execute_python`→save/readback/export. Record version, executable path, headless recipe, add-on state, architecture, and an observed refusal if absent; a different host record is not availability evidence.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["0.7"],
      "dependencyRationales": ["Requires fresh observed host and runtime availability."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-dcc-runtime",
        "host-capability-observation",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-dcc-runtime",
          "host-capability-observation",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [
          "docs/audits/BELLONA_BLENDER_SMOKE_2026-09.md",
          "libs/bellona/blender-agent/src/blender-executable-smoke.integration.spec.ts"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Pin and smoke the actual Blender executable outside the agent loop: probe the current host and configured path (including /Applications/Blender.app on macOS), then handshake→health→safe `execute_python`→save/readback/export. Record version, executable path, headless recipe, add-on state, architecture, and an observed refusal if absent; a different host record is not availability evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.4",
      "phaseId": "5",
      "closureState": "completed",
      "requirement": "Classify the admitted Blender action catalog by read/write/destructive/ external-export risk; validate parameters and project roots; make planners, estimators, dry-run diffs, artifact manifests, and audit records real and deterministic before agent exposure.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.1", "5.3"],
      "dependencyRationales": [
        "Consumes the audited real Bellona delegation path.",
        "Requires a real Blender handshake and save/readback smoke."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-5-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "libs/bellona/blender-agent/src/blender-action-risk.ts",
          "libs/bellona/blender-agent/src/blender-action-risk.spec.ts"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Classify the admitted Blender action catalog by read/write/destructive/ external-export risk; validate parameters and project roots; make planners, estimators, dry-run diffs, artifact manifests, and audit records real and deterministic before agent exposure. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.5",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "After the cross-phase gates, register Bellona stdio MCP only on an attributed leased-work surface. It is never a copilot-drawer tool. Bridge actor/task/lease/fencing/confirmation/budget/trace into the intent ledger.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.8", "5.2", "5.4", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Requires capability-correct registry model bindings.",
        "Uses the deterministic risk-classified Blender action catalog.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-dcc-runtime",
        "protocol-interop",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-5-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-dcc-runtime",
          "protocol-interop",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "After the cross-phase gates, register Bellona stdio MCP only on an attributed leased-work surface. It is never a copilot-drawer tool. Bridge actor/task/lease/fencing/confirmation/budget/trace into the intent ledger. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.6",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "First light: a leased item creates a parameterized scene, saves and exports it, then independent verification checks Blender readback, semantic scene properties, content hash, and render/artifact diff. Cite the dry-run, tool trace, audit rows, and produced artifact.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.5"],
      "dependencyRationales": ["Requires governed leased Bellona admission."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "real-dcc-runtime",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "real-dcc-runtime",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "service-integration",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "First light: a leased item creates a parameterized scene, saves and exports it, then independent verification checks Blender readback, semantic scene properties, content hash, and render/artifact diff. Cite the dry-run, tool trace, audit rows, and produced artifact. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.7",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Breadth suite: inspect, create, edit, undo, resume, import, export, missing dependency, version mismatch, long job/progress, cancellation, invalid project, and deterministic reopen. Add visual-quality evaluation only where a calibrated visual judge/human rubric exists.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.6"],
      "dependencyRationales": [
        "Extends the independently verified real Blender first-light artifact."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-dcc-runtime",
        "fault-recovery",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-dcc-runtime",
          "fault-recovery",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Breadth suite: inspect, create, edit, undo, resume, import, export, missing dependency, version mismatch, long job/progress, cancellation, invalid project, and deterministic reopen. Add visual-quality evaluation only where a calibrated visual judge/human rubric exists. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.8",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Negative controls: absent/killed Blender, RPC timeout, malformed result, injected scene/text/node names, path traversal, external network request, dry-run rejection, stale lease, duplicate action, partial export, and verifier disagreement. No fabricated file or success survives.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.5", "5.7"],
      "dependencyRationales": [
        "Requires governed leased Bellona admission.",
        "Requires the Blender breadth and reopen behavior under test."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-dcc-runtime",
        "fault-recovery",
        "security-adversarial",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-dcc-runtime",
          "fault-recovery",
          "security-adversarial",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Negative controls: absent/killed Blender, RPC timeout, malformed result, injected scene/text/node names, path traversal, external network request, dry-run rejection, stale lease, duplicate action, partial export, and verifier disagreement. No fabricated file or success survives. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.9",
      "phaseId": "5",
      "closureState": "completed",
      "requirement": "Recheck local UE at the mandated path before every availability claim. For Unreal/Unity/Houdini/Maya/etc., maintain a host/runtime/licence matrix, per-adapter audit, and exact live unblock criteria; do not let Blender first light imply DCC-estate coverage.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["0.7"],
      "dependencyRationales": ["Requires fresh observed host and runtime availability."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "host-capability-observation",
        "privacy-data-rights",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-5-9",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "host-capability-observation",
          "privacy-data-rights",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": ["docs/audits/BELLONA_DCC_HOST_MATRIX_2026-09.md"],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-9.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Recheck local UE at the mandated path before every availability claim. For Unreal/Unity/Houdini/Maya/etc., maintain a host/runtime/licence matrix, per-adapter audit, and exact live unblock criteria; do not let Blender first light imply DCC-estate coverage. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.10",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver the governed Unreal execution path for the charter workflows that require it: host/version/licence preflight, audited real adapter, scoped leased execution, editable project import/create/edit, compile, cook/package, automated play, save/reopen, cancellation, rollback, and independent semantic/visual/performance verification. Run diverse real V2–V8 tasks and the engine-backed V9/V10 producers where required. Missing hardware, editor, permissions, or human quality evidence keeps this task open; a host matrix or Blender result cannot close it. Security, Evaluation, Reliability, and Privacy gates precede live admission. Implementation is split between tasks 5.12–5.14; this parent requires both the admitted adapter and the real workflow/quality evidence.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["0.8", "4.8", "5.12", "5.13", "5.14", "5.33", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Uses the real governed Unreal adapter and editor state.",
        "Requires packaged/playable Unreal workflows, recovery and independent quality evidence.",
        "Requires complete tool-schema delivery proven on the admitted Unreal profile, which settles the optional native backend chain (5.30 to 5.32) by adoption or measured rejection.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-agent-runtime",
        "real-engine-runtime",
        "host-capability-observation",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-10",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-agent-runtime",
          "real-engine-runtime",
          "host-capability-observation",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-10.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver the governed Unreal execution path for the charter workflows that require it: host/version/licence preflight, audited real adapter, scoped leased execution, editable project import/create/edit, compile, cook/package, automated play, save/reopen, cancellation, rollback, and independent semantic/visual/performance verification. Run diverse real V2–V8 tasks and the engine-backed V9/V10 producers where required. Missing hardware, editor, permissions, or human quality evidence keeps this task open; a host matrix or Blender result cannot close it. Security, Evaluation, Reliability, and Privacy gates precede live admission. Implementation is split between tasks 5.12–5.14; this parent requires both the admitted adapter and the real workflow/quality evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.11",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver every other runtime/toolchain required by the ratified charter inventory through the same discovery→audit→adapter→governed execution→artifact readback→breadth/failure→operator acceptance milestones. Include the internal Maya engine/UGC sandbox, required native/VR targets, content/voice/media and formal/scientific toolchains at their real boundaries. Distinguish the Maya engine domain from Autodesk Maya DCC. Unity/Houdini/Autodesk Maya/other adapters are required only when a source requirement needs them; an alternative must preserve and prove that outcome. Every required runtime has task ownership and live evidence; absent runtimes and transferred work remain blockers, never zero-work completion verdicts. Tasks 5.12 and 5.15–5.19 own the bounded packages below. Every additional required runtime discovered by 0.8 must receive a separate implementation task and direct prerequisite edge before this parent can close.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["0.8", "5.8", "5.10", "5.12", "5.15", "5.16", "5.17", "5.18", "5.19"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Requires observed Blender failure and false-success controls.",
        "Requires complete Unreal delivery evidence for required engine workflows.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Requires internal Maya/UGC sandbox delivery and hostile-content containment.",
        "Requires separate real solver and numerical-engine acceptance receipts.",
        "Requires real voice/media and companion-simulation package evidence.",
        "Requires actual declared platform/device packaging and user-journey proof.",
        "Requires all additionally selected creative-application child tasks to close."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-model-provider",
        "native-desktop-runtime",
        "mobile-runtime",
        "real-dcc-runtime",
        "real-engine-runtime",
        "real-multimodal-runtime",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-11",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-model-provider",
          "native-desktop-runtime",
          "mobile-runtime",
          "real-dcc-runtime",
          "real-engine-runtime",
          "real-multimodal-runtime",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-11.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver every other runtime/toolchain required by the ratified charter inventory through the same discovery→audit→adapter→governed execution→artifact readback→breadth/failure→operator acceptance milestones. Include the internal Maya engine/UGC sandbox, required native/VR targets, content/voice/media and formal/scientific toolchains at their real boundaries. Distinguish the Maya engine domain from Autodesk Maya DCC. Unity/Houdini/Autodesk Maya/other adapters are required only when a source requirement needs them; an alternative must preserve and prove that outcome. Every required runtime has task ownership and live evidence; absent runtimes and transferred work remain blockers, never zero-work completion verdicts. Tasks 5.12 and 5.15–5.19 own the bounded packages below. Every additional required runtime discovered by 0.8 must receive a separate implementation task and direct prerequisite edge before this parent can close. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.12",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Ratify runtime work packages from 0.8 and the fresh 5.9 host matrix. Owner: Agentic AI PM; verifier: QA Lead with each domain owner. For each required runtime/version/platform, name the source requirement, executable service/adapter, implementation task, owner, six milestone receipts, semantic acceptance oracle, licence/host decision, and exact unblock action. Split Unity, Houdini, Autodesk Maya, Adobe applications, or other newly required adapters into separate tasks before implementation; retain source-justified alternatives without erasing the required outcome. A missing package or owner blocks 5.10/5.11; this inventory is not runtime delivery.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["0.8", "5.9"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Uses the fresh host/runtime/licence matrix."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "host-capability-observation",
        "governance-decision",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-5-12",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "host-capability-observation",
          "governance-decision",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "live-runtime",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-12.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Ratify runtime work packages from 0.8 and the fresh 5.9 host matrix. Owner: Agentic AI PM; verifier: QA Lead with each domain owner. For each required runtime/version/platform, name the source requirement, executable service/adapter, implementation task, owner, six milestone receipts, semantic acceptance oracle, licence/host decision, and exact unblock action. Split Unity, Houdini, Autodesk Maya, Adobe applications, or other newly required adapters into separate tasks before implementation; retain source-justified alternatives without erasing the required outcome. A missing package or owner blocks 5.10/5.11; this inventory is not runtime delivery. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.13",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Implement the governed Unreal adapter. Owner: Engine Lead; verifier: Security Lead. Bind the 5.12 runtime/version contract to a real editor command/API, registry model legs, actor/task/lease/fence, project roots, dry-run/confirmation, cancellation and process cleanup. Test actual editor handshake, read/create/edit/save, stale lease, hostile project, duplicate request, permission denial, timeout and killed editor after the live admission gates. Retain sanitized command and editor receipts; simulated responses and process exit alone cannot prove editable project state.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.8", "5.12", "12.7", "13.7", "14.7", "15.1"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance.",
        "Consumes priced, capability-correct, fail-loud model registry bindings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-engine-runtime",
        "fault-recovery",
        "security-adversarial",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-13",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-engine-runtime",
          "fault-recovery",
          "security-adversarial",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-13.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Implement the governed Unreal adapter. Owner: Engine Lead; verifier: Security Lead. Bind the 5.12 runtime/version contract to a real editor command/API, registry model legs, actor/task/lease/fence, project roots, dry-run/confirmation, cancellation and process cleanup. Test actual editor handshake, read/create/edit/save, stale lease, hostile project, duplicate request, permission denial, timeout and killed editor after the live admission gates. Retain sanitized command and editor receipts; simulated responses and process exit alone cannot prove editable project state. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.14",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver Unreal workflow and recovery evidence. Owner: Engine Lead; verifier: QA Lead plus the product operator for quality. Using 5.13, create and modify source projects, compile, cook/package, run automated play, reopen/save, and restore after crash/cancel/partial export. Exercise the ratified V2–V8 ruleset cells and required V9/V10 producers with independent semantic, visual, performance and accessibility acceptance. Retain editable source, engine readback, packaged behavior, human quality labels and failure receipts per declared platform; missing hosts or labels keep the package open.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.13", "5.34", "5.35"],
      "dependencyRationales": [
        "Uses the real governed Unreal adapter and editor state.",
        "Retains the target-resolution failure and persisted-state receipts inside this battery for each admitted backend.",
        "Records the project authoring-convention results inside this battery rather than in another release gate."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-engine-runtime",
        "fault-recovery",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-14",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-engine-runtime",
          "fault-recovery",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-14.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver Unreal workflow and recovery evidence. Owner: Engine Lead; verifier: QA Lead plus the product operator for quality. Using 5.13, create and modify source projects, compile, cook/package, run automated play, reopen/save, and restore after crash/cancel/partial export. Exercise the ratified V2–V8 ruleset cells and required V9/V10 producers with independent semantic, visual, performance and accessibility acceptance. Retain editable source, engine readback, packaged behavior, human quality labels and failure receipts per declared platform; missing hosts or labels keep the package open. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.15",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver the internal Maya engine and UGC sandbox path. Owner: Mawu Engine Lead; verifier: Security Lead and QA Lead. Bind the real V7 script/package/realm contracts, validate and publish authorized test content, upgrade and roll back a realm, and verify authoritative state after reload/reconnect. Prove hostile script and dependency containment, permissions, rights, deterministic package compatibility, resource ceilings and creator/player acceptance. Follow all six runtime milestones at each required target. Internal Maya is distinct from Autodesk Maya; one cannot prove the other.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.8", "5.12", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-engine-runtime",
        "fault-recovery",
        "security-adversarial",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-15",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-engine-runtime",
          "fault-recovery",
          "security-adversarial",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-15.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver the internal Maya engine and UGC sandbox path. Owner: Mawu Engine Lead; verifier: Security Lead and QA Lead. Bind the real V7 script/package/realm contracts, validate and publish authorized test content, upgrade and roll back a realm, and verify authoritative state after reload/reconnect. Prove hostile script and dependency containment, permissions, rights, deterministic package compatibility, resource ceilings and creator/player acceptance. Follow all six runtime milestones at each required target. Internal Maya is distinct from Autodesk Maya; one cannot prove the other. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.16",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver the formal and computed-content paths as distinct source-owned packages. Owner: Ariadne Lead for the V8 solver/case compiler and Metis Lead for V9 numerical engines; verifier: QA Lead plus domain human assessors. Maintain separate package IDs and receipts for each solver/engine. Execute actual unique/solvable mystery compilation and engine playthrough; execute actual scientific calculations and all seven lesson gates with source, numerical tolerance, dimensional and pedagogy checks. Adversarial inconsistent cases, unsupported claims, solver timeout, stale inputs and false solver success must fail. Split any newly required toolchain into its own task under 5.12; a generic parser or one family score cannot close another package.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.8", "5.12", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-engine-runtime",
        "fault-recovery",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-16",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-engine-runtime",
          "fault-recovery",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-16.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver the formal and computed-content paths as distinct source-owned packages. Owner: Ariadne Lead for the V8 solver/case compiler and Metis Lead for V9 numerical engines; verifier: QA Lead plus domain human assessors. Maintain separate package IDs and receipts for each solver/engine. Execute actual unique/solvable mystery compilation and engine playthrough; execute actual scientific calculations and all seven lesson gates with source, numerical tolerance, dimensional and pedagogy checks. Adversarial inconsistent cases, unsupported claims, solver timeout, stale inputs and false solver success must fail. Split any newly required toolchain into its own task under 5.12; a generic parser or one family score cannot close another package. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.17",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver source-owned voice, media and companion-simulation packages. Owner: Media Lead and Egbe Lead; verifier: QA Lead with independent human quality reviewers. Keep distinct producer/package IDs for speech, audio/video production and Ori simulation; use their real service/engine boundaries and all six milestones. Measure editability, source/provenance, consent, timing, temporal consistency, multi-session persona/state continuity, simulation replay, cancellation, provider loss, budget and human creative quality per applicable package. Reuse SMX governed improvement and Phase-17 modality evaluations; do not count a generated file or a model self-rating as full quality evidence.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.8", "5.12", "12.7", "13.7", "14.7", "17.4", "17.5"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance.",
        "Uses the owning domain real generation toolchain and editable artifacts.",
        "Requires separate modality quality, human and failure evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "real-engine-runtime",
        "real-multimodal-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-17",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "real-engine-runtime",
          "real-multimodal-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-17.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver source-owned voice, media and companion-simulation packages. Owner: Media Lead and Egbe Lead; verifier: QA Lead with independent human quality reviewers. Keep distinct producer/package IDs for speech, audio/video production and Ori simulation; use their real service/engine boundaries and all six milestones. Measure editability, source/provenance, consent, timing, temporal consistency, multi-session persona/state continuity, simulation replay, cancellation, provider loss, budget and human creative quality per applicable package. Reuse SMX governed improvement and Phase-17 modality evaluations; do not count a generated file or a model self-rating as full quality evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.18",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver required platform packaging and device acceptance. Owner: Client/Engine Leads; verifier: QA Lead and accessibility assessors. From 0.8, instantiate a package per declared desktop, mobile, console or VR target and V10 native Rail producer/consumer boundary. Run the actual build/install/launch, input/accessibility, offline/reconnect, memory/frame/streaming budget, lifecycle, upgrade and rollback journeys on the required device/runtime. Browser emulation cannot prove native or VR execution. Keep hardware, signing, distribution and human-use decisions explicit blockers until satisfied.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.8", "5.12", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "native-desktop-runtime",
        "mobile-runtime",
        "real-engine-runtime",
        "fault-recovery",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-18",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "native-desktop-runtime",
          "mobile-runtime",
          "real-engine-runtime",
          "fault-recovery",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-18.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver required platform packaging and device acceptance. Owner: Client/Engine Leads; verifier: QA Lead and accessibility assessors. From 0.8, instantiate a package per declared desktop, mobile, console or VR target and V10 native Rail producer/consumer boundary. Run the actual build/install/launch, input/accessibility, offline/reconnect, memory/frame/streaming budget, lifecycle, upgrade and rollback journeys on the required device/runtime. Browser emulation cannot prove native or VR execution. Keep hardware, signing, distribution and human-use decisions explicit blockers until satisfied. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.19",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Reconcile additional DCC/creative applications selected by 5.12, including Unity, Houdini, Autodesk Maya and individual Adobe applications only where sources require them. Owner: Creative Tools Lead; verifier: QA Lead. Each selected application must have its own ledger task and version/host/adapter/acceptance receipts covering all six milestones, editable source and export readback, real failure/recovery and human quality evidence. This coordination item closes only when every selected child does; an empty selection requires independent source- backed ratification, not an unavailable-licence verdict. Adding a required application updates the dependency policy and reopens this parent.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.12", "5.29"],
      "dependencyRationales": [
        "Consumes source-owned runtime packages with exact adapter, owner and acceptance boundaries.",
        "Requires the selected After Effects application delivery and breadth evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "governance-decision",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-19",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "governance-decision",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-19.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Reconcile additional DCC/creative applications selected by 5.12, including Unity, Houdini, Autodesk Maya and individual Adobe applications only where sources require them. Owner: Creative Tools Lead; verifier: QA Lead. Each selected application must have its own ledger task and version/host/adapter/acceptance receipts covering all six milestones, editable source and export readback, real failure/recovery and human quality evidence. This coordination item closes only when every selected child does; an empty selection requires independent source- backed ratification, not an unavailable-licence verdict. Adding a required application updates the dependency policy and reopens this parent. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.20",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Correct the Blender executable smoke's compressed-file assumption. Owner: Bellona Blender; verifier: DCC QA. Depends on 5.3. Reproduce the macOS Blender 5.0.1 failure recorded in the assessment, then validate both compressed and uncompressed saves by resetting/reopening in real Blender and checking named objects, transforms, dimensions, materials, and scene settings. Exercise GLB/OBJ export after both saves; compare reported and actual bytes and decoded content. Corrupt, truncated, wrong-format, and missing files must fail. Retain the observed red/green regression, fresh version/host receipt, and cleanup proof; weakening the header assertion without semantic readback cannot close this task.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.3"],
      "dependencyRationales": [
        "Corrects the observed compressed-save regression in the real executable smoke."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-dcc-runtime",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-20",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-dcc-runtime",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-20.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Correct the Blender executable smoke's compressed-file assumption. Owner: Bellona Blender; verifier: DCC QA. Depends on 5.3. Reproduce the macOS Blender 5.0.1 failure recorded in the assessment, then validate both compressed and uncompressed saves by resetting/reopening in real Blender and checking named objects, transforms, dimensions, materials, and scene settings. Exercise GLB/OBJ export after both saves; compare reported and actual bytes and decoded content. Corrupt, truncated, wrong-format, and missing files must fail. Retain the observed red/green regression, fresh version/host receipt, and cleanup proof; weakening the header assertion without semantic readback cannot close this task. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.21",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Provision and verify the actual creative execution hosts. Owner: Bellona platform; verifier: runtime QA. Depends on 5.9 and 5.12. Extend the current runtime packages with After Effects, Blender, Unreal, exporter/importer versions, fonts, plugins, render capabilities, project roots, storage, licence state, and native permissions where used. Probe real processes and authenticated transports, including the mandated UE path on each execution host; distinguish installed, reachable, admitted, and verified. Supply the required usable hosts and capabilities, expire stale receipts, and demonstrate unavailable/version-mismatch refusal. An inventory with an absent required runtime remains open.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.9", "5.12"],
      "dependencyRationales": [
        "Refreshes current host and runtime availability rather than borrowing another host receipt.",
        "Extends the source-owned runtime packages with usable creative application hosts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "real-dcc-runtime",
        "real-engine-runtime",
        "host-capability-observation",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-5-21",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "real-dcc-runtime",
          "real-engine-runtime",
          "host-capability-observation",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-21.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Provision and verify the actual creative execution hosts. Owner: Bellona platform; verifier: runtime QA. Depends on 5.9 and 5.12. Extend the current runtime packages with After Effects, Blender, Unreal, exporter/importer versions, fonts, plugins, render capabilities, project roots, storage, licence state, and native permissions where used. Probe real processes and authenticated transports, including the mandated UE path on each execution host; distinguish installed, reachable, admitted, and verified. Supply the required usable hosts and capabilities, expire stale receipts, and demonstrate unavailable/version-mismatch refusal. An inventory with an absent required runtime remains open. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.22",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Implement the live After Effects backend behind `photoshop-aftereffects-adapter.ts`. Owner: Bellona Adobe; verifier: platform security. Depends on 5.21, 4.5, 4.6, and 4.7. Pin the actual supported Adobe automation API/transport rather than assuming the advertised scripting language is available. Authenticate the local session, marshal work correctly, validate arguments/results, observe actual composition/layer state, and surface app/busy/modal/script errors. Exercise inspect and reversible property mutation against real AE plus absent/killed application, timeout, malformed response, and wrong-project negatives. In-memory conformance is supplementary, not live evidence.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["4.5", "4.6", "4.7", "5.21"],
      "dependencyRationales": [
        "Requires execution isolation before application mutation.",
        "Uses authenticated external-tool and transport trust.",
        "Requires deterministic preview, confirmation, and reversal controls.",
        "Uses the provisioned and version-pinned After Effects host."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-dcc-runtime",
        "fault-recovery",
        "security-adversarial",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-22",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-dcc-runtime",
          "fault-recovery",
          "security-adversarial",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-22.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Implement the live After Effects backend behind `photoshop-aftereffects-adapter.ts`. Owner: Bellona Adobe; verifier: platform security. Depends on 5.21, 4.5, 4.6, and 4.7. Pin the actual supported Adobe automation API/transport rather than assuming the advertised scripting language is available. Authenticate the local session, marshal work correctly, validate arguments/results, observe actual composition/layer state, and surface app/busy/modal/script errors. Exercise inspect and reversible property mutation against real AE plus absent/killed application, timeout, malformed response, and wrong-project negatives. In-memory conformance is supplementary, not live evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.23",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Deliver editable motion authoring through the AE backend. Owner: Bellona Adobe; verifier: motion-design QA. Depends on 5.22. Implement typed, bounded operations for composition creation, text/fonts, shape layers and Bezier paths, asset imports, parenting, masks, supported effects, keyframes, interpolation/easing, motion blur, and cameras. Define explicit supported/unsupported semantics and validate frame rate, duration, units, layer/property addressing, and effect/plugin versions. Read back authored values and render representative motion; verify edit isolation, undo or declared compensation, and rejection of invalid keyframes, missing fonts/effects, and unsupported operations.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.22"],
      "dependencyRationales": ["Builds motion authoring on a verified live AE backend."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-dcc-runtime",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-23",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-dcc-runtime",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-23.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver editable motion authoring through the AE backend. Owner: Bellona Adobe; verifier: motion-design QA. Depends on 5.22. Implement typed, bounded operations for composition creation, text/fonts, shape layers and Bezier paths, asset imports, parenting, masks, supported effects, keyframes, interpolation/easing, motion blur, and cameras. Define explicit supported/unsupported semantics and validate frame rate, duration, units, layer/property addressing, and effect/plugin versions. Read back authored values and render representative motion; verify edit isolation, undo or declared compensation, and rejection of invalid keyframes, missing fonts/effects, and unsupported operations. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.24",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Add AE project and render lifecycle operations. Owner: Bellona Adobe; verifier: artifact QA. Depends on 5.23 and 14.7. Save versioned `.aep` projects, collect/relink dependencies, reopen in a fresh application session, and render preview frames and video through the pinned real renderer. Verify source layers/keyframes survive reopen and rendered frame count, duration, dimensions, frame rate, alpha/audio where required, and file contents match the job. Return hashed artifacts and actionable progress/errors; handle missing media, failed renders, partial output, cancellation, and output collisions without reporting completion.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.23", "14.7"],
      "dependencyRationales": [
        "Uses actual editable AE composition and keyframe operations.",
        "Requires source-media rights and artifact governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-24",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-24.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Add AE project and render lifecycle operations. Owner: Bellona Adobe; verifier: artifact QA. Depends on 5.23 and 14.7. Save versioned `.aep` projects, collect/relink dependencies, reopen in a fresh application session, and render preview frames and video through the pinned real renderer. Verify source layers/keyframes survive reopen and rendered frame count, duration, dimensions, frame rate, alpha/audio where required, and file contents match the job. Return hashed artifacts and actionable progress/errors; handle missing media, failed renders, partial output, cancellation, and output collisions without reporting completion. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.25",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Bind AE jobs to Eve's existing leased Bellona execution path. Owner: Eve DCC; verifier: security and integration QA. Depends on 5.5, 5.24, 12.10, and 14.7. Connect production gateway discovery, host/backend construction, tool dispatch, and result collection to the same actor/task/lease/fence/confirmation/budget/trace contract. Prove one real create/edit/save/render job from an attributed Eve task, independently verify its output, and refuse missing authority, stale fences, expired confirmations, and incorrect project/host routing. Keep drawer tools within the existing ownership decision. Any native-input branch must additionally pass 6.6–6.8 on its declared OS before that branch is exposed.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.5", "5.24", "12.10", "14.7"],
      "dependencyRationales": [
        "Reuses attributed leased Bellona admission and its cross-phase gates.",
        "Requires real AE save, reopen, and render operations.",
        "Uses registered creative-family evidence and rejection rules.",
        "Requires actual media and project governance for live execution."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-model-provider",
        "real-dcc-runtime",
        "fault-recovery",
        "security-adversarial",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-25",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-model-provider",
          "real-dcc-runtime",
          "fault-recovery",
          "security-adversarial",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-25.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Bind AE jobs to Eve's existing leased Bellona execution path. Owner: Eve DCC; verifier: security and integration QA. Depends on 5.5, 5.24, 12.10, and 14.7. Connect production gateway discovery, host/backend construction, tool dispatch, and result collection to the same actor/task/lease/fence/confirmation/budget/trace contract. Prove one real create/edit/save/render job from an attributed Eve task, independently verify its output, and refuse missing authority, stale fences, expired confirmations, and incorrect project/host routing. Keep drawer tools within the existing ownership decision. Any native-input branch must additionally pass 6.6–6.8 on its declared OS before that branch is exposed. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.26",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Wire production providers for the existing cross-app creative flows. Owner: Bellona integration with Isis/Yemaya service owners; verifier: integration QA. Depends on 5.5, 5.13, 17.4, and 14.7. Replace unconfigured execution boundaries with real Isis asset, Blender, project-scoped file transfer, Unreal import/capture, artifact-store, and Yemaya review clients. Prove each composed route reaches the actual services and apps; retain hash/identity propagation, tenant checks, unavailable-provider refusal, and partial-result behavior. Remove stale stage-23 capability claims only after tracing their current bindings; preserve historical evidence and keep test providers out of production construction.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.5", "5.13", "14.7", "17.4"],
      "dependencyRationales": [
        "Requires governed leased Bellona execution.",
        "Uses the admitted real Unreal editor adapter and authenticated transport.",
        "Requires cross-domain source and artifact rights governance.",
        "Uses live generation through the owning domain."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-dcc-runtime",
        "real-engine-runtime",
        "real-multimodal-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-26",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-dcc-runtime",
          "real-engine-runtime",
          "real-multimodal-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-26.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Wire production providers for the existing cross-app creative flows. Owner: Bellona integration with Isis/Yemaya service owners; verifier: integration QA. Depends on 5.5, 5.13, 17.4, and 14.7. Replace unconfigured execution boundaries with real Isis asset, Blender, project-scoped file transfer, Unreal import/capture, artifact-store, and Yemaya review clients. Prove each composed route reaches the actual services and apps; retain hash/identity propagation, tenant checks, unavailable-provider refusal, and partial-result behavior. Remove stale stage-23 capability claims only after tracing their current bindings; preserve historical evidence and keep test providers out of production construction. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.27",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Prove semantic Blender-to-Unreal interchange. Owner: Bellona interchange; verifier: engine QA. Depends on 5.20, 5.26, and 5.14. Export, transfer, import, place, save, and reopen real multi-object scenes in UE; independently compare scale/units, coordinate axes, pivots/transforms, hierarchy, mesh geometry, material/texture assignments, cameras, and collision/navigation data required by the selected workflow. Resolve unsupported mappings explicitly. Test reimport, renamed/deleted objects, missing textures, duplicate delivery, corrupted transfer, and rollback; screenshots supplement measured scene readback rather than replace it.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.14", "5.20", "5.26"],
      "dependencyRationales": [
        "Uses verified Unreal workflow and recovery behavior.",
        "Uses corrected compressed and uncompressed Blender readback/export verification.",
        "Requires actual cross-app provider bindings and transfer."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-dcc-runtime",
        "real-engine-runtime",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-27",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-dcc-runtime",
          "real-engine-runtime",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-27.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Prove semantic Blender-to-Unreal interchange. Owner: Bellona interchange; verifier: engine QA. Depends on 5.20, 5.26, and 5.14. Export, transfer, import, place, save, and reopen real multi-object scenes in UE; independently compare scale/units, coordinate axes, pivots/transforms, hierarchy, mesh geometry, material/texture assignments, cameras, and collision/navigation data required by the selected workflow. Resolve unsupported mappings explicitly. Test reimport, renamed/deleted objects, missing textures, duplicate delivery, corrupted transfer, and rollback; screenshots supplement measured scene readback rather than replace it. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.28",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Implement durable creative-job recovery across application steps. Owner: Bellona runtime and Yemaya orchestration; verifier: reliability QA. Depends on 5.24, 5.26, and 13.3. Persist step intents, source/revision hashes, produced artifacts, application/project identity, and checkpoints so retry resumes from independently verified state. Exercise process loss, host disconnect, render timeout, restart, stale project edits, disk-full, cancellation, and duplicate dispatch. Retain progress and partial work, stop downstream writes after cancellation, and prove recovery or explicit compensation without overwriting newer operator work or paying for an already completed generation/render again.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.24", "5.26", "13.3"],
      "dependencyRationales": [
        "Uses the real native project and render lifecycle.",
        "Exercises failure across actual cross-application boundaries.",
        "Reuses canonical retry, deadline, idempotency, and cancellation semantics."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "real-dcc-runtime",
        "real-engine-runtime",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-28",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "real-dcc-runtime",
          "real-engine-runtime",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-28.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Implement durable creative-job recovery across application steps. Owner: Bellona runtime and Yemaya orchestration; verifier: reliability QA. Depends on 5.24, 5.26, and 13.3. Persist step intents, source/revision hashes, produced artifacts, application/project identity, and checkpoints so retry resumes from independently verified state. Exercise process loss, host disconnect, render timeout, restart, stale project edits, disk-full, cancellation, and duplicate dispatch. Retain progress and partial work, stop downstream writes after cancellation, and prove recovery or explicit compensation without overwriting newer operator work or paying for an already completed generation/render again. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.29",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Run the AE application breadth and failure battery. Owner: DCC QA; verifier: independent security/evaluation reviewer. Depends on 5.25, 5.28, and 12.9. Cover real inspect/create/edit/undo/save/reopen/import/ render/cancel/resume across the declared host/version matrix. Observe malicious reference/project/layer names, expressions/scripts, external paths, ungranted network/file access, modal interruptions, app crashes, and stale state fail safely while paired benign jobs still finish. Measure verified output and intervention rate; generic desktop fixtures, browser tests, or backend doubles cannot stand in for this AE evidence.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.25", "5.28", "12.9"],
      "dependencyRationales": [
        "Exercises real attributed Eve-to-AE execution.",
        "Requires durable application failure and recovery behavior.",
        "Uses preregistered creative measurement and failure criteria."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "authorization-isolation",
        "real-dcc-runtime",
        "fault-recovery",
        "security-adversarial",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-29",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "authorization-isolation",
          "real-dcc-runtime",
          "fault-recovery",
          "security-adversarial",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-29.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Run the AE application breadth and failure battery. Owner: DCC QA; verifier: independent security/evaluation reviewer. Depends on 5.25, 5.28, and 12.9. Cover real inspect/create/edit/undo/save/reopen/import/ render/cancel/resume across the declared host/version matrix. Observe malicious reference/project/layer names, expressions/scripts, external paths, ungranted network/file access, modal interruptions, app crashes, and stale state fail safely while paired benign jobs still finish. Measure verified output and intervention rate; generic desktop fixtures, browser tests, or backend doubles cannot stand in for this AE evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.30",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Qualify an optional native Unreal MCP backend against the existing Bellona route. Owner: Engine Lead; verifier: engine QA. Source and evidence limits: docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md. Extend existing version discovery and 5.12/5.21 host records with exact engine/plugin/client versions, project identity, enabled capabilities, and endpoint ownership. Preserve current project pins. Produce an isolated setup/diagnostic harness that distinguishes configured, reachable, initialized, and operation-verified states. Exercise missing plugins/toolsets, occupied ports, wrong working directory/project, existing client configuration, unsupported engine, and editor restart without overwriting unrelated configuration. On the qualified host, retain sanitized handshake, capability, and harmless readback receipts; distinguish editor tooling from packaged-runtime capability. Compare at least one required workflow with the current backend using the existing 5.14/T.21 rubric and record adopt/reject rationale and measured limitations. Fixture success cannot prove a live editor. Existing admission gates precede live exposure; provisioning stays with 5.21. Missing host evidence keeps qualification open; a measured rejection must preserve a verified alternative for the required outcome.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.13", "5.21"],
      "dependencyRationales": [
        "Compares a required workflow against the current governed Bellona backend.",
        "Extends the provisioned, version-pinned host records; provisioning stays with 5.21."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-engine-runtime",
        "protocol-interop",
        "host-capability-observation",
        "governance-decision",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-30",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-engine-runtime",
          "protocol-interop",
          "host-capability-observation",
          "governance-decision",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-30.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Qualify an optional native Unreal MCP backend against the existing Bellona route. Owner: Engine Lead; verifier: engine QA. Source and evidence limits: docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md. Extend existing version discovery and 5.12/5.21 host records with exact engine/plugin/client versions, project identity, enabled capabilities, and endpoint ownership. Preserve current project pins. Produce an isolated setup/diagnostic harness that distinguishes configured, reachable, initialized, and operation-verified states. Exercise missing plugins/toolsets, occupied ports, wrong working directory/project, existing client configuration, unsupported engine, and editor restart without overwriting unrelated configuration. On the qualified host, retain sanitized handshake, capability, and harmless readback receipts; distinguish editor tooling from packaged-runtime capability. Compare at least one required workflow with the current backend using the existing 5.14/T.21 rubric and record adopt/reject rationale and measured limitations. Fixture success cannot prove a live editor. Existing admission gates precede live exposure; provisioning stays with 5.21. Missing host evidence keeps qualification open; a measured rejection must preserve a verified alternative for the required outcome. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.31",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Add the native Unreal MCP transport with governed dispatch and per-editor serialization. Owner: Bellona runtime; verifier: reliability and security QA. Depends on 5.30. Source: docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md. Extend DccCommandTransport and the remote-host boundary, reusing the existing MCP SDK client and 5.13 authority contract. Retain Bellona's current backend and expose the candidate only for qualified profiles. Reach the editor locally behind the governed host; reject nonlocal endpoints, redirects, and incorrect project/process identity before dispatch. Serialize all tool invocations, including reads, per editor process across callers. Recheck lease/fence and cancellation when dequeuing; do not confuse client timeout with editor cancellation or replay an unsettled write. After process replacement, fence old work and revalidate identity and state. Test JSON/event-stream responses, progress, protocol/tool errors, disconnects, queued cancellation, delayed completion, and duplicate mutations with an instrumented peer and actual pinned-editor receipts. Prove at most one in-flight invocation and no writes after revoked authority. Declare operation-specific compensation instead of assuming undo support. Production admission remains subject to 5.5, 5.13 and the cross-phase gates.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.5", "5.13", "5.30"],
      "dependencyRationales": [
        "Production admission stays behind the attributed leased Bellona registration.",
        "Reuses the governed adapter authority contract and its live-admission gates.",
        "Exposes the native transport only for profiles the qualification admitted."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-engine-runtime",
        "protocol-interop",
        "fault-recovery",
        "security-adversarial",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-31",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-engine-runtime",
          "protocol-interop",
          "fault-recovery",
          "security-adversarial",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-31.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Add the native Unreal MCP transport with governed dispatch and per-editor serialization. Owner: Bellona runtime; verifier: reliability and security QA. Depends on 5.30. Source: docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md. Extend DccCommandTransport and the remote-host boundary, reusing the existing MCP SDK client and 5.13 authority contract. Retain Bellona's current backend and expose the candidate only for qualified profiles. Reach the editor locally behind the governed host; reject nonlocal endpoints, redirects, and incorrect project/process identity before dispatch. Serialize all tool invocations, including reads, per editor process across callers. Recheck lease/fence and cancellation when dequeuing; do not confuse client timeout with editor cancellation or replay an unsettled write. After process replacement, fence old work and revalidate identity and state. Test JSON/event-stream responses, progress, protocol/tool errors, disconnects, queued cancellation, delayed completion, and duplicate mutations with an instrumented peer and actual pinned-editor receipts. Prove at most one in-flight invocation and no writes after revoked authority. Declare operation-specific compensation instead of assuming undo support. Production admission remains subject to 5.5, 5.13 and the cross-phase gates. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.32",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Resolve Unreal lazy tool discovery to explicitly authorized operations. Owner: Eve tool registry and Bellona; verifier: security/evaluation QA. Depends on 5.31. Source: docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md. Integrate the native discovery profile with existing tool registry/cache and trust controls. Bind the resolved toolset, operation, validated arguments, schema digest, project/process, actor, task and fence into each authorization and audit receipt. Permission to invoke a discovery dispatcher must never authorize arbitrary nested writes or script execution. Reauthorize at execution and reject unknown or changed targets. Bound discovery/context cost; support explicitly qualified eager profiles without assuming all servers share that shape. Invalidate affected schemas and approvals after tool refresh, reconnect or restart; absent optional capabilities must not become invented functionality. Add negative controls for an allowed outer dispatcher with a denied inner operation, forged read-only classification, hostile descriptions/asset metadata, changed schemas, wrong-project cache reuse and unapproved Python/console targets, paired with successful permitted edits. Verify denied calls never reach the transport and measure discovery tokens and verified task success using 5.14/T.21 fixtures. Preserve generic discovery task 97.3.3.3.a and all existing live admission gates.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.31"],
      "dependencyRationales": [
        "Authorizes operations dispatched over the serialized native transport."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-engine-runtime",
        "security-adversarial",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-32",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-engine-runtime",
          "security-adversarial",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-32.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Resolve Unreal lazy tool discovery to explicitly authorized operations. Owner: Eve tool registry and Bellona; verifier: security/evaluation QA. Depends on 5.31. Source: docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md. Integrate the native discovery profile with existing tool registry/cache and trust controls. Bind the resolved toolset, operation, validated arguments, schema digest, project/process, actor, task and fence into each authorization and audit receipt. Permission to invoke a discovery dispatcher must never authorize arbitrary nested writes or script execution. Reauthorize at execution and reject unknown or changed targets. Bound discovery/context cost; support explicitly qualified eager profiles without assuming all servers share that shape. Invalidate affected schemas and approvals after tool refresh, reconnect or restart; absent optional capabilities must not become invented functionality. Add negative controls for an allowed outer dispatcher with a denied inner operation, forged read-only classification, hostile descriptions/asset metadata, changed schemas, wrong-project cache reuse and unapproved Python/console targets, paired with successful permitted edits. Verify denied calls never reach the transport and measure discovery tokens and verified task success using 5.14/T.21 fixtures. Preserve generic discovery task 97.3.3.3.a and all existing live admission gates. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.33",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Detect and recover incomplete MCP schema delivery across harness and model limits. Owner: Eve tool registry and model-runtime leads; verifier: evaluation QA. Source: `docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md`, supplied transcript 44:53-50:40. Extend the existing registry, 15.3 loss handling and T.21 benchmark; do not duplicate them. Measure declared units, raw and delivered schema sizes, token estimates, harness output caps and effective context headroom for each pinned engine/toolset/harness/model tuple. Initial lazy discovery is insufficient if one description exceeds a downstream limit. Retrieve complete bounded operation schemas with their constraints and identity; detect truncated, summarized, malformed or unverifiably complete descriptions before dependent execution. Preserve permission/schema bindings, emit an actionable diagnosis, and bound re-query, retries, time and spend instead of guessing missing APIs. Test a required argument/constraint near the tail, silent harness clipping, context pressure, repeated failed discovery and paired intact-schema success. Compare verified material and Niagara outcomes, intervention, latency and total cost using measured sizes, not the talk's ambiguous quantities or anecdotal one-minute timing. Generic fixture/harness work can start now; native integration uses 5.32 and must pass its real profile and existing admission gates before rollout.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.32", "15.3"],
      "dependencyRationales": [
        "Native integration and rollout use the authorized discovery profile; generic fixture work may start before it.",
        "Extends the long-context instruction and schema loss handling rather than duplicating it."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "real-engine-runtime",
        "fault-recovery",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-33",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "real-engine-runtime",
          "fault-recovery",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-33.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Detect and recover incomplete MCP schema delivery across harness and model limits. Owner: Eve tool registry and model-runtime leads; verifier: evaluation QA. Source: `docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md`, supplied transcript 44:53-50:40. Extend the existing registry, 15.3 loss handling and T.21 benchmark; do not duplicate them. Measure declared units, raw and delivered schema sizes, token estimates, harness output caps and effective context headroom for each pinned engine/toolset/harness/model tuple. Initial lazy discovery is insufficient if one description exceeds a downstream limit. Retrieve complete bounded operation schemas with their constraints and identity; detect truncated, summarized, malformed or unverifiably complete descriptions before dependent execution. Preserve permission/schema bindings, emit an actionable diagnosis, and bound re-query, retries, time and spend instead of guessing missing APIs. Test a required argument/constraint near the tail, silent harness clipping, context pressure, repeated failed discovery and paired intact-schema success. Compare verified material and Niagara outcomes, intervention, latency and total cost using measured sizes, not the talk's ambiguous quantities or anecdotal one-minute timing. Generic fixture/harness work can start now; native integration uses 5.32 and must pass its real profile and existing admission gates before rollout. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.34",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Resolve Unreal edit targets across Blueprint assets, editor instances and play worlds. Owner: Bellona Unreal; verifier: engine and integration QA. Depends on 5.13. Source: `docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md`, supplied transcript 20:19-28:16 and 52:06-53:03. Extend existing actor, asset and planning contracts with stable target identity, editing scope, project/map/world session, revision and intended runtime-spawn source. Resolve selection, component/attachment target and transform space before editing; use existing clarification/confirmation rules for ambiguous intent. A request about the spawned player must not silently mutate a placed copy or create a substitute actor. Bind batch previews to exact asset IDs/revisions and predicate/operation semantics; revalidate the selected set before dispatch and refuse stale or broadened targets. Test duplicate labels, wrong map, missing runtime actor, asset-versus-instance confusion, play-session restart and selection/list changes after preview. Reproduce the character attachment and misplaced-light corrections; independently inspect intended and untouched targets, save/reopen, spawn a fresh player and verify attachment/transform behavior. Retain failure and persisted-state receipts through the existing 5.14 battery for each admitted backend.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.13"],
      "dependencyRationales": [
        "Extends the governed adapter actor, asset and planning contracts with target identity."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "persistence-recovery",
        "real-engine-runtime",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-34",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "persistence-recovery",
          "real-engine-runtime",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-34.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Resolve Unreal edit targets across Blueprint assets, editor instances and play worlds. Owner: Bellona Unreal; verifier: engine and integration QA. Depends on 5.13. Source: `docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md`, supplied transcript 20:19-28:16 and 52:06-53:03. Extend existing actor, asset and planning contracts with stable target identity, editing scope, project/map/world session, revision and intended runtime-spawn source. Resolve selection, component/attachment target and transform space before editing; use existing clarification/confirmation rules for ambiguous intent. A request about the spawned player must not silently mutate a placed copy or create a substitute actor. Bind batch previews to exact asset IDs/revisions and predicate/operation semantics; revalidate the selected set before dispatch and refuse stale or broadened targets. Test duplicate labels, wrong map, missing runtime actor, asset-versus-instance confusion, play-session restart and selection/list changes after preview. Reproduce the character attachment and misplaced-light corrections; independently inspect intended and untouched targets, save/reopen, spawn a fresh player and verify attachment/transform behavior. Retain failure and persisted-state receipts through the existing 5.14 battery for each admitted backend. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "5.35",
      "phaseId": "5",
      "closureState": "open",
      "requirement": "Enforce project-specific Unreal authoring conventions in agent plans and build validation. Owner: Bellona Unreal and project engine owners; verifier: engine quality QA. Depends on 5.13. Source: `docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md`, supplied transcript 39:00-40:54, 53:40-54:38 and 56:32-57:51. Version each project's asset naming/placement, material representation, Blueprint/C++ split and timing/performance rules; carry the policy identity into plans and result evidence. Prefer existing material-expression authoring and asset/build validators. Inspect real generated graph/code structure before accepting work: detect an unapproved HLSL substitution for requested native nodes, project-prohibited Tick use, or a delay chain that violates the declared timing design. Support scoped, explained exceptions and legitimate custom shaders, Tick and latent actions; never impose the speaker's personal C++ architecture or universal bans. Test violations and permitted counterparts, changed policies, undeclared exceptions and graph changes hidden behind a successful tool response. Require compilation and semantic readback after save/reopen, plus relevant target-platform shader/timing/performance checks. Prove the same policy applies to the existing and any admitted native backend and record results within 5.14 rather than creating another release gate.",
      "gapRefs": ["G5", "G14", "G15"],
      "dependencyTaskIds": ["5.13"],
      "dependencyRationales": [
        "Carries the project policy identity through the governed adapter plans and result evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-engine-runtime",
        "performance-quality",
        "governance-decision",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-5-35",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-engine-runtime",
          "performance-quality",
          "governance-decision",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-05/task-5-35.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Enforce project-specific Unreal authoring conventions in agent plans and build validation. Owner: Bellona Unreal and project engine owners; verifier: engine quality QA. Depends on 5.13. Source: `docs/audits/UNREAL_MCP_TALK_GAP_REVIEW_2026-09-19.md`, supplied transcript 39:00-40:54, 53:40-54:38 and 56:32-57:51. Version each project's asset naming/placement, material representation, Blueprint/C++ split and timing/performance rules; carry the policy identity into plans and result evidence. Prefer existing material-expression authoring and asset/build validators. Inspect real generated graph/code structure before accepting work: detect an unapproved HLSL substitution for requested native nodes, project-prohibited Tick use, or a delay chain that violates the declared timing design. Support scoped, explained exceptions and legitimate custom shaders, Tick and latent actions; never impose the speaker's personal C++ architecture or universal bans. Test violations and permitted counterparts, changed policies, undeclared exceptions and graph changes hidden behind a successful tool response. Require compilation and semantic readback after save/reopen, plus relevant target-platform shader/timing/performance checks. Prove the same policy applies to the existing and any admitted native backend and record results within 5.14 rather than creating another release gate. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.1",
      "phaseId": "6",
      "closureState": "completed",
      "requirement": "ADR: one owner for browser driving (reuse the real Playwright tools) and a sharply defined value for computer-use-core (native desktop only, unless a measured exception wins). Reject duplicate browser machines by default.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-6-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/adr/ADR-0077-eve-browser-and-native-computer-use-ownership.md",
          "docs/audits/eve-sota-computer-use-ownership/2026-09-08.json",
          "docs/audits/eve-sota-computer-use-ownership.schema.json",
          "docs/audits/eve-sota-evidence/phase-06/task-6-1.json",
          "tools/eve-everywhere/generate-computer-use-ownership.mjs",
          "tools/eve-everywhere/verify-computer-use-ownership.mjs",
          "tools/eve-everywhere/verify-computer-use-ownership.test.mjs",
          "tools/eve-everywhere/run-computer-use-ownership-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "ADR: one owner for browser driving (reuse the real Playwright tools) and a sharply defined value for computer-use-core (native desktop only, unless a measured exception wins). Reject duplicate browser machines by default. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.2",
      "phaseId": "6",
      "closureState": "completed",
      "requirement": "Rebind `psyche/computer-use-core` from direct Anthropic use to the registry/provider interfaces for planning and vision. Record screenshot format/size/redaction and fail loud when the required modality is unbound.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["6.1"],
      "dependencyRationales": ["Uses the native-versus-browser ownership decision."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-6-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/eve-sota-computer-use-provider/2026-09-08.json",
          "docs/audits/eve-sota-computer-use-provider/2026-09-08.live.json",
          "docs/audits/eve-sota-computer-use-provider/2026-09-08.qwen-zdr-negative.json",
          "docs/audits/eve-sota-computer-use-provider.schema.json",
          "docs/audits/eve-sota-computer-use-provider-live.schema.json",
          "docs/audits/eve-sota-computer-use-provider-rejection.schema.json",
          "docs/audits/eve-sota-evidence/phase-06/task-6-2.json",
          "libs/psyche/computer-use-core/src/agent.ts",
          "libs/psyche/computer-use-core/src/model-binding.ts",
          "libs/psyche/computer-use-core/src/screenshot-governance.ts",
          "apps/oshun/bff/src/assistant/computer-use-model-registry.ts",
          "tools/eve-everywhere/generate-computer-use-provider-contract.mjs",
          "tools/eve-everywhere/verify-computer-use-provider-contract.mjs",
          "tools/eve-everywhere/verify-computer-use-provider-contract.test.mjs",
          "tools/eve-everywhere/probe-computer-use-provider.ts",
          "tools/eve-everywhere/run-computer-use-provider-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Rebind `psyche/computer-use-core` from direct Anthropic use to the registry/provider interfaces for planning and vision. Record screenshot format/size/redaction and fail loud when the required modality is unbound. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.3",
      "phaseId": "6",
      "closureState": "completed",
      "requirement": "Two-pass fabrication/security audit of `computer-use-core`, `browser-automation`, action executors, screenshot/vision path, and all simulated-vs-real factories. Remove production-path simulation or make it an explicit test-only dependency.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["6.1", "6.2"],
      "dependencyRationales": [
        "Uses the native-versus-browser ownership decision.",
        "Requires the shared planning/vision registry and governed screenshot-input contract."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-6-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "security-exercise"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0078-eve-computer-use-fabrication-boundary.md",
          "docs/audits/eve-sota-computer-use-fabrication/2026-09-08.json",
          "docs/audits/eve-sota-computer-use-fabrication.schema.json",
          "docs/audits/eve-sota-evidence/phase-06/task-6-3.json",
          "libs/psyche/computer-use-core/src/action-executor.ts",
          "libs/psyche/computer-use-core/src/screenshot.ts",
          "libs/psyche/computer-use-core/src/testing.ts",
          "libs/iris/agents/computer-use/src/action-executor.ts",
          "libs/iris/agents/computer-use/src/screen-capture.ts",
          "libs/iris/agents/computer-use/src/fabrication-boundary.spec.ts",
          "libs/iris/agents/computer-use/vision/src/screen-analyzer.ts",
          "libs/iris/agents/computer-use/vision/src/change-detector.ts",
          "tools/eve-everywhere/generate-computer-use-fabrication-audit.mjs",
          "tools/eve-everywhere/verify-computer-use-fabrication-audit.mjs",
          "tools/eve-everywhere/verify-computer-use-fabrication-audit.test.mjs",
          "tools/eve-everywhere/run-computer-use-fabrication-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Two-pass fabrication/security audit of `computer-use-core`, `browser-automation`, action executors, screenshot/vision path, and all simulated-vs-real factories. Remove production-path simulation or make it an explicit test-only dependency. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.4",
      "phaseId": "6",
      "closureState": "completed",
      "requirement": "Build a native desktop fixture/harness separate from Playwright: known app/window, controlled files and clipboard, deterministic success state, Accessibility permission preflight, multi-display/DPI and occlusion handling, screenshot redaction/retention, and cleanup.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["0.7", "6.1"],
      "dependencyRationales": [
        "Requires fresh observed host and runtime availability.",
        "Uses the native-versus-browser ownership decision."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "native-desktop-runtime",
        "host-capability-observation",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-6-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "native-desktop-runtime",
          "host-capability-observation",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0079-eve-native-desktop-fixture-boundary.md",
          "docs/audits/eve-sota-native-desktop/2026-09-08.json",
          "docs/audits/eve-sota-native-desktop.schema.json",
          "docs/audits/eve-sota-evidence/phase-06/task-6-4.json",
          "tools/eve-everywhere/native-desktop-harness.mjs",
          "tools/eve-everywhere/native-desktop-harness.test.mjs",
          "tools/eve-everywhere/run-native-desktop-fixture.mjs",
          "tools/eve-everywhere/verify-native-desktop-fixture.mjs",
          "tools/eve-everywhere/verify-native-desktop-fixture.test.mjs",
          "tools/eve-everywhere/run-native-desktop-fixture-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build a native desktop fixture/harness separate from Playwright: known app/window, controlled files and clipboard, deterministic success state, Accessibility permission preflight, multi-display/DPI and occlusion handling, screenshot redaction/retention, and cleanup. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.5",
      "phaseId": "6",
      "closureState": "completed",
      "requirement": "Enforce per-run app/window/action/network/file allowlists, preview and confirmation by risk, stale-frame detection, rate/step/time/token budgets, interrupt latency, safe focus handling, and independently verified end state. Drawer exposure remains none.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["6.3", "6.4"],
      "dependencyRationales": [
        "Requires the actual native execution chain to pass fabrication/security review.",
        "Uses a real OS-level desktop fixture and permission preflight."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "authorization-isolation",
        "native-desktop-runtime",
        "fault-recovery",
        "security-adversarial",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-6-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "authorization-isolation",
          "native-desktop-runtime",
          "fault-recovery",
          "security-adversarial",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0080-eve-native-desktop-execution-controls.md",
          "docs/audits/eve-sota-native-desktop-controls/2026-09-09.json",
          "docs/audits/eve-sota-native-desktop-controls.schema.json",
          "docs/audits/eve-sota-evidence/phase-06/task-6-5.json",
          "libs/psyche/computer-use-core/src/execution-controls.ts",
          "libs/psyche/computer-use-core/src/execution-controls.spec.ts",
          "docs/systems/lib-psyche.md",
          "tools/eve-everywhere/native-desktop-controls-harness.mjs",
          "tools/eve-everywhere/run-native-desktop-controls-fixture.mjs",
          "tools/eve-everywhere/verify-native-desktop-controls.mjs",
          "tools/eve-everywhere/verify-native-desktop-controls.test.mjs",
          "tools/eve-everywhere/run-native-desktop-controls-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Enforce per-run app/window/action/network/file allowlists, preview and confirmation by risk, stale-frame detection, rate/step/time/token budgets, interrupt latency, safe focus handling, and independently verified end state. Drawer exposure remains none. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.6",
      "phaseId": "6",
      "closureState": "open",
      "requirement": "After the gates, admit native computer use only for leased work. A Playwright run may verify browser composition but cannot substitute for the native fixture's OS-level proof.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["4.8", "6.2", "6.3", "6.4", "6.5", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Requires native planning/vision registry bindings.",
        "Requires the actual native execution chain to pass fabrication/security review.",
        "Uses a real OS-level desktop fixture and permission preflight.",
        "Requires per-run authority, focus, budget and interrupt enforcement.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-model-provider",
        "native-desktop-runtime"
      ],
      "evidencePlan": {
        "id": "evidence-6-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-model-provider",
          "native-desktop-runtime"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "After the gates, admit native computer use only for leased work. A Playwright run may verify browser composition but cannot substitute for the native fixture's OS-level proof. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.7",
      "phaseId": "6",
      "closureState": "open",
      "requirement": "Benchmark diverse bounded tasks and failure modes: read-only inspect, text/form entry, file open/save, menu/dialog, scrolling, retry after stale frame, cancel mid-task, app crash/restart, ambiguous target, permission denial, and safe abstention. Report completion, intervention, steps, latency, cost, and unsafe-action rate.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["6.6"],
      "dependencyRationales": ["Requires governed native leased-work admission."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-model-provider",
        "native-desktop-runtime",
        "fault-recovery",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-6-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-model-provider",
          "native-desktop-runtime",
          "fault-recovery",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Benchmark diverse bounded tasks and failure modes: read-only inspect, text/form entry, file open/save, menu/dialog, scrolling, retry after stale frame, cancel mid-task, app crash/restart, ambiguous target, permission denial, and safe abstention. Report completion, intervention, steps, latency, cost, and unsafe-action rate. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "6.8",
      "phaseId": "6",
      "closureState": "open",
      "requirement": "Injection negatives include visible text, OCR, image-embedded text, window title, clipboard, notification, downloaded file, and prior-agent artifact. Safe continuation must still complete benign tasks where possible.",
      "gapRefs": ["G6", "G10", "G14"],
      "dependencyTaskIds": ["6.7"],
      "dependencyRationales": ["Requires measured native task breadth and recovery behavior."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-model-provider",
        "native-desktop-runtime",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-6-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-model-provider",
          "native-desktop-runtime",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-06/task-6-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Injection negatives include visible text, OCR, image-embedded text, window title, clipboard, notification, downloaded file, and prior-agent artifact. Safe continuation must still complete benign tasks where possible. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.1",
      "phaseId": "7",
      "closureState": "completed",
      "requirement": "Record the accurate fusion scope: Hermes construction done 23/23; remaining surfaces are Eve measurement/wiring, watchers, skill doctrine, semantic recall, live-channel posture, Signal/Singularity blockers, and protocol/ops/security integration.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract"],
      "evidencePlan": {
        "id": "evidence-7-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract"],
        "evidenceClassRefs": ["source-review", "automated-static"],
        "artifactLocators": [
          "docs/audits/eve-sota-hermes-fusion-scope/2026-09-09.json",
          "docs/audits/eve-sota-hermes-fusion-scope.schema.json",
          "docs/audits/EVE_SOTA_HERMES_FUSION_SCOPE_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-07/task-7-1.json",
          "tools/eve-everywhere/generate-hermes-fusion-scope.mjs",
          "tools/eve-everywhere/verify-hermes-fusion-scope.mjs",
          "tools/eve-everywhere/verify-hermes-fusion-scope.test.mjs",
          "tools/eve-everywhere/run-hermes-fusion-scope-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Record the accurate fusion scope: Hermes construction done 23/23; remaining surfaces are Eve measurement/wiring, watchers, skill doctrine, semantic recall, live-channel posture, Signal/Singularity blockers, and protocol/ops/security integration. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.2",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "Add task families for assistant runtime tool selection, schedules, timezone/DST parsing, skill retrieval, subagent delegation, refusal, cancellation, restart, and channel boundaries. Pure graders, independent cases, negatives, k≥10 floors, and long-horizon outcomes are required.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["7.1", "12.2"],
      "dependencyRationales": [
        "Uses the corrected existing Hermes/fusion boundary.",
        "Consumes independent cohort, grader and statistically feasible sample contracts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "authorization-isolation",
        "real-model-provider",
        "fault-recovery",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-7-2",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "authorization-isolation",
          "real-model-provider",
          "fault-recovery",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-2.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Add task families for assistant runtime tool selection, schedules, timezone/DST parsing, skill retrieval, subagent delegation, refusal, cancellation, restart, and channel boundaries. Pure graders, independent cases, negatives, k≥10 floors, and long-horizon outcomes are required. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.3",
      "phaseId": "7",
      "closureState": "completed",
      "requirement": "Specify watcher semantics before UI: event vs polling source, condition truth, evidence freshness, at-least-once delivery with idempotent dedupe, missed-run/backfill, timezone/DST, quiet hours, rate/budget, retry/dead-letter, authorization recheck, pause/cancel/expiry, and restart.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["7.1"],
      "dependencyRationales": ["Uses the corrected existing Hermes/fusion boundary."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "persistence-recovery",
        "authorization-isolation",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-7-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "persistence-recovery",
          "authorization-isolation",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0081-eve-watcher-semantics-before-ui.md",
          "docs/audits/eve-sota-watcher-semantics/2026-09-09.json",
          "docs/audits/eve-sota-watcher-semantics.schema.json",
          "docs/audits/EVE_SOTA_WATCHER_SEMANTICS_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-07/task-7-3.json",
          "libs/oshun/assistant/src/watchers/watcher-contract.ts",
          "libs/oshun/assistant/src/watchers/watcher-contract.spec.ts",
          "libs/oshun/assistant/src/watchers/watcher-engine.ts",
          "libs/oshun/assistant/src/watchers/watcher-engine.spec.ts",
          "libs/oshun/assistant/src/watchers/watcher-store.ts",
          "libs/oshun/assistant/src/watchers/watcher-store.spec.ts",
          "libs/oshun/assistant/src/watchers/postgres-watcher-store.ts",
          "tools/eve-everywhere/generate-watcher-semantics.mjs",
          "tools/eve-everywhere/verify-watcher-semantics.mjs",
          "tools/eve-everywhere/verify-watcher-semantics.test.mjs",
          "tools/eve-everywhere/run-watcher-semantics-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Specify watcher semantics before UI: event vs polling source, condition truth, evidence freshness, at-least-once delivery with idempotent dedupe, missed-run/backfill, timezone/DST, quiet hours, rate/budget, retry/dead-letter, authorization recheck, pause/cancel/expiry, and restart. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.4",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "After gates, add confirm-carded create and typed list/pause/resume/ cancel tools over the existing scheduler. Notifications cite the triggering evidence, watcher version, evaluation time, and delivery outcome.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["4.8", "7.2", "7.3", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes independently graded watcher, channel and assistant-runtime cases.",
        "Implements the specified watcher event, freshness and lifecycle semantics.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-7-4",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-4.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "After gates, add confirm-carded create and typed list/pause/resume/ cancel tools over the existing scheduler. Notifications cite the triggering evidence, watcher version, evaluation time, and delivery outcome. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.5",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "Prove multiple live watcher classes, duplicate suppression, condition flapping, dependency outage, restart recovery, revoked permission, poisoned source content, and cancellation. One happy event is first light, not watcher reliability.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["7.4"],
      "dependencyRationales": ["Uses admitted confirmed watcher tools and scheduler state."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-7-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Prove multiple live watcher classes, duplicate suppression, condition flapping, dependency outage, restart recovery, revoked permission, poisoned source content, and cancellation. One happy event is first light, not watcher reliability. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.6",
      "phaseId": "7",
      "closureState": "completed",
      "requirement": "Reconcile Voyager vs SMX skill systems through an ADR: ownership, layering, version/pinning, retrieval, privilege clamp, provenance, poisoning/quarantine, feedback, rollback, and one canonical user-visible skill story.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["7.1"],
      "dependencyRationales": ["Uses the corrected existing Hermes/fusion boundary."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "authorization-isolation",
        "fault-recovery",
        "security-adversarial",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-7-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "authorization-isolation",
          "fault-recovery",
          "security-adversarial",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0082-eve-canonical-skill-reconciliation.md",
          "docs/audits/eve-sota-skill-reconciliation/2026-09-09.json",
          "docs/audits/eve-sota-skill-reconciliation.schema.json",
          "docs/audits/EVE_SOTA_SKILL_RECONCILIATION_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-07/task-7-6.json",
          "libs/oshun/skill-system/src/eve-reconciliation.ts",
          "libs/oshun/skill-system/src/eve-reconciliation.spec.ts",
          "libs/oshun/skill-system/src/index.ts",
          "libs/oshun/skill-system/generated/catalog.json",
          "tools/eve-everywhere/generate-skill-reconciliation.mjs",
          "tools/eve-everywhere/verify-skill-reconciliation.mjs",
          "tools/eve-everywhere/verify-skill-reconciliation.test.mjs",
          "tools/eve-everywhere/run-skill-reconciliation-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Reconcile Voyager vs SMX skill systems through an ADR: ownership, layering, version/pinning, retrieval, privilege clamp, provenance, poisoning/quarantine, feedback, rollback, and one canonical user-visible skill story. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.7",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "Semantic recall reuses Phase 3's approved embedding route and Phase 9's memory policy behind `ConversationMemory`; no second ungoverned vector store or bypass of deletion/tenant boundaries.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["3.7", "7.6", "9.4"],
      "dependencyRationales": [
        "Consumes the measured retrieval promotion or lexical-only decision.",
        "Uses one governed skill ownership, retrieval and poisoning policy.",
        "Uses provenance, supersession, expiry and reauthorization policy."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-vector-store",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-7-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-vector-store",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Semantic recall reuses Phase 3's approved embedding route and Phase 9's memory policy behind `ConversationMemory`; no second ungoverned vector store or bypass of deletion/tenant boundaries. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.8",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "Present live-channel options to the operator with credential/identity, channel-specific consent, retention, injection, rate/spam, notification, kill switch, incident, and cost posture. Telegram may be first, but no channel runs for the builder until explicitly chosen and live-gated.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["4.8", "7.2", "7.5", "7.6", "7.7", "12.7", "13.7", "14.7"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Consumes independently graded watcher, channel and assistant-runtime cases.",
        "Requires live watcher breadth, dedupe and recovery evidence.",
        "Uses one governed skill ownership, retrieval and poisoning policy.",
        "Uses the shared semantic recall path and deletion/tenant boundaries.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-7-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "security-exercise",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Present live-channel options to the operator with credential/identity, channel-specific consent, retention, injection, rate/spam, notification, kill switch, incident, and cost posture. Telegram may be first, but no channel runs for the builder until explicitly chosen and live-gated. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.9",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "Extend the existing skill owner with versioned creative procedures. Owner: Eve skills; verifier: memory/authority QA. Depends on 7.6, 17.7, and 14.7. Reuse `skill_save/search/run` and the reconciled skill lifecycle for style rules, parameterized scene/shot recipes, source references, app/plugin/font requirements, supported operations, and accepted versus rejected examples. Preserve author/reviewer, source rights, revision history, supersession, and workspace/tenant access. Run only with the intersection of current task authority and declared tools; unavailable capabilities, poisoned recipes, stale dependencies, and cross-tenant retrieval must not broaden execution privileges.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["7.6", "14.7", "17.7"],
      "dependencyRationales": [
        "Reuses the ratified skill ownership and lifecycle.",
        "Requires retained examples and source assets to carry rights governance.",
        "Uses explicit creative workflow and capability requirements."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-7-9",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-9.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Extend the existing skill owner with versioned creative procedures. Owner: Eve skills; verifier: memory/authority QA. Depends on 7.6, 17.7, and 14.7. Reuse `skill_save/search/run` and the reconciled skill lifecycle for style rules, parameterized scene/shot recipes, source references, app/plugin/font requirements, supported operations, and accepted versus rejected examples. Preserve author/reviewer, source rights, revision history, supersession, and workspace/tenant access. Run only with the intersection of current task authority and declared tools; unavailable capabilities, poisoned recipes, stale dependencies, and cross-tenant retrieval must not broaden execution privileges. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "7.10",
      "phaseId": "7",
      "closureState": "open",
      "requirement": "Promote creative skills only after transferable quality evidence. Owner: Eve skills and creative evaluation; verifier: motion-design lead. Depends on 7.9 and 12.9. Distill approved human corrections into a proposed recipe revision with an inspectable diff; exercise save/search/run on unseen briefs and repeated sessions against the prior recipe. Measure visual outcome, tool correctness, intervention, time, and total cost; reject regression and support rollback/quarantine. Keep skill learning distinct from model-weight training, and require a real capability-bound execution for every app/tool combination a promoted recipe claims.",
      "gapRefs": ["G3", "G11", "G12", "G13", "G14", "G15", "G16", "G17", "G18"],
      "dependencyTaskIds": ["7.9", "12.9"],
      "dependencyRationales": [
        "Uses versioned and authority-clamped creative recipes.",
        "Uses held-out briefs and preregistered human-grounded quality rules."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-model-provider",
        "real-dcc-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-7-10",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-model-provider",
          "real-dcc-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-07/task-7-10.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Promote creative skills only after transferable quality evidence. Owner: Eve skills and creative evaluation; verifier: motion-design lead. Depends on 7.9 and 12.9. Distill approved human corrections into a proposed recipe revision with an inspectable diff; exercise save/search/run on unseen briefs and repeated sessions against the prior recipe. Measure visual outcome, tool correctness, intervention, time, and total cost; reject regression and support rollback/quarantine. Keep skill learning distinct from model-weight training, and require a real capability-bound execution for every app/tool combination a promoted recipe claims. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.1",
      "phaseId": "8",
      "closureState": "completed",
      "requirement": "Re-baseline what already ships: admin tours, voice, selection-ask, incident/crash entry, header/shortcut, mobile buffered mode, and feature- capability declarations. Fix documentation/metadata drift before adding anything. Inventory every core admin workspace and row/action class.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract"],
      "evidencePlan": {
        "id": "evidence-8-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract"],
        "evidenceClassRefs": ["source-review", "automated-static"],
        "artifactLocators": [
          "docs/audits/eve-sota-interface-baseline/2026-09-09.json",
          "docs/audits/eve-sota-interface-baseline.schema.json",
          "docs/audits/EVE_SOTA_INTERFACE_BASELINE_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-08/task-8-1.json",
          "apps/oshun/admin/src/lib/eve-interface-baseline.ts",
          "apps/oshun/admin/src/__tests__/eve-interface-baseline.spec.ts",
          "libs/oshun/shell-assistant/src/platform-feature-capabilities.ts",
          "libs/oshun/shell-assistant/src/__tests__/platform-feature-capabilities.spec.ts",
          "tools/eve-everywhere/print-interface-baseline.ts",
          "tools/eve-everywhere/generate-interface-baseline.mjs",
          "tools/eve-everywhere/verify-interface-baseline.mjs",
          "tools/eve-everywhere/verify-interface-baseline.test.mjs",
          "tools/eve-everywhere/run-interface-baseline-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Re-baseline what already ships: admin tours, voice, selection-ask, incident/crash entry, header/shortcut, mobile buffered mode, and feature- capability declarations. Fix documentation/metadata drift before adding anything. Inventory every core admin workspace and row/action class. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.2",
      "phaseId": "8",
      "closureState": "completed",
      "requirement": "Before meaningful UI changes, record the required design brief: visual thesis, content plan, and interaction thesis. Preserve restrained app hierarchy, utility copy, minimal chrome, clear primary workspace, and motion that improves state/affordance; no generic card-grid redesign.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.1"],
      "dependencyRationales": ["Uses the actual shipped surface and invocation inventory."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-8-2",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/eve-sota-interaction-design-brief/2026-09-09.json",
          "docs/audits/eve-sota-interaction-design-brief.schema.json",
          "docs/audits/EVE_SOTA_INTERACTION_DESIGN_BRIEF_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-08/task-8-2.json",
          "docs/oshun/ia-and-experience-quality.md",
          "tools/eve-everywhere/generate-interaction-design-brief.mjs",
          "tools/eve-everywhere/verify-interaction-design-brief.mjs",
          "tools/eve-everywhere/verify-interaction-design-brief.test.mjs",
          "tools/eve-everywhere/run-interaction-design-brief-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Before meaningful UI changes, record the required design brief: visual thesis, content plan, and interaction thesis. Preserve restrained app hierarchy, utility copy, minimal chrome, clear primary workspace, and motion that improves state/affordance; no generic card-grid redesign. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.3",
      "phaseId": "8",
      "closureState": "completed",
      "requirement": "Close contextual invocation totality through the typed registry: review items and every high-value missing row/action from the inventory. Context must pass privacy sanitization and reach the prompt/tool trace; unknown/stale/blocked points refuse visibly.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.1", "8.2"],
      "dependencyRationales": [
        "Uses the actual shipped surface and invocation inventory.",
        "Consumes the approved restrained interaction and design brief."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "real-browser-ui",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-8-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "real-browser-ui",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/eve-sota-contextual-invocation/2026-09-09.json",
          "docs/audits/eve-sota-contextual-invocation.schema.json",
          "docs/audits/EVE_SOTA_CONTEXTUAL_INVOCATION_TOTALITY_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-08/task-8-3.json",
          "libs/oshun/shell-assistant/src/admin-context-targets.ts",
          "libs/oshun/shell-assistant/src/context-handoff.ts",
          "apps/oshun/admin/src/components/AdminAssistantContextAction.tsx",
          "apps/oshun/admin/src/components/AdminShell.tsx",
          "apps/oshun/bff/src/assistant/context-handoff-prompt.ts",
          "apps/oshun/bff/src/routes/assistant.ts",
          "apps/oshun/admin/e2e/admin-assistant-invocation.spec.ts",
          "apps/oshun/bff/src/__tests__/assistant-context-handoff.spec.ts",
          "tools/eve-everywhere/print-contextual-invocation-totality.ts",
          "tools/eve-everywhere/generate-contextual-invocation-totality.mjs",
          "tools/eve-everywhere/verify-contextual-invocation-totality.mjs",
          "tools/eve-everywhere/verify-contextual-invocation-totality.test.mjs",
          "tools/eve-everywhere/run-contextual-invocation-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Close contextual invocation totality through the typed registry: review items and every high-value missing row/action from the inventory. Context must pass privacy sanitization and reach the prompt/tool trace; unknown/stale/blocked points refuse visibly. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.4",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Measure mobile streaming vs buffered mode, including TTFT, battery/ memory, unreliable network, background/foreground, reconnect, cancel, duplicate prevention, and transcript continuity. Implement the winning contract with mobile automation; no silent status quo.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.1", "8.2"],
      "dependencyRationales": [
        "Uses the actual shipped surface and invocation inventory.",
        "Consumes the approved restrained interaction and design brief."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "mobile-runtime",
        "fault-recovery",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-8-4",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "mobile-runtime",
          "fault-recovery",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-4.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Measure mobile streaming vs buffered mode, including TTFT, battery/ memory, unreliable network, background/foreground, reconnect, cancel, duplicate prevention, and transcript continuity. Implement the winning contract with mobile automation; no silent status quo. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.5",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Add user steering and control for long turns: stop, resume where safe, retry, edit-before-confirm, inspect scope, view activity/evidence, and undo/compensate. Cancellation latency and no-post-cancel-side-effect are automated release gates.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.2"],
      "dependencyRationales": ["Consumes the approved restrained interaction and design brief."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-browser-ui",
        "mobile-runtime",
        "fault-recovery",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-8-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-browser-ui",
          "mobile-runtime",
          "fault-recovery",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Add user steering and control for long turns: stop, resume where safe, retry, edit-before-confirm, inspect scope, view activity/evidence, and undo/compensate. Cancellation latency and no-post-cancel-side-effect are automated release gates. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.6",
      "phaseId": "8",
      "closureState": "completed",
      "requirement": "Typed generative-UI decision: render one allowlisted confirm/status/ evidence intent from a versioned schema; validate unknown components, hostile props/URLs, state replay, a11y, and fallback. Adopt only if it beats the existing deterministic UI on measured usefulness/reliability.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.2"],
      "dependencyRationales": ["Consumes the approved restrained interaction and design brief."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-browser-ui",
        "security-adversarial",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-8-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-browser-ui",
          "security-adversarial",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/eve-sota-generative-ui-decision/2026-09-09.json",
          "docs/audits/eve-sota-generative-ui-decision.schema.json",
          "docs/audits/EVE_SOTA_GENERATIVE_UI_DECISION_2026-09.md",
          "docs/adr/ADR-0083-eve-typed-generative-ui-confirmation.md",
          "docs/audits/eve-sota-evidence/phase-08/task-8-6.json",
          "libs/oshun/shell-assistant/src/generative-ui.ts",
          "libs/oshun/shell-assistant/src/__tests__/generative-ui.spec.ts",
          "libs/oshun/shell-assistant/src/turn-stream-frames.ts",
          "apps/oshun/bff/src/assistant/agent-tools.ts",
          "apps/oshun/bff/src/assistant/do-tier-confirm-cards.spec.ts",
          "apps/oshun/bff/src/routes/assistant.ts",
          "apps/oshun/bff/src/__tests__/assistant-turns-route.spec.ts",
          "apps/oshun/web/src/lib/assistant/turn-stream.ts",
          "apps/oshun/web/src/lib/assistant/__tests__/turn-stream.spec.ts",
          "apps/oshun/web/src/components/assistant/AssistantPanel.tsx",
          "apps/oshun/web/src/components/assistant/__tests__/AssistantPanelStreaming.spec.tsx",
          "apps/oshun/web/e2e/assistant-generative-ui.spec.ts",
          "apps/oshun/admin/src/components/AdminAssistantChat.tsx",
          "apps/oshun/admin/src/__tests__/AdminAssistantChat.spec.tsx",
          "apps/oshun/admin/e2e/admin-assistant-invocation.spec.ts",
          "tools/eve-everywhere/measure-generative-ui-decision.ts",
          "tools/eve-everywhere/generate-generative-ui-decision.mjs",
          "tools/eve-everywhere/verify-generative-ui-decision.mjs",
          "tools/eve-everywhere/verify-generative-ui-decision.test.mjs",
          "tools/eve-everywhere/run-generative-ui-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Typed generative-UI decision: render one allowlisted confirm/status/ evidence intent from a versioned schema; validate unknown components, hostile props/URLs, state replay, a11y, and fallback. Adopt only if it beats the existing deterministic UI on measured usefulness/reliability. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.7",
      "phaseId": "8",
      "closureState": "completed",
      "requirement": "Voice depth decision based on actual shipped async voice: VAD, captions, playback controls, interruption/barge-in, privacy indicators, accent/noise/empty-audio errors, and text fallback. Do not re-create the already-shipped microphone/TTS path.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.1", "8.2"],
      "dependencyRationales": [
        "Uses the actual shipped surface and invocation inventory.",
        "Consumes the approved restrained interaction and design brief."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-browser-ui",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-8-7",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-browser-ui",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0084-eve-governed-async-voice-depth.md",
          "docs/audits/EVE_SOTA_VOICE_DEPTH_DECISION_2026-09.md",
          "docs/audits/eve-sota-voice-depth-decision/2026-09-12.json",
          "docs/audits/eve-sota-evidence/phase-08/task-8-7.json",
          "tools/eve-everywhere/verify-voice-depth-decision.mjs",
          "tools/eve-everywhere/run-voice-depth-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-7.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Voice depth decision based on actual shipped async voice: VAD, captions, playback controls, interruption/barge-in, privacy indicators, accent/noise/empty-audio errors, and text fallback. Do not re-create the already-shipped microphone/TTS path. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.8",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "WCAG 2.2 AA and assistive-tech gate for drawer, tours, selection, confirmations, generated intents, streaming/live regions, focus restore, keyboard, zoom/reflow, target size, reduced motion, captions, and error recovery. Run axe plus Playwright behavior and a named screen-reader manual matrix; automation alone does not prove AT interoperability.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.3", "8.4", "8.5", "8.6", "8.7"],
      "dependencyRationales": [
        "Exercises contextual invocation totality and sanitized context.",
        "Requires the measured mobile streaming and lifecycle contract.",
        "Exercises long-turn steering, cancel and recovery behavior.",
        "Requires the evaluated typed UI or deterministic fallback decision.",
        "Requires the measured voice depth and accessible fallback boundary."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-browser-ui",
        "manual-assistive-tech"
      ],
      "evidencePlan": {
        "id": "evidence-8-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-browser-ui",
          "manual-assistive-tech"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "WCAG 2.2 AA and assistive-tech gate for drawer, tours, selection, confirmations, generated intents, streaming/live regions, focus restore, keyboard, zoom/reflow, target size, reduced motion, captions, and error recovery. Run axe plus Playwright behavior and a named screen-reader manual matrix; automation alone does not prove AT interoperability. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.9",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Deep Playwright/mobile journeys cover real server turns, tool/client- tool round trips, privacy handoff, voice/tour, cancellation/reconnect, confirmations/declines, degraded states, and responsive viewports. Visual inspection is retained for the highest-value states.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.1", "8.2", "8.3", "8.4", "8.5", "8.6", "8.7", "8.8", "8.20"],
      "dependencyRationales": [
        "Uses the actual shipped surface and invocation inventory.",
        "Consumes the approved restrained interaction and design brief.",
        "Exercises contextual invocation totality and sanitized context.",
        "Requires the measured mobile streaming and lifecycle contract.",
        "Exercises long-turn steering, cancel and recovery behavior.",
        "Requires the evaluated typed UI or deterministic fallback decision.",
        "Requires the measured voice depth and accessible fallback boundary.",
        "Requires assistive-tech and WCAG acceptance for the affected states.",
        "Requires the proven chat-surface parity journeys and register."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "real-browser-ui",
        "mobile-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-8-9",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "real-browser-ui",
          "mobile-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-9.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deep Playwright/mobile journeys cover real server turns, tool/client- tool round trips, privacy handoff, voice/tour, cancellation/reconnect, confirmations/declines, degraded states, and responsive viewports. Visual inspection is retained for the highest-value states. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.10",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Deliver the creative storyboard and revision review surface. Owner: Yemaya experience with Eve workbench; verifier: product/accessibility QA. Depends on 8.2, 8.5, 17.9, and 17.12. Open and follow `frontend-skill` before UI planning or implementation. Extend the existing project/dailies surfaces to compare alternatives and renders, annotate exact frames or regions, select a version, approve or request changes, inspect progress and cost, and stop/resume supported work. Bind controls to durable server state and the exact reviewed revision; show pending/failed/partial/stale states truthfully. Preserve keyboard, screen-reader, reduced-motion, responsive, and text/caption alternatives without exposing internal plumbing in the operator's creative flow.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.2", "8.5", "17.9", "17.12"],
      "dependencyRationales": [
        "Uses the required interface and interaction design brief.",
        "Reuses user steering and long-turn controls.",
        "Presents actual versioned storyboard alternatives and selection.",
        "Binds annotations to a working native revision loop."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-browser-ui",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-8-10",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-browser-ui",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-10.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver the creative storyboard and revision review surface. Owner: Yemaya experience with Eve workbench; verifier: product/accessibility QA. Depends on 8.2, 8.5, 17.9, and 17.12. Open and follow `frontend-skill` before UI planning or implementation. Extend the existing project/dailies surfaces to compare alternatives and renders, annotate exact frames or regions, select a version, approve or request changes, inspect progress and cost, and stop/resume supported work. Bind controls to durable server state and the exact reviewed revision; show pending/failed/partial/stale states truthfully. Preserve keyboard, screen-reader, reduced-motion, responsive, and text/caption alternatives without exposing internal plumbing in the operator's creative flow. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.11",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Prove the complete creative review journey through real services. Owner: web/mobile QA; verifier: independent product operator. Depends on 8.10 and 17.13. Add deep Playwright coverage for brief/reference input, storyboard selection, asset approval, job progress, frame-note revision, cancel/reconnect/resume, stale-review rejection, final download, and reopenable source delivery. Exercise authorization and accessible error/ recovery states. Run applicable mobile automation for declared mobile review clients. Browser tests prove UI/service behavior; link separate live DCC receipts for actual authoring/rendering rather than treating fixture previews or Playwright as native application proof.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.10", "17.13"],
      "dependencyRationales": [
        "Exercises the real creative review controls and service state.",
        "Requires actual portable, downloadable native project packages."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-browser-ui",
        "mobile-runtime",
        "real-dcc-runtime",
        "fault-recovery",
        "human-outcomes",
        "manual-assistive-tech",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-8-11",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-browser-ui",
          "mobile-runtime",
          "real-dcc-runtime",
          "fault-recovery",
          "human-outcomes",
          "manual-assistive-tech",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-11.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Prove the complete creative review journey through real services. Owner: web/mobile QA; verifier: independent product operator. Depends on 8.10 and 17.13. Add deep Playwright coverage for brief/reference input, storyboard selection, asset approval, job progress, frame-note revision, cancel/reconnect/resume, stale-review rejection, final download, and reopenable source delivery. Exercise authorization and accessible error/ recovery states. Run applicable mobile automation for declared mobile review clients. Browser tests prove UI/service behavior; link separate live DCC receipts for actual authoring/rendering rather than treating fixture previews or Playwright as native application proof. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.12",
      "phaseId": "8",
      "closureState": "completed",
      "requirement": "Ratify the chat-surface parity contract. Owner: Eve product; verifier: charter QA. Depends on 8.1 and 8.2. Adopt the dated ChatGPT/Claude.ai crosswalk as a source-owned per-surface feature register (admin drawer, member web panel/dock, mobile sheet) with ships/partial/absent status, deciding evidence, and owning task for every row. Define parity as a measured operator outcome through the intent ledger, confirm cards, privacy boundary, and capability declarations, not copied chrome. Bind every absent or partial row to a task in this expansion or an existing owner; a source test rejects an unbound row, a status without evidence, or a claim the surface source does not carry.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.1", "8.2"],
      "dependencyRationales": [
        "Uses the actual shipped surface and invocation inventory.",
        "Consumes the approved restrained interaction and design brief."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "governance-decision",
        "docs-render-integrity"
      ],
      "evidencePlan": {
        "id": "evidence-8-12",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "governance-decision",
          "docs-render-integrity"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/EVE_CHAT_UI_PARITY_AUDIT_2026-09-11.md",
          "docs/audits/eve-chat-surface-parity/v1.0.0/register.json",
          "docs/audits/eve-chat-surface-parity.schema.json",
          "docs/audits/eve-sota-evidence/phase-08/task-8-12.json",
          "tools/eve-everywhere/generate-chat-surface-parity.mjs",
          "tools/eve-everywhere/verify-chat-surface-parity.mjs",
          "tools/eve-everywhere/verify-chat-surface-parity.test.mjs",
          "tools/eve-everywhere/run-chat-surface-parity-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-12.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Ratify the chat-surface parity contract. Owner: Eve product; verifier: charter QA. Depends on 8.1 and 8.2. Adopt the dated ChatGPT/Claude.ai crosswalk as a source-owned per-surface feature register (admin drawer, member web panel/dock, mobile sheet) with ships/partial/absent status, deciding evidence, and owning task for every row. Define parity as a measured operator outcome through the intent ledger, confirm cards, privacy boundary, and capability declarations, not copied chrome. Bind every absent or partial row to a task in this expansion or an existing owner; a source test rejects an unbound row, a status without evidence, or a claim the surface source does not carry. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.13",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Ship the multimodal composer. Owner: Eve interaction with BFF transport; verifier: privacy/security QA. Depends on 8.2, 8.3, 8.12, 14.8, and 17.1. Accept file, document, spreadsheet, image, audio, and video attachments by upload, paste, drag-drop, and mobile camera/library on all three surfaces, with attachment chips, removal, size/type/count limits, malware and policy scanning, tenant-scoped storage, and a typed attachment envelope on the turn contract that reaches the prompt trace and the modality parsers as untrusted data. Unsupported types refuse visibly. Prove authorization, cross-tenant refusal, oversized/malformed/ hostile files, interrupted uploads, and deletion propagation.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.2", "8.3", "8.12", "14.8", "17.1"],
      "dependencyRationales": [
        "Consumes the approved restrained interaction and design brief.",
        "Reuses the shared privacy boundary and untrusted context-handoff block.",
        "Consumes the ratified per-surface parity register.",
        "Requires attachment classification, scanning, retention and deletion policy.",
        "Uses the real modality/toolchain capability and limitation matrix."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-browser-ui",
        "mobile-runtime",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-8-13",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-browser-ui",
          "mobile-runtime",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-13.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Ship the multimodal composer. Owner: Eve interaction with BFF transport; verifier: privacy/security QA. Depends on 8.2, 8.3, 8.12, 14.8, and 17.1. Accept file, document, spreadsheet, image, audio, and video attachments by upload, paste, drag-drop, and mobile camera/library on all three surfaces, with attachment chips, removal, size/type/count limits, malware and policy scanning, tenant-scoped storage, and a typed attachment envelope on the turn contract that reaches the prompt trace and the modality parsers as untrusted data. Unsupported types refuse visibly. Prove authorization, cross-tenant refusal, oversized/malformed/ hostile files, interrupted uploads, and deletion propagation. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.14",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Ship rich reply rendering on every surface. Owner: shell-assistant renderer; verifier: accessibility/security QA. Depends on 8.2 and 8.12. Extend the shared closed-subset renderer with syntax-highlighted code blocks carrying a language label and copy/download controls, math, diagrams, inline images with alt text, lightbox, and download, audio and video players with captions/transcripts, file cards, and honest fallbacks; bring the mobile sheet from plain text to the same contract. Keep the no-raw-markup rule, restricted URL schemes, no remote fetch without consent, and unrecognised-syntax-renders-as-itself. Test hostile markup, oversized media, reduced motion, and screen-reader semantics.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.2", "8.12"],
      "dependencyRationales": [
        "Consumes the approved restrained interaction and design brief.",
        "Consumes the ratified per-surface parity register."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-browser-ui",
        "mobile-runtime",
        "security-adversarial",
        "manual-assistive-tech"
      ],
      "evidencePlan": {
        "id": "evidence-8-14",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-browser-ui",
          "mobile-runtime",
          "security-adversarial",
          "manual-assistive-tech"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "security-exercise",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-14.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Ship rich reply rendering on every surface. Owner: shell-assistant renderer; verifier: accessibility/security QA. Depends on 8.2 and 8.12. Extend the shared closed-subset renderer with syntax-highlighted code blocks carrying a language label and copy/download controls, math, diagrams, inline images with alt text, lightbox, and download, audio and video players with captions/transcripts, file cards, and honest fallbacks; bring the mobile sheet from plain text to the same contract. Keep the no-raw-markup rule, restricted URL schemes, no remote fetch without consent, and unrecognised-syntax-renders-as-itself. Test hostile markup, oversized media, reduced motion, and screen-reader semantics. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.15",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Deliver the artifact workspace. Owner: Eve interaction with session store; verifier: product/security QA. Depends on 8.5, 8.6, and 8.14. Add a typed, versioned artifact contract (code, document, HTML/SVG preview, data table, generated media) attached to sessions, rendered in a side-by-side panel on web/admin and a sheet on mobile, with version navigation, diff, Eve edit-in-place through the intent ledger, download/ export, save to the owning domain (Nisaba notebook, Tara, Isis output gallery), and an explicit publish decision. Previews run sandboxed with CSP and no network. Extend the 8.6 generative-UI allowlist rather than bypassing it; prove replay, stale-version rejection, authorization, and hostile artifact content fail closed.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.5", "8.6", "8.14"],
      "dependencyRationales": [
        "Exercises long-turn steering, cancel and recovery behavior.",
        "Extends the adopted typed generative-UI allowlist and validators.",
        "Uses the rich renderer for artifact previews and media."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-browser-ui",
        "mobile-runtime",
        "security-adversarial",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-8-15",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-browser-ui",
          "mobile-runtime",
          "security-adversarial",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-15.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver the artifact workspace. Owner: Eve interaction with session store; verifier: product/security QA. Depends on 8.5, 8.6, and 8.14. Add a typed, versioned artifact contract (code, document, HTML/SVG preview, data table, generated media) attached to sessions, rendered in a side-by-side panel on web/admin and a sheet on mobile, with version navigation, diff, Eve edit-in-place through the intent ledger, download/ export, save to the owning domain (Nisaba notebook, Tara, Isis output gallery), and an explicit publish decision. Previews run sandboxed with CSP and no network. Extend the 8.6 generative-UI allowlist rather than bypassing it; prove replay, stale-version rejection, authorization, and hostile artifact content fail closed. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.16",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Close turn-level control parity. Owner: Eve interaction; verifier: cross-client QA. Depends on 8.5 and 8.12. Add edit-and-resend with branch and version navigation, regenerate on the same or an alternative registry-approved route, copy on every surface, per-turn feedback with reasons on every surface through the existing feedback routes, read- aloud per reply where speech is configured, turn deletion, and share/ export (Markdown, JSON, access-controlled permalink with redaction). Decide collapsible reasoning display against the actual small-model route; never fabricate a reasoning stream. Persist branches durably and prove cancel, duplicate, and post-cancel behavior per turn.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.5", "8.12"],
      "dependencyRationales": [
        "Exercises long-turn steering, cancel and recovery behavior.",
        "Consumes the ratified per-surface parity register."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-browser-ui",
        "mobile-runtime",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-8-16",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-browser-ui",
          "mobile-runtime",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-16.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Close turn-level control parity. Owner: Eve interaction; verifier: cross-client QA. Depends on 8.5 and 8.12. Add edit-and-resend with branch and version navigation, regenerate on the same or an alternative registry-approved route, copy on every surface, per-turn feedback with reasons on every surface through the existing feedback routes, read- aloud per reply where speech is configured, turn deletion, and share/ export (Markdown, JSON, access-controlled permalink with redaction). Decide collapsible reasoning display against the actual small-model route; never fabricate a reasoning stream. Persist branches durably and prove cancel, duplicate, and post-cancel behavior per turn. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.17",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Close conversation-management parity. Owner: Eve session store and shells; verifier: privacy QA. Depends on 8.12, 9.2, and 14.8. Auto-title sessions, list them with search on all surfaces including admin, add rename, pin, archive, and delete wired to the existing session routes, folders/projects with files and instructions, an explicit temporary-chat mode with a verified no-persistence guarantee, and cross-device resume. Prove tenant isolation, deletion propagation to memory/artifacts/attachments, and honest disclosure of what temporary mode does and does not forget.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.12", "9.2", "14.8"],
      "dependencyRationales": [
        "Consumes the ratified per-surface parity register.",
        "Uses the operator-visible memory inspect/correct/forget controls.",
        "Requires deletion propagation and permalink access policy."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database",
        "real-browser-ui",
        "mobile-runtime",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-8-17",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database",
          "real-browser-ui",
          "mobile-runtime",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-17.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Close conversation-management parity. Owner: Eve session store and shells; verifier: privacy QA. Depends on 8.12, 9.2, and 14.8. Auto-title sessions, list them with search on all surfaces including admin, add rename, pin, archive, and delete wired to the existing session routes, folders/projects with files and instructions, an explicit temporary-chat mode with a verified no-persistence guarantee, and cross-device resume. Prove tenant isolation, deletion propagation to memory/artifacts/attachments, and honest disclosure of what temporary mode does and does not forget. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.18",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Ship mode, tool, and route selection in the composer. Owner: Eve interaction with model registry; verifier: cost/governance QA. Depends on 8.12 and 15.7. Add a picker for search docs/web, create image/video/ audio/3D, analyze data, deep research, use computer, and escalate effort, driven by capability declarations so unavailable modes refuse honestly; model/effort choice limited to registry-approved routes with cost disclosure; slash commands and mentions for skills, tours, and workbench targets; prompt starters on admin; custom instructions bound to the persona contract. Every selection reaches the prompt trace and the intent ledger.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.12", "15.7"],
      "dependencyRationales": [
        "Consumes the ratified per-surface parity register.",
        "Uses the admitted generation legs and priced route choices."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-browser-ui",
        "mobile-runtime",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-8-18",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-browser-ui",
          "mobile-runtime",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-18.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Ship mode, tool, and route selection in the composer. Owner: Eve interaction with model registry; verifier: cost/governance QA. Depends on 8.12 and 15.7. Add a picker for search docs/web, create image/video/ audio/3D, analyze data, deep research, use computer, and escalate effort, driven by capability declarations so unavailable modes refuse honestly; model/effort choice limited to registry-approved routes with cost disclosure; slash commands and mentions for skills, tours, and workbench targets; prompt starters on admin; custom instructions bound to the persona contract. Every selection reaches the prompt trace and the intent ledger. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.19",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Deliver long-running work into the conversation. Owner: Eve interaction with job runtime; verifier: reliability QA. Depends on 8.5, 8.15, and 13.3. Render progress cards for background work (generation jobs, deep research, watcher results, fleet items) with cancel/resume, cost so far, and completion delivery into the originating thread; raise completion notifications through the existing notification center and declared mobile channels. Prove reconnect, duplicate suppression, stale thread, partial completion, and post-cancel behavior.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.5", "8.15", "13.3"],
      "dependencyRationales": [
        "Exercises long-turn steering, cancel and recovery behavior.",
        "Delivers results into the artifact workspace.",
        "Uses standardized deadline, retry, idempotency and cancellation semantics."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "real-browser-ui",
        "mobile-runtime",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-8-19",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "real-browser-ui",
          "mobile-runtime",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-19.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver long-running work into the conversation. Owner: Eve interaction with job runtime; verifier: reliability QA. Depends on 8.5, 8.15, and 13.3. Render progress cards for background work (generation jobs, deep research, watcher results, fleet items) with cancel/resume, cost so far, and completion delivery into the originating thread; raise completion notifications through the existing notification center and declared mobile channels. Prove reconnect, duplicate suppression, stale thread, partial completion, and post-cancel behavior. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "8.20",
      "phaseId": "8",
      "closureState": "open",
      "requirement": "Prove chat-surface parity end to end. Owner: web/mobile QA; verifier: independent product operator. Depends on 8.8, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, and 8.19. Deep Playwright and mobile journeys cover attachment, rendering, artifact, turn-control, conversation, mode-selection, and long-running flows on real server turns; run axe plus the named assistive-technology matrix for the new states; regenerate the per-surface parity register from source and reconcile it with the capability declarations. Feed 8.9 and 18.1; any absent or partial row keeps Phase 8/G9 open.",
      "gapRefs": ["G9"],
      "dependencyTaskIds": ["8.8", "8.13", "8.14", "8.15", "8.16", "8.17", "8.18", "8.19"],
      "dependencyRationales": [
        "Requires assistive-tech and WCAG acceptance for the affected states.",
        "Requires the shipped multimodal composer.",
        "Requires rich rendering on every surface.",
        "Requires the delivered, versioned artifact workspace on every surface.",
        "Requires turn-level edit, regenerate, copy, feedback and share parity.",
        "Requires conversation list, rename, archive, delete and project parity.",
        "Requires composer mode, tool and route selection.",
        "Requires long-running work progress and completion delivery in chat."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-browser-ui",
        "mobile-runtime",
        "manual-assistive-tech",
        "independent-verification",
        "docs-render-integrity"
      ],
      "evidencePlan": {
        "id": "evidence-8-20",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-browser-ui",
          "mobile-runtime",
          "manual-assistive-tech",
          "independent-verification",
          "docs-render-integrity"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-08/task-8-20.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Prove chat-surface parity end to end. Owner: web/mobile QA; verifier: independent product operator. Depends on 8.8, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, and 8.19. Deep Playwright and mobile journeys cover attachment, rendering, artifact, turn-control, conversation, mode-selection, and long-running flows on real server turns; run axe plus the named assistive-technology matrix for the new states; regenerate the per-surface parity register from source and reconcile it with the capability declarations. Feed 8.9 and 18.1; any absent or partial row keeps Phase 8/G9 open. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.1",
      "phaseId": "9",
      "closureState": "completed",
      "requirement": "Verify and document the actual current posture: default-on only when the operator DB is bound; flag is a kill switch; session-only degradation is visible. Remove every stale \"flag-gated/default-off\" claim from code, handbook, UI metadata, audit, and runbooks.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-database",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-9-1",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-database",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_OPERATOR_MEMORY_POSTURE_2026-09.md",
          "docs/audits/eve-sota-operator-memory-posture/postgres-receipt-2026-09-12.json",
          "docs/audits/eve-sota-evidence/phase-09/task-9-1.json",
          "tools/eve-everywhere/verify-operator-memory-posture.mjs",
          "tools/eve-everywhere/run-operator-memory-posture-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Verify and document the actual current posture: default-on only when the operator DB is bound; flag is a kill switch; session-only degradation is visible. Remove every stale \"flag-gated/default-off\" claim from code, handbook, UI metadata, audit, and runbooks. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.2",
      "phaseId": "9",
      "closureState": "completed",
      "requirement": "Complete operator-visible inspect/edit/correct/forget-all controls and disclosure: what is stored, source/confirmation, last update/use, scope, retention, and where to erase it. Verify exact row-level deletion and no adjacent-subject loss.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["9.1"],
      "dependencyRationales": ["Uses the actual persisted-memory and session-only posture."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database",
        "real-browser-ui",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-9-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database",
          "real-browser-ui",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_OPERATOR_MEMORY_CONTROLS_2026-09.md",
          "docs/audits/eve-sota-operator-memory-controls/postgres-receipt-2026-09-12.json",
          "docs/audits/eve-sota-operator-memory-controls/operator-memory-controls.png",
          "docs/audits/eve-sota-evidence/phase-09/task-9-2.json",
          "tools/eve-everywhere/verify-operator-memory-controls.mjs",
          "tools/eve-everywhere/run-operator-memory-controls-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Complete operator-visible inspect/edit/correct/forget-all controls and disclosure: what is stored, source/confirmation, last update/use, scope, retention, and where to erase it. Verify exact row-level deletion and no adjacent-subject loss. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.3",
      "phaseId": "9",
      "closureState": "open",
      "requirement": "Build a memory relevance set for precision, recall, usefulness, contradiction, staleness, preference change, no-recall, and over- personalization. Measure with real multi-session turns and human labels; telemetry silence is not evidence of zero leaks.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["9.1"],
      "dependencyRationales": ["Uses the actual persisted-memory and session-only posture."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "real-database",
        "performance-quality",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-9-3",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "real-database",
          "performance-quality",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-3.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Build a memory relevance set for precision, recall, usefulness, contradiction, staleness, preference change, no-recall, and over- personalization. Measure with real multi-session turns and human labels; telemetry silence is not evidence of zero leaks. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.4",
      "phaseId": "9",
      "closureState": "completed",
      "requirement": "Add provenance, correction/supersession, dedupe, salience/expiry policy, source reauthorization, and bounded context rendering. Never let a stale memory override live authoritative state or security policy.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["9.1", "9.2"],
      "dependencyRationales": [
        "Uses the actual persisted-memory and session-only posture.",
        "Requires operator data inspection, correction and deletion controls."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-9-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_OPERATOR_MEMORY_GOVERNANCE_2026-09.md",
          "docs/audits/eve-sota-operator-memory-governance/postgres-receipt-2026-09-12.json",
          "docs/audits/eve-sota-operator-memory-governance/operator-memory-governance.png",
          "docs/audits/eve-sota-evidence/phase-09/task-9-4.json",
          "tools/eve-everywhere/verify-operator-memory-governance.mjs",
          "tools/eve-everywhere/run-operator-memory-governance-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Add provenance, correction/supersession, dedupe, salience/expiry policy, source reauthorization, and bounded context rendering. Never let a stale memory override live authoritative state or security policy. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.5",
      "phaseId": "9",
      "closureState": "completed",
      "requirement": "Red-team memory poisoning through user/channel/tool/docs/agent inputs, cross-tenant/operator access, sensitive/member-data smuggling, deletion resurrection, vector remnants, prompt exfiltration, and conflicting notes.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["9.2", "9.4"],
      "dependencyRationales": [
        "Requires operator data inspection, correction and deletion controls.",
        "Uses provenance, supersession, expiry and reauthorization policy."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database",
        "real-vector-store",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-9-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database",
          "real-vector-store",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_OPERATOR_MEMORY_POISONING_2026-09.md",
          "docs/audits/eve-sota-operator-memory-poisoning/postgres-receipt-2026-09-12.json",
          "docs/audits/eve-sota-operator-memory-poisoning/live-model-receipt-2026-09-12.json",
          "docs/audits/eve-sota-evidence/phase-09/task-9-5.json",
          "tools/eve-everywhere/verify-operator-memory-poisoning.mjs",
          "tools/eve-everywhere/run-operator-memory-poisoning-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Red-team memory poisoning through user/channel/tool/docs/agent inputs, cross-tenant/operator access, sensitive/member-data smuggling, deletion resurrection, vector remnants, prompt exfiltration, and conflicting notes. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.6",
      "phaseId": "9",
      "closureState": "open",
      "requirement": "If semantic recall promotes, implement it behind the existing port with ACL-before-retrieval, versioned embeddings, citations to memory entries, exact deletion propagation, backup/restore, migration, and lexical/fail-loud fallback.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["3.7", "7.7", "9.4"],
      "dependencyRationales": [
        "Consumes the measured retrieval promotion or lexical-only decision.",
        "Uses the shared semantic recall path and deletion/tenant boundaries.",
        "Uses provenance, supersession, expiry and reauthorization policy."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-vector-store",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-9-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-vector-store",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "If semantic recall promotes, implement it behind the existing port with ACL-before-retrieval, versioned embeddings, citations to memory entries, exact deletion propagation, backup/restore, migration, and lexical/fail-loud fallback. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "9.7",
      "phaseId": "9",
      "closureState": "open",
      "requirement": "Canary and rollout evidence includes usefulness, correction/forget success, leakage/poisoning attacks, latency/cost, and kill-switch rollback. No task in this phase \"promotes default-on\" because that decision already shipped.",
      "gapRefs": ["G11"],
      "dependencyTaskIds": ["9.2", "9.3", "9.4", "9.5", "9.6"],
      "dependencyRationales": [
        "Requires operator data inspection, correction and deletion controls.",
        "Requires independently human-labelled multi-session memory cases.",
        "Uses provenance, supersession, expiry and reauthorization policy.",
        "Requires observed poisoning, isolation and deletion-resurrection controls.",
        "Requires the admitted semantic-memory path or evidenced non-adoption boundary."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "real-database",
        "real-vector-store",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-9-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "real-database",
          "real-vector-store",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-09/task-9-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Canary and rollout evidence includes usefulness, correction/forget success, leakage/poisoning attacks, latency/cost, and kill-switch rollback. No task in this phase \"promotes default-on\" because that decision already shipped. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "10.1",
      "phaseId": "10",
      "closureState": "completed",
      "requirement": "Verify the existing seven cases' current V1.0 expectations, `releaseBlocked` metadata, advisory status, exact V1.2 restore expectations, and retained k=10 evidence. Correct the audit; do not claim this substrate is missing.",
      "gapRefs": ["G8"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
      "evidencePlan": {
        "id": "evidence-10-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
        "evidenceClassRefs": ["source-review", "automated-static", "automated-test"],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/evals/release-blocked-eval-audit.ts",
          "apps/oshun/bff/src/assistant/evals/release-blocked-eval-audit.spec.ts",
          "apps/oshun/bff/tsconfig.release-blocked-eval-audit.json",
          "docs/audits/eve-sota-release-scope-eval-audit/2026-09-12.json",
          "docs/audits/eve-sota-release-scope-eval-audit.schema.json",
          "docs/audits/EVE_SOTA_RELEASE_SCOPE_EVAL_AUDIT_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-10/task-10-1.json",
          "tools/eve-everywhere/capture-release-blocked-eval-audit.ts",
          "tools/eve-everywhere/verify-release-blocked-eval-audit.mjs",
          "tools/eve-everywhere/verify-release-blocked-eval-audit.test.mjs",
          "tools/eve-everywhere/run-release-blocked-eval-audit-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-10/task-10-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Verify the existing seven cases' current V1.0 expectations, `releaseBlocked` metadata, advisory status, exact V1.2 restore expectations, and retained k=10 evidence. Correct the audit; do not claim this substrate is missing. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "10.2",
      "phaseId": "10",
      "closureState": "completed",
      "requirement": "Make expectation selection consume the authoritative runtime release scope so V1.0 runs the honest boundary and V1.2 runs the original room semantics automatically. Unknown/malformed scopes fail closed.",
      "gapRefs": ["G8"],
      "dependencyTaskIds": ["10.1"],
      "dependencyRationales": [
        "Uses the authoritative existing release-blocked room expectations."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
      "evidencePlan": {
        "id": "evidence-10-2",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "automated-behavior"],
        "evidenceClassRefs": ["source-review", "automated-static", "automated-test"],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/evals/eval-release-scope.ts",
          "apps/oshun/bff/src/assistant/evals/eval-release-scope.spec.ts",
          "apps/oshun/bff/src/assistant/evals/assistant-golden.eval.ts",
          "apps/oshun/bff/tsconfig.eval-release-scope.json",
          "docs/audits/eve-sota-release-scope-selection/2026-09-12.json",
          "docs/audits/eve-sota-release-scope-selection.schema.json",
          "docs/audits/EVE_SOTA_RELEASE_SCOPE_SELECTION_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-10/task-10-2.json",
          "tools/eve-everywhere/capture-release-scope-selection.ts",
          "tools/eve-everywhere/verify-release-scope-selection.mjs",
          "tools/eve-everywhere/verify-release-scope-selection.test.mjs",
          "tools/eve-everywhere/run-release-scope-selection-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-10/task-10-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Make expectation selection consume the authoritative runtime release scope so V1.0 runs the honest boundary and V1.2 runs the original room semantics automatically. Unknown/malformed scopes fail closed. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "10.3",
      "phaseId": "10",
      "closureState": "completed",
      "requirement": "Dual-scope provider-free tests execute all seven under V1.0 and V1.2, prove withheld tools cannot appear early, prove restored tools are required later, and red on an inverted/missing release mapping.",
      "gapRefs": ["G8"],
      "dependencyTaskIds": ["10.2"],
      "dependencyRationales": ["Exercises runtime release-scope expectation selection."],
      "requiredProofScopeRefs": ["source-inspection", "automated-behavior", "service-integration"],
      "evidencePlan": {
        "id": "evidence-10-3",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "automated-behavior", "service-integration"],
        "evidenceClassRefs": ["source-review", "automated-test", "service-integration"],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/evals/release-scope-dual-provider-free.spec.ts",
          "apps/oshun/bff/tsconfig.release-scope-dual-provider-free.json",
          "docs/audits/eve-sota-release-scope-dual-provider-free/2026-09-12.json",
          "docs/audits/eve-sota-release-scope-dual-provider-free.schema.json",
          "docs/audits/EVE_SOTA_RELEASE_SCOPE_DUAL_PROVIDER_FREE_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-10/task-10-3.json",
          "tools/eve-everywhere/capture-release-scope-dual-provider-free.ts",
          "tools/eve-everywhere/verify-release-scope-dual-provider-free.mjs",
          "tools/eve-everywhere/verify-release-scope-dual-provider-free.test.mjs",
          "tools/eve-everywhere/run-release-scope-dual-provider-free-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-10/task-10-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Dual-scope provider-free tests execute all seven under V1.0 and V1.2, prove withheld tools cannot appear early, prove restored tools are required later, and red on an inverted/missing release mapping. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "10.4",
      "phaseId": "10",
      "closureState": "open",
      "requirement": "Re-run k≥10 on current V1.0 and record without changing the existing advisory rationale. When V1.2 actually opens, rerun the restored semantics and promote/retire annotations only after those floors pass.",
      "gapRefs": ["G8"],
      "dependencyTaskIds": ["10.1", "10.2", "10.3"],
      "dependencyRationales": [
        "Uses the authoritative existing release-blocked room expectations.",
        "Exercises runtime release-scope expectation selection.",
        "Requires provider-free dual-scope and inverted-mapping controls."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-10-4",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-10/task-10-4.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Re-run k≥10 on current V1.0 and record without changing the existing advisory rationale. When V1.2 actually opens, rerun the restored semantics and promote/retire annotations only after those floors pass. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.1",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Build an internal, versioned engineering benchmark from real closed work: diagnosis-only, bug fix, feature, refactor, migration/contract, security repair, docs/product graph, UI/Playwright, service integration, and DCC/native tasks. Keep hidden acceptance evidence separate from agent context and prevent benchmark contamination.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-11-1",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/eve-engineering-benchmark.schema.json",
          "docs/audits/eve-engineering-benchmark/v1.0.0/public/catalog.json",
          "docs/audits/eve-engineering-benchmark/v1.0.0/evaluator/acceptance.json",
          "docs/audits/eve-engineering-benchmark/v1.0.0/release.json",
          "docs/audits/EVE_ENGINEERING_BENCHMARK_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-11/task-11-1.json",
          "tools/eve-everywhere/seal-engineering-benchmark.mjs",
          "tools/eve-everywhere/export-engineering-benchmark-context.mjs",
          "tools/eve-everywhere/verify-engineering-benchmark.mjs",
          "tools/eve-everywhere/verify-engineering-benchmark.test.mjs",
          "tools/eve-everywhere/run-engineering-benchmark-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build an internal, versioned engineering benchmark from real closed work: diagnosis-only, bug fix, feature, refactor, migration/contract, security repair, docs/product graph, UI/Playwright, service integration, and DCC/native tasks. Keep hidden acceptance evidence separate from agent context and prevent benchmark contamination. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.2",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Specify and grade the plan-quality contract: requirements and non-goals, authoritative source discovery, dependency rationale, risk, verification matrix, rollback, and clarification threshold. Grade uncovered requirements, contradictory decisions, wrong-scope work, weak proof, and stale plans. This task owns the rubric and schema; tasks 11.9–11.11 own durable planning implementation and real lifecycle integration under ADR-0076. A passing rubric cannot claim those runtime capabilities delivered.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["2.1"],
      "dependencyRationales": ["Implements the adopted attributed delivery lifecycle."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-11-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "performance-quality"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "automated-test", "measurement"],
        "artifactLocators": [
          "docs/audits/eve-engineering-plan-quality.schema.json",
          "docs/audits/eve-engineering-plan-quality/v1.0.0/rubric.json",
          "docs/audits/eve-engineering-plan-quality/v1.0.0/context.json",
          "docs/audits/eve-engineering-plan-quality/v1.0.0/passing-plan.json",
          "docs/audits/eve-engineering-plan-quality/v1.0.0/conformance.json",
          "docs/audits/eve-engineering-plan-quality/v1.0.0/measurement-2026-09-12.json",
          "docs/audits/EVE_ENGINEERING_PLAN_QUALITY_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-11/task-11-2.json",
          "tools/eve-everywhere/seal-engineering-plan-quality.mjs",
          "tools/eve-everywhere/grade-engineering-plan.mjs",
          "tools/eve-everywhere/grade-engineering-plan.test.mjs",
          "tools/eve-everywhere/measure-engineering-plan-grader.mjs",
          "tools/eve-everywhere/verify-engineering-plan-quality.mjs",
          "tools/eve-everywhere/verify-engineering-plan-quality.test.mjs",
          "tools/eve-everywhere/run-engineering-plan-quality-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Specify and grade the plan-quality contract: requirements and non-goals, authoritative source discovery, dependency rationale, risk, verification matrix, rollback, and clarification threshold. Grade uncovered requirements, contradictory decisions, wrong-scope work, weak proof, and stale plans. This task owns the rubric and schema; tasks 11.9–11.11 own durable planning implementation and real lifecycle integration under ADR-0076. A passing rubric cannot claim those runtime capabilities delivered. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.3",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Repository execution contract: preserve user changes, isolate work, never expose secrets, follow ownership/AGENTS, use correct generators, choose targeted tests, supervise resources, and retain machine-readable command/artifact evidence.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "host-capability-observation",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-11-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "host-capability-observation",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/eve-repository-execution.schema.json",
          "docs/audits/eve-repository-execution/v1.0.0/contract.json",
          "docs/audits/eve-repository-execution/v1.0.0/measurement-2026-09-12.json",
          "docs/audits/EVE_REPOSITORY_EXECUTION_CONTRACT_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-11/task-11-3.json",
          "tools/eve-repository-execution-lib.mjs",
          "tools/eve-repository-execution.test.mjs",
          "tools/eve-everywhere/seal-repository-execution.mjs",
          "tools/eve-everywhere/probe-repository-execution.mjs",
          "tools/eve-everywhere/verify-repository-execution.mjs",
          "tools/eve-everywhere/verify-repository-execution.test.mjs",
          "tools/eve-everywhere/run-repository-execution-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Repository execution contract: preserve user changes, isolate work, never expose secrets, follow ownership/AGENTS, use correct generators, choose targeted tests, supervise resources, and retain machine-readable command/artifact evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.4",
      "phaseId": "11",
      "closureState": "open",
      "requirement": "Independent review/verification lane evaluates behavior, code quality, security/privacy/accessibility, test strength, migration/backward compatibility, and fabricated-success patterns. The implementer cannot self-approve `verified`.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["4.8", "11.2", "11.3"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Implements or grades the explicit plan-quality and scope contract.",
        "Uses the repository execution, isolation and evidence contract."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-11-4",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "security-exercise",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-4.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Independent review/verification lane evaluates behavior, code quality, security/privacy/accessibility, test strength, migration/backward compatibility, and fabricated-success patterns. The implementer cannot self-approve `verified`. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.5",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Exercise conflict, moving `origin/main`, failed hook, flaky/provider- sick test, pre-existing failure, dependency outage, partial commit, agent crash, budget/kill switch, revert, and resume. Each ends in a truthful, recoverable state with no lost user work.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["11.3", "11.11"],
      "dependencyRationales": [
        "Uses the repository execution, isolation and evidence contract.",
        "Exercises revision-bound fleet execution, invalidation and recovery."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "host-capability-observation",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-11-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "host-capability-observation",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [
          "docs/audits/EVE_DELIVERY_FAULT_GAME_2026-09.md",
          "docs/audits/eve-delivery-fault-game-admission.schema.json",
          "docs/audits/eve-delivery-fault-game/v1.0.0/admission-2026-09-16.json",
          "docs/audits/eve-delivery-fault-game/v1.0.0/measurement-2026-09-13.json",
          "docs/audits/eve-delivery-fault-game/v1.0.0/preparation-evidence.json",
          "docs/audits/eve-sota-evidence/phase-11/task-11-5.json",
          "tools/eve-everywhere/verify-delivery-fault-game-admission.mjs",
          "tools/eve-everywhere/verify-delivery-fault-game-admission.test.mjs",
          "tools/eve-everywhere/run-delivery-fault-game-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Exercise conflict, moving `origin/main`, failed hook, flaky/provider- sick test, pre-existing failure, dependency outage, partial commit, agent crash, budget/kill switch, revert, and resume. Each ends in a truthful, recoverable state with no lost user work. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.6",
      "phaseId": "11",
      "closureState": "open",
      "requirement": "Measure end-to-end on diverse unseen benchmark tasks: verified success, human interventions, escaped defects, revert rate, changed-lines quality, time, tokens/cost, test selection, and explanation fidelity. Compare against the manual lane and pre-register promotion floors.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["11.1", "11.4", "11.5", "11.12", "12.2"],
      "dependencyRationales": [
        "Uses unseen versioned engineering cases with hidden acceptance evidence.",
        "Requires independent behavioral review and anti-fabrication evidence.",
        "Requires real delivery conflict, crash, rollback and resume behavior.",
        "Requires complete operator labor accounting, including approvals and failed work.",
        "Consumes independent cohort, grader and statistically feasible sample contracts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-agent-runtime",
        "operational-load-soak",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-11-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-agent-runtime",
          "operational-load-soak",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "operational-exercise",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Measure end-to-end on diverse unseen benchmark tasks: verified success, human interventions, escaped defects, revert rate, changed-lines quality, time, tokens/cost, test selection, and explanation fidelity. Compare against the manual lane and pre-register promotion floors. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.7",
      "phaseId": "11",
      "closureState": "open",
      "requirement": "Live capstone: an operator goal becomes an approved plan and real scoped work items; the fleet implements, reviews, integrates, pushes, machine-verifies, and narrates the exact change with rollback evidence.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["2.8", "11.6", "11.11"],
      "dependencyRationales": [
        "Requires the actual governed fleet drain and soak evidence.",
        "Requires measured delivery competence against paired baselines.",
        "Exercises revision-bound fleet execution, invalidation and recovery."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "persistence-recovery",
        "real-agent-runtime",
        "operational-load-soak",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-11-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "persistence-recovery",
          "real-agent-runtime",
          "operational-load-soak",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Live capstone: an operator goal becomes an approved plan and real scoped work items; the fleet implements, reviews, integrates, pushes, machine-verifies, and narrates the exact change with rollback evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.8",
      "phaseId": "11",
      "closureState": "open",
      "requirement": "Execute the ratified charter benchmark across V1.0/V1.1/V1.2 and V2–V10, including every required workflow, ruleset cell, platform, and runtime stratum. Use independently authored unseen goals that combine discovery, design, implementation/content production, integration, distribution, operation, and improvement over multiple sessions. Include changed requirements, failure/recovery, and the scorecard's complete 14-day persistent-result observation window. Apply its sample minima and targets per stratum, retain blinded operator quality judgments, and compare paired manual and current agent baselines at declared budgets. Neither a successful Blender scene nor a software capstone substitutes for a missing workflow. Required release/host access and human labels keep this task open until actually available and measured.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["0.8", "5.11", "11.7", "12.8", "17.6"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Requires every selected runtime package, including newly discovered children, to be delivered.",
        "Requires an actual operator-goal-to-verified-delivery trajectory.",
        "Requires the full evidence-joining charter gate implementation, independently of later production results.",
        "Requires real governed cross-modal delivery and verification."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "persistence-recovery",
        "real-model-provider",
        "real-agent-runtime",
        "real-database",
        "real-browser-ui",
        "native-desktop-runtime",
        "mobile-runtime",
        "real-dcc-runtime",
        "real-engine-runtime",
        "real-multimodal-runtime",
        "operational-load-soak",
        "fault-recovery",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-11-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "persistence-recovery",
          "real-model-provider",
          "real-agent-runtime",
          "real-database",
          "real-browser-ui",
          "native-desktop-runtime",
          "mobile-runtime",
          "real-dcc-runtime",
          "real-engine-runtime",
          "real-multimodal-runtime",
          "operational-load-soak",
          "fault-recovery",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Execute the ratified charter benchmark across V1.0/V1.1/V1.2 and V2–V10, including every required workflow, ruleset cell, platform, and runtime stratum. Use independently authored unseen goals that combine discovery, design, implementation/content production, integration, distribution, operation, and improvement over multiple sessions. Include changed requirements, failure/recovery, and the scorecard's complete 14-day persistent-result observation window. Apply its sample minima and targets per stratum, retain blinded operator quality judgments, and compare paired manual and current agent baselines at declared budgets. Neither a successful Blender scene nor a software capstone substitutes for a missing workflow. Required release/host access and human labels keep this task open until actually available and measured. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.9",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Implement durable goal and requirement revisions under ADR-0076. Owner: Agentic AI Lead; verifier: QA Lead. Add versioned contracts, persistence/migrations and authenticated APIs for attributed objectives, non- goals, stable requirement IDs, source/decision refs and acceptance criteria; preserve append-only revisions, tenant isolation and expected-version concurrency. Test real database restart, idempotent retry, migration/backward compatibility, concurrent human edits, conflicting decisions, unauthorized acceptance and missing requirement coverage through the service boundary.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["11.2"],
      "dependencyRationales": [
        "Implements or grades the explicit plan-quality and scope contract."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-11-9",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [
          "libs/contracts/src/planning/goal-requirement-revision.ts",
          "libs/oshun/persistence/prisma/schema.prisma",
          "libs/oshun/persistence/prisma/migrations/20260913020000_planning_goal_requirement_revisions/migration.sql",
          "apps/oshun/bff/src/workbench/planning-store.ts",
          "apps/oshun/bff/src/routes/planning-goals.ts",
          "apps/oshun/bff/src/workbench/planning-store.integration.spec.ts",
          "apps/oshun/bff/openapi/oshun-bff.openapi.yaml",
          "docs/audits/eve-goal-requirement-revisions/v1.0.0/database-receipt.json",
          "docs/audits/eve-sota-evidence/phase-11/task-11-9.json",
          "tools/eve-everywhere/verify-goal-requirement-revisions.mjs",
          "tools/eve-everywhere/verify-goal-requirement-revisions.test.mjs",
          "tools/eve-everywhere/run-goal-requirement-revisions-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-9.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Implement durable goal and requirement revisions under ADR-0076. Owner: Agentic AI Lead; verifier: QA Lead. Add versioned contracts, persistence/migrations and authenticated APIs for attributed objectives, non- goals, stable requirement IDs, source/decision refs and acceptance criteria; preserve append-only revisions, tenant isolation and expected-version concurrency. Test real database restart, idempotent retry, migration/backward compatibility, concurrent human edits, conflicting decisions, unauthorized acceptance and missing requirement coverage through the service boundary. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.10",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Implement the versioned dependency DAG and preregistered verification plan over 11.9. Owner: Agentic AI Lead; verifier: QA Lead. Persist typed edges with individual reasons, canonical graph/plan digests, requirements-to-work ownership and proof-boundary rows. Reject unknown/orphan nodes, cycles, uncovered goals, weak evidence plans and unaccepted material scope changes; allow independent branches without numeric-order dependencies. Test persistence, round-trip APIs, competing revisions and exact requirement→plan→proof joins. Keep evaluation hidden answers outside agent context.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["11.9"],
      "dependencyRationales": ["Consumes persisted attributed goal and requirement revisions."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-database"
      ],
      "evidencePlan": {
        "id": "evidence-11-10",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-database"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [
          "libs/contracts/src/planning/delivery-plan-revision.ts",
          "libs/oshun/persistence/prisma/schema.prisma",
          "libs/oshun/persistence/prisma/migrations/20260913040000_planning_delivery_plan_revisions/migration.sql",
          "apps/oshun/bff/src/workbench/planning-plan-store.ts",
          "apps/oshun/bff/src/routes/planning-plans.ts",
          "apps/oshun/bff/src/workbench/planning-plan-store.integration.spec.ts",
          "apps/oshun/bff/openapi/oshun-bff.openapi.yaml",
          "docs/audits/eve-delivery-plan-revisions/v1.0.0/database-receipt.json",
          "docs/audits/eve-sota-evidence/phase-11/task-11-10.json",
          "tools/eve-everywhere/verify-delivery-plan-revisions.mjs",
          "tools/eve-everywhere/verify-delivery-plan-revisions.test.mjs",
          "tools/eve-everywhere/run-delivery-plan-revisions-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-10.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Implement the versioned dependency DAG and preregistered verification plan over 11.9. Owner: Agentic AI Lead; verifier: QA Lead. Persist typed edges with individual reasons, canonical graph/plan digests, requirements-to-work ownership and proof-boundary rows. Reject unknown/orphan nodes, cycles, uncovered goals, weak evidence plans and unaccepted material scope changes; allow independent branches without numeric-order dependencies. Test persistence, round-trip APIs, competing revisions and exact requirement→plan→proof joins. Keep evaluation hidden answers outside agent context. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.11",
      "phaseId": "11",
      "closureState": "completed",
      "requirement": "Bind planning revisions into the real fleet lifecycle. Owner: Agentic AI Lead; verifier: QA Lead independently. Work items carry exact goalRevisionId, planRevisionId, requirementRefs, dependencyRefs and verificationPlanRefs; canonical readiness, hand lease and drain enforce those bindings. Goal/decision changes invalidate affected ready work and triage active leases without rewriting shipped history. Test real goal→plan→lease→review→ship→verify, replanning, cancellation, process restart and concurrent scope changes against persisted state; stale plans cannot lease or close, and implementers cannot self-verify.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["2.7", "11.10"],
      "dependencyRationales": [
        "Consumes the fault-tested queue and hand-lease/drain parity contract.",
        "Consumes the persisted acyclic dependency graph and proof plan."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-agent-runtime",
        "real-database",
        "fault-recovery",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-11-11",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-agent-runtime",
          "real-database",
          "fault-recovery",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [
          "libs/contracts/src/planning/fleet-lifecycle.ts",
          "libs/oshun/persistence/prisma/schema.prisma",
          "libs/oshun/persistence/prisma/migrations/20260913050000_planning_fleet_lifecycle/migration.sql",
          "libs/oshun/persistence/prisma/migrations/20260913060000_planning_workbench_event_integrity/migration.sql",
          "apps/oshun/bff/src/workbench/intent-store.ts",
          "apps/oshun/bff/src/workbench/work-queue.ts",
          "apps/oshun/bff/src/workbench/work-queue.integration.spec.ts",
          "apps/oshun/bff/src/workbench/agent-auth.ts",
          "apps/oshun/bff/src/workbench/agent-auth.spec.ts",
          "apps/oshun/bff/src/workbench/artifact-verifier.ts",
          "apps/oshun/bff/src/workbench/planning-store.ts",
          "apps/oshun/bff/src/workbench/planning-plan-store.ts",
          "apps/oshun/bff/src/routes/planning-fleet.ts",
          "apps/oshun/bff/src/routes/workbench.ts",
          "apps/oshun/bff/src/routes/assistant.ts",
          "apps/oshun/bff/src/workbench/workbench-agent-tools.ts",
          "apps/oshun/bff/src/workbench/planning-fleet-lifecycle.integration.spec.ts",
          "apps/oshun/bff/src/workbench/planning-fleet-restart-probe.ts",
          "apps/oshun/bff/src/app.ts",
          "apps/oshun/bff/openapi/oshun-bff.openapi.yaml",
          "libs/contracts/src/planning/fleet-lifecycle.spec.ts",
          "libs/oshun/persistence/src/planning-fleet-schema.spec.ts",
          "tools/eve-fleet-drain.mjs",
          "tools/eve-fleet-drain.test.mjs",
          "tools/workbench-mcp/server.mjs",
          "tools/eve-codex-agent.mjs",
          "tools/workbench-cli.mjs",
          "tools/eve-execution-isolation-lib.mjs",
          "tools/eve-execution-isolation.test.mjs",
          "docs/audits/eve-planning-fleet-lifecycle/v1.0.0/database-receipt.json",
          "docs/audits/eve-planning-fleet-lifecycle/v1.0.0/qa-review.schema.json",
          "docs/audits/eve-planning-fleet-lifecycle/v1.0.0/qa-review-prompt.md",
          "docs/audits/eve-planning-fleet-lifecycle/v1.0.0/qa-review.json",
          "docs/audits/eve-sota-evidence/phase-11/task-11-11.json",
          "tools/eve-everywhere/verify-planning-fleet-lifecycle.mjs",
          "tools/eve-everywhere/verify-planning-fleet-lifecycle.test.mjs",
          "tools/eve-everywhere/run-planning-fleet-lifecycle-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-11.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Bind planning revisions into the real fleet lifecycle. Owner: Agentic AI Lead; verifier: QA Lead independently. Work items carry exact goalRevisionId, planRevisionId, requirementRefs, dependencyRefs and verificationPlanRefs; canonical readiness, hand lease and drain enforce those bindings. Goal/decision changes invalidate affected ready work and triage active leases without rewriting shipped history. Test real goal→plan→lease→review→ship→verify, replanning, cancellation, process restart and concurrent scope changes against persisted state; stale plans cannot lease or close, and implementers cannot self-verify. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "11.12",
      "phaseId": "11",
      "closureState": "open",
      "requirement": "Instrument total operator labor per verified result. Owner: Operations Lead; verifier: QA Lead with the product operator. Record attributed hands-on minutes for goal formulation/planning, clarification, required approvals/confirmations, monitoring, review/acceptance, correction/recovery and release/operations in both Eve and paired manual cohorts. Include failed attempts, retries and overhead; report elapsed decision wait separately. Deduplicate overlapping intervals per person without erasing other reviewers, preserve unknown time as incomplete, and retain privacy-safe source receipts. Test missing categories, manual baseline mismatch, zero verified results, concurrent timers and governance reclassification. Collect independent real operator time records; enforce the version-2 workload target without skipping required human decisions.",
      "gapRefs": ["G12"],
      "dependencyTaskIds": ["11.2", "13.2"],
      "dependencyRationales": [
        "Implements or grades the explicit plan-quality and scope contract.",
        "Consumes attributed end-to-end trace/correlation records."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-11-12",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "measurement",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-11/task-11-12.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Instrument total operator labor per verified result. Owner: Operations Lead; verifier: QA Lead with the product operator. Record attributed hands-on minutes for goal formulation/planning, clarification, required approvals/confirmations, monitoring, review/acceptance, correction/recovery and release/operations in both Eve and paired manual cohorts. Include failed attempts, retries and overhead; report elapsed decision wait separately. Deduplicate overlapping intervals per person without erasing other reviewers, preserve unknown time as incomplete, and retain privacy-safe source receipts. Test missing categories, manual baseline mismatch, zero verified results, concurrent timers and governance reclassification. Collect independent real operator time records; enforce the version-2 workload target without skipping required human decisions. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.1",
      "phaseId": "12",
      "closureState": "completed",
      "requirement": "Expand the task/eval taxonomy to cover every required charter capability as well as every admitted capability and risk: conversation, routing/tools, retrieval/citations, planning/code, fleet, DCC, computer use, watchers/channels, memory, multimodal, UX/a11y, security, reliability/recovery, privacy, and cost.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["0.8"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract"],
      "evidencePlan": {
        "id": "evidence-12-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract"],
        "evidenceClassRefs": ["source-review", "automated-static"],
        "artifactLocators": [
          "libs/oshun/analytics/src/eve-evaluation-taxonomy.ts",
          "libs/oshun/analytics/src/eve-workflow-primary-context.ts",
          "libs/oshun/analytics/src/__tests__/eve-evaluation-taxonomy.spec.ts",
          "libs/oshun/analytics/src/index.ts",
          "docs/audits/eve-sota-evaluation-taxonomy/2026-09-13.json",
          "docs/audits/eve-sota-evaluation-taxonomy.schema.json",
          "docs/audits/eve-sota-evaluation-taxonomy-review.schema.json",
          "docs/audits/eve-sota-evaluation-taxonomy/reviews/confirmatory.json",
          "docs/audits/eve-sota-evaluation-taxonomy/reviews/adversarial.json",
          "docs/audits/eve-sota-evidence/phase-12/task-12-1.json",
          "tools/eve-everywhere/generate-evaluation-taxonomy.mjs",
          "tools/eve-everywhere/verify-evaluation-taxonomy.mjs",
          "tools/eve-everywhere/verify-evaluation-taxonomy.test.mjs",
          "tools/eve-everywhere/verify-evaluation-taxonomy-reviews.mjs",
          "tools/eve-everywhere/verify-evaluation-taxonomy-reviews.test.mjs",
          "tools/eve-everywhere/run-evaluation-taxonomy-evidence.mjs",
          "tools/eve-everywhere/run-evaluation-taxonomy-evidence.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Expand the task/eval taxonomy to cover every required charter capability as well as every admitted capability and risk: conversation, routing/tools, retrieval/citations, planning/code, fleet, DCC, computer use, watchers/channels, memory, multimodal, UX/a11y, security, reliability/recovery, privacy, and cost. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.2",
      "phaseId": "12",
      "closureState": "completed",
      "requirement": "For each family define independent case diversity, stochastic runs, pure/model/human rubric, negative/benign controls, hard safety locks, outcome metrics, statistical unit/test, floor, and escalation. Implement the prospective version-2 scorecard sample-design contract: enumerate every applicable stratum and criterion denominator, require Wilson-floor feasibility and at least 80% planned floor-passing probability at the declared target, and preregister bootstrap precision/power using a separate pilot for continuous metrics. Nested seeds are not independent cases. Retain actual human assessor ownership and reject missing, undersized, post-result-expanded, or silently pooled strata through the evaluation CLI. No family closes with shape-only assertions.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["0.3", "12.1"],
      "dependencyRationales": [
        "Consumes the preregistered outcome thresholds and decision rules.",
        "Uses the complete required-capability and risk taxonomy."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-12-2",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_EVALUATION_DESIGN_2026-09.md",
          "docs/audits/eve-sota-evaluation-design/2026-09-13.json",
          "docs/audits/eve-sota-evaluation-design.schema.json",
          "docs/audits/eve-sota-evaluation-cohort.schema.json",
          "docs/audits/eve-sota-evidence/phase-12/task-12-2.json",
          "tools/eve-everywhere/evaluation-design-policy.mjs",
          "tools/eve-everywhere/generate-evaluation-design.mjs",
          "tools/eve-everywhere/verify-evaluation-design.mjs",
          "tools/eve-everywhere/verify-evaluation-design.test.mjs",
          "tools/eve-everywhere/evaluate-evaluation-cohort.mjs",
          "tools/eve-everywhere/evaluate-evaluation-cohort.test.mjs",
          "tools/eve-everywhere/run-evaluation-design-evidence.mjs",
          "tools/eve-everywhere/run-evaluation-design-evidence.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "For each family define independent case diversity, stochastic runs, pure/model/human rubric, negative/benign controls, hard safety locks, outcome metrics, statistical unit/test, floor, and escalation. Implement the prospective version-2 scorecard sample-design contract: enumerate every applicable stratum and criterion denominator, require Wilson-floor feasibility and at least 80% planned floor-passing probability at the declared target, and preregister bootstrap precision/power using a separate pilot for continuous metrics. Nested seeds are not independent cases. Retain actual human assessor ownership and reject missing, undersized, post-result-expanded, or silently pooled strata through the evaluation CLI. No family closes with shape-only assertions. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.3",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Complete the pre-registered ≥40-transcript blinded human-label set and judge tournament. Agreement is per class; classes below the bar stay advisory. The harness never authors the labels by which it is judged.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["0.3"],
      "dependencyRationales": ["Consumes the preregistered outcome thresholds and decision rules."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-model-provider",
        "performance-quality",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-12-3",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-model-provider",
          "performance-quality",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-3.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Complete the pre-registered ≥40-transcript blinded human-label set and judge tournament. Agreement is per class; classes below the bar stay advisory. The harness never authors the labels by which it is judged. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.4",
      "phaseId": "12",
      "closureState": "completed",
      "requirement": "Add long-horizon trajectory grading: goal completion, unnecessary steps, recovery, repeated error, state drift, premature success, safe abstention, and evidence fidelity. Final-answer quality alone cannot hide unsafe or wasteful trajectories.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["12.2"],
      "dependencyRationales": [
        "Consumes independent cohort, grader and statistically feasible sample contracts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "fault-recovery",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-12-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "fault-recovery",
          "performance-quality"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "automated-test", "measurement"],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_TRAJECTORY_GRADING_2026-09.md",
          "docs/audits/eve-sota-trajectory-grading/2026-09-13.performance.json",
          "docs/audits/eve-sota-trajectory-grading/contract-fixture.lock.json",
          "docs/audits/eve-sota-trajectory-grading/contract-fixture.results.json",
          "docs/audits/eve-sota-trajectory-grading/contract-fixture.report.json",
          "docs/audits/eve-sota-trajectory-lock.schema.json",
          "docs/audits/eve-sota-trajectory-results.schema.json",
          "docs/audits/eve-sota-trajectory-report.schema.json",
          "docs/audits/eve-sota-trajectory-performance.schema.json",
          "docs/audits/eve-sota-evidence/phase-12/task-12-4.json",
          "tools/eve-everywhere/trajectory-grading-policy.mjs",
          "tools/eve-everywhere/trajectory-grading-policy.test.mjs",
          "tools/eve-everywhere/grade-trajectory-cohort.mjs",
          "tools/eve-everywhere/generate-trajectory-contract-fixtures.mjs",
          "tools/eve-everywhere/measure-trajectory-grading.mjs",
          "tools/eve-everywhere/verify-trajectory-grading.mjs",
          "tools/eve-everywhere/verify-trajectory-grading.test.mjs",
          "tools/eve-everywhere/run-trajectory-grading-evidence.mjs",
          "tools/eve-everywhere/run-trajectory-grading-evidence.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Add long-horizon trajectory grading: goal completion, unnecessary steps, recovery, repeated error, state drift, premature success, safe abstention, and evidence fidelity. Final-answer quality alone cannot hide unsafe or wasteful trajectories. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.5",
      "phaseId": "12",
      "closureState": "completed",
      "requirement": "Establish eval-data governance: source/licence, privacy/redaction, version/hash, train/tune/graded/held-out separation, contamination checks, freshness/retirement, review ownership, and raw evidence retention.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "privacy-data-rights",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-12-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "privacy-data-rights",
          "governance-decision"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/adr/ADR-0085-eve-eval-data-governance.md",
          "docs/audits/EVE_SOTA_EVAL_DATA_GOVERNANCE_2026-09.md",
          "docs/audits/eve-sota-eval-data-governance.schema.json",
          "docs/audits/eve-sota-eval-data-governance/registry.json",
          "docs/audits/eve-sota-evidence/phase-12/task-12-5.json",
          "tools/eve-everywhere/eval-data-governance-policy.mjs",
          "tools/eve-everywhere/generate-eval-data-governance.mjs",
          "tools/eve-everywhere/admit-eval-dataset.mjs",
          "tools/eve-everywhere/verify-eval-data-governance.mjs",
          "tools/eve-everywhere/verify-eval-data-governance.test.mjs",
          "tools/eve-everywhere/run-eval-data-governance-evidence.mjs",
          "tools/eve-everywhere/run-eval-data-governance-evidence.test.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Establish eval-data governance: source/licence, privacy/redaction, version/hash, train/tune/graded/held-out separation, contamination checks, freshness/retirement, review ownership, and raw evidence retention. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.6",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Add shadow/canary and online outcome feedback linked to offline cases; detect distribution drift without logging raw sensitive content. Human acceptance/correction/undo and downstream verified outcomes outrank thumbs-up alone.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["12.2", "12.4", "12.5"],
      "dependencyRationales": [
        "Consumes independent cohort, grader and statistically feasible sample contracts.",
        "Requires trajectory-level grading of state, efficiency and truthfulness.",
        "Uses held-out-data governance, provenance and contamination controls."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "operational-load-soak",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-12-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "operational-load-soak",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "operational-exercise",
          "measurement",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Add shadow/canary and online outcome feedback linked to offline cases; detect distribution drift without logging raw sensitive content. Human acceptance/correction/undo and downstream verified outcomes outrank thumbs-up alone. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.7",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Release gate consumes the complete family manifest and fails on a missing/stale family, unvalidated grader, absent negative, floor breach, unpriced leg, or high-risk capability without current red-team evidence.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["4.8", "12.1", "12.2", "12.3", "12.4", "12.5"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Uses the complete required-capability and risk taxonomy.",
        "Consumes independent cohort, grader and statistically feasible sample contracts.",
        "Requires real blinded human labels and validated judge classes.",
        "Requires trajectory-level grading of state, efficiency and truthfulness.",
        "Uses held-out-data governance, provenance and contamination controls."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "fault-recovery",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-12-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "fault-recovery",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Release gate consumes the complete family manifest and fails on a missing/stale family, unvalidated grader, absent negative, floor breach, unpriced leg, or high-risk capability without current red-team evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.8",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Implement the charter-completeness gate over the ratified source inventory, actual execution manifests, scorecard results, runtime receipts, independent verification, and human acceptance. Derive task, phase, initiative, and charter status from evidence; accept completion only with zero unresolved blockers and all required targets met. Reject missing/unadmitted workflows, stale sources/evidence, weak proof, incomplete strata, blocked dependencies, unvalidated judges, and any named/accepted/deferred/successor gap. Demonstrate each rejection through the real gate CLI and a green complete fixture without manufacturing production receipts. Gate implementation tests do not prove the charter achieved. Keep capability admission separate from final completion so bootstrap work does not require its own future delivery evidence.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["0.8", "12.2", "12.7"],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Consumes independent cohort, grader and statistically feasible sample contracts.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "fault-recovery",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-12-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "fault-recovery",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Implement the charter-completeness gate over the ratified source inventory, actual execution manifests, scorecard results, runtime receipts, independent verification, and human acceptance. Derive task, phase, initiative, and charter status from evidence; accept completion only with zero unresolved blockers and all required targets met. Reject missing/unadmitted workflows, stale sources/evidence, weak proof, incomplete strata, blocked dependencies, unvalidated judges, and any named/accepted/deferred/successor gap. Demonstrate each rejection through the real gate CLI and a green complete fixture without manufacturing production receipts. Gate implementation tests do not prove the charter achieved. Keep capability admission separate from final completion so bootstrap work does not require its own future delivery evidence. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.9",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Preregister the creative-workflow quality and performance benchmark. Owner: evaluation science; verifier: independent motion designer and architectural reviewer. Depends on 0.3, 12.1, 12.2, and 17.7. Define separate reference-motion, original-motion, reconstruction, and walkthrough families with independent briefs, held-out cases, repeats, minimum sample counts, numeric thresholds, and decision rules. Grade typography, layout, easing/timing, Bezier fidelity, materials, lighting, temporal artifacts, editability, dimensional tolerances, and interaction at their correct boundaries. Calibrate any visual judge with blinded human labels; require humans where calibration is inadequate. Include source-to-delivery labor, revisions, failures, provider/render cost, and latency, using approved measured model routes rather than assuming the video's model label or headline duration establishes parity.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["0.3", "12.1", "12.2", "17.7"],
      "dependencyRationales": [
        "Uses the north-star outcome and decision contract.",
        "Extends the existing task and evaluation family taxonomy.",
        "Reuses independent case sampling and stochastic decision rules.",
        "Measures the required creative workflow outcomes."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "performance-quality",
        "governance-decision",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-12-9",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "performance-quality",
          "governance-decision",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "measurement",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-9.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Preregister the creative-workflow quality and performance benchmark. Owner: evaluation science; verifier: independent motion designer and architectural reviewer. Depends on 0.3, 12.1, 12.2, and 17.7. Define separate reference-motion, original-motion, reconstruction, and walkthrough families with independent briefs, held-out cases, repeats, minimum sample counts, numeric thresholds, and decision rules. Grade typography, layout, easing/timing, Bezier fidelity, materials, lighting, temporal artifacts, editability, dimensional tolerances, and interaction at their correct boundaries. Calibrate any visual judge with blinded human labels; require humans where calibration is inadequate. Include source-to-delivery labor, revisions, failures, provider/render cost, and latency, using approved measured model routes rather than assuming the video's model label or headline duration establishes parity. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.10",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Extend the existing evaluation/charter gates for these creative families. Owner: evaluation platform; verifier: release QA. Depends on 12.7, 12.8, and 12.9. Register required cases, native artifact/readback evidence, model/runtime/source pins, quality thresholds, and human decisions without creating a second release authority. Reject missing families, test-provider evidence presented as live, stale hosts/sources, compressed-file false failures, fake or unopenable projects, uncalibrated scores, absent required labels, partial jobs marked complete, and hidden failed attempts/costs. Prove these rejection rules with focused fixtures; implementing the gate does not require or claim that later capstones already pass, avoiding circular runtime admission dependencies.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["12.7", "12.8", "12.9"],
      "dependencyRationales": [
        "Extends the existing applicable-family release gate.",
        "Extends the charter completeness evidence join.",
        "Uses explicit creative family thresholds and evidence boundaries."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-12-10",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-10.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Extend the existing evaluation/charter gates for these creative families. Owner: evaluation platform; verifier: release QA. Depends on 12.7, 12.8, and 12.9. Register required cases, native artifact/readback evidence, model/runtime/source pins, quality thresholds, and human decisions without creating a second release authority. Reject missing families, test-provider evidence presented as live, stale hosts/sources, compressed-file false failures, fake or unopenable projects, uncalibrated scores, absent required labels, partial jobs marked complete, and hidden failed attempts/costs. Prove these rejection rules with focused fixtures; implementing the gate does not require or claim that later capstones already pass, avoiding circular runtime admission dependencies. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "12.11",
      "phaseId": "12",
      "closureState": "open",
      "requirement": "Preregister the chat-surface parity and generated-media evaluation family. Owner: evaluation science; verifier: charter QA. Depends on 8.12, 12.1, and 12.2. Define independent cases for attachment understanding, rendering fidelity, artifact edit fidelity, turn controls, conversation management, generation quality per modality, accessibility, cost and latency per verified outcome, and failure honesty; include paired representative tasks against ChatGPT and Claude.ai where executable access exists and record inaccessible comparisons honestly. Non-vacuous negative controls per case class.",
      "gapRefs": ["G7", "G14"],
      "dependencyTaskIds": ["8.12", "12.1", "12.2"],
      "dependencyRationales": [
        "Consumes the ratified per-surface parity register.",
        "Uses the expanded task/eval taxonomy covering UX, multimodal and cost.",
        "Uses the case diversity and stochastic-run rules."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "performance-quality",
        "governance-decision",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-12-11",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "performance-quality",
          "governance-decision",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "measurement",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-12/task-12-11.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Preregister the chat-surface parity and generated-media evaluation family. Owner: evaluation science; verifier: charter QA. Depends on 8.12, 12.1, and 12.2. Define independent cases for attachment understanding, rendering fidelity, artifact edit fidelity, turn controls, conversation management, generation quality per modality, accessibility, cost and latency per verified outcome, and failure honesty; include paired representative tasks against ChatGPT and Claude.ai where executable access exists and record inaccessible comparisons honestly. Non-vacuous negative controls per case class. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.1",
      "phaseId": "13",
      "closureState": "completed",
      "requirement": "Define per-plane SLIs/SLOs and error budgets: availability, TTFT and total latency, tool/task completion, cancel/kill latency, duplicate/late action, queue age, recovery, grounding, provider errors, cost, and data- boundary violations. Every alert has owner, severity, runbook, and safe degraded mode.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["0.3"],
      "dependencyRationales": ["Consumes the preregistered outcome thresholds and decision rules."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-13-1",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0086-eve-per-plane-reliability-objectives.md",
          "docs/audits/EVE_SOTA_RELIABILITY_SLO_CONTRACT_2026-09.md",
          "docs/audits/eve-sota-reliability-slo.schema.json",
          "docs/audits/eve-sota-reliability-slo/2026-09-14.json",
          "docs/audits/eve-sota-evidence/phase-13/task-13-1.json",
          "docs/operations/slos.md",
          "tools/eve-everywhere/generate-reliability-slo-contract.mjs",
          "tools/eve-everywhere/verify-reliability-slo-contract.mjs",
          "tools/eve-everywhere/verify-reliability-slo-contract.test.mjs",
          "tools/eve-everywhere/run-reliability-slo-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Define per-plane SLIs/SLOs and error budgets: availability, TTFT and total latency, tool/task completion, cancel/kill latency, duplicate/late action, queue age, recovery, grounding, provider errors, cost, and data- boundary violations. Every alert has owner, severity, runbook, and safe degraded mode. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.2",
      "phaseId": "13",
      "closureState": "completed",
      "requirement": "Propagate one trace/correlation context across invocation, session/ turn, router/model, tool/client-tool, MCP/A2A, confirmation, ledger, queue/lease/agent, watcher/channel, and artifact verification. Align to a pinned OpenTelemetry convention where useful; never put prompts, secrets, or sensitive payloads into default telemetry.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["13.1"],
      "dependencyRationales": ["Uses the fixed per-plane SLO, RTO, budget and alert contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "protocol-interop",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-13-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "protocol-interop",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0087-eve-trace-correlation-continuity.md",
          "docs/audits/eve-sota-evidence/phase-13/task-13-2.json",
          "libs/shared/tracing/src/eve-context.ts",
          "libs/shared/tracing/src/eve-context.spec.ts",
          "apps/oshun/bff/src/assistant/eve-trace-flow.ts",
          "apps/oshun/bff/src/workbench/work-queue.integration.spec.ts",
          "libs/oshun/skill-system/src/mcp.ts",
          "libs/oshun/ai-platform/src/agents.ts",
          "libs/oshun/assistant/src/watchers/watcher-engine.ts",
          "libs/oshun/messaging-channels/src/delivery.ts",
          "tools/eve-everywhere/verify-trace-context-propagation.ts",
          "tools/eve-everywhere/run-trace-context-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Propagate one trace/correlation context across invocation, session/ turn, router/model, tool/client-tool, MCP/A2A, confirmation, ledger, queue/lease/agent, watcher/channel, and artifact verification. Align to a pinned OpenTelemetry convention where useful; never put prompts, secrets, or sensitive payloads into default telemetry. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.3",
      "phaseId": "13",
      "closureState": "completed",
      "requirement": "Standardize deadline, timeout, bounded retry/backoff/jitter, circuit breaker, backpressure, concurrency, idempotency/fencing, cancellation, and resumability by operation class. A client disconnect must not create an unobservable side effect.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["13.1"],
      "dependencyRationales": ["Uses the fixed per-plane SLO, RTO, budget and alert contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-13-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0088-eve-operation-class-reliability-policy.md",
          "docs/audits/eve-sota-evidence/phase-13/task-13-3.json",
          "libs/shared/resilience/src/eve-operation-policy.ts",
          "libs/shared/resilience/src/eve-operation-policy.spec.ts",
          "apps/oshun/bff/src/assistant/action-confirm.ts",
          "apps/oshun/bff/src/workbench/queue-semantics.ts",
          "apps/oshun/bff/src/workbench/work-queue.ts",
          "apps/oshun/bff/src/workbench/intent-store.ts",
          "apps/oshun/bff/src/workbench/work-queue.integration.spec.ts",
          "apps/oshun/bff/src/workbench/queue-semantics.integration.spec.ts",
          "libs/oshun/assistant/src/watchers/watcher-engine.ts",
          "apps/oshun/bff/src/workbench/artifact-verifier.ts",
          "tools/eve-everywhere/verify-operation-reliability-policy.ts",
          "tools/eve-everywhere/run-operation-reliability-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Standardize deadline, timeout, bounded retry/backoff/jitter, circuit breaker, backpressure, concurrency, idempotency/fencing, cancellation, and resumability by operation class. A client disconnect must not create an unobservable side effect. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.4",
      "phaseId": "13",
      "closureState": "completed",
      "requirement": "Load/soak and resource tests cover realistic concurrent streams, tool calls, queues, vector search, watchers, and long jobs within host safety limits. Report p50/p95/p99, error/timeout/duplicate rates, memory/ CPU, and cost; test one expensive surface at a time on constrained hosts.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["13.2", "13.3"],
      "dependencyRationales": [
        "Consumes attributed end-to-end trace/correlation records.",
        "Exercises bounded retry, fencing, backpressure and cancellation semantics."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "persistence-recovery",
        "real-model-provider",
        "real-database",
        "real-vector-store",
        "operational-load-soak",
        "fault-recovery",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-13-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "persistence-recovery",
          "real-model-provider",
          "real-database",
          "real-vector-store",
          "operational-load-soak",
          "fault-recovery",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "measurement"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_LOAD_SOAK_REPORT_2026-09.md",
          "docs/audits/eve-sota-load-soak/contract.v1.json",
          "docs/audits/eve-sota-load-soak/2026-09-14-attempt-04.json",
          "docs/audits/eve-sota-load-soak/2026-09-14-vector-lifecycle-01.json",
          "docs/audits/eve-sota-load-soak/2026-09-14-long-job-recovery-01.json",
          "docs/audits/eve-sota-evidence/phase-13/task-13-4.json",
          "tools/eve-everywhere/run-load-soak.ts",
          "tools/eve-everywhere/verify-load-soak.mjs",
          "tools/eve-everywhere/verify-load-soak.test.mjs",
          "tools/eve-everywhere/run-vector-lifecycle-proof.ts",
          "tools/eve-everywhere/verify-vector-lifecycle.mjs",
          "tools/eve-everywhere/run-long-job-recovery-proof.ts",
          "tools/eve-everywhere/verify-long-job-recovery.mjs",
          "tools/eve-everywhere/run-load-soak-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Load/soak and resource tests cover realistic concurrent streams, tool calls, queues, vector search, watchers, and long jobs within host safety limits. Report p50/p95/p99, error/timeout/duplicate rates, memory/ CPU, and cost; test one expensive surface at a time on constrained hosts. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.5",
      "phaseId": "13",
      "closureState": "open",
      "requirement": "Fault/chaos matrix: provider/endpoint loss, malformed stream, DB/ Redis/vector/MCP/browser/DCC/channel outage, network partition, process crash, lease expiry, telemetry blindness, clock skew, disk pressure, and partial artifact. Verify safe fallback, no false success, and recovery.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["13.2", "13.3"],
      "dependencyRationales": [
        "Consumes attributed end-to-end trace/correlation records.",
        "Exercises bounded retry, fencing, backpressure and cancellation semantics."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-model-provider",
        "real-database",
        "real-vector-store",
        "real-browser-ui",
        "real-dcc-runtime",
        "external-channel-runtime",
        "protocol-interop",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-13-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-model-provider",
          "real-database",
          "real-vector-store",
          "real-browser-ui",
          "real-dcc-runtime",
          "external-channel-runtime",
          "protocol-interop",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Fault/chaos matrix: provider/endpoint loss, malformed stream, DB/ Redis/vector/MCP/browser/DCC/channel outage, network partition, process crash, lease expiry, telemetry blindness, clock skew, disk pressure, and partial artifact. Verify safe fallback, no false success, and recovery. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.6",
      "phaseId": "13",
      "closureState": "completed",
      "requirement": "Backup/restore and migration proof for conversations, memory, vectors/index metadata, workbench/ledger, schedules/watchers, task state, audit, and evidence manifests. Set and test RPO/RTO; deletion/tombstones remain honored after restore.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["13.1"],
      "dependencyRationales": ["Uses the fixed per-plane SLO, RTO, budget and alert contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-database",
        "real-vector-store",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-13-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-database",
          "real-vector-store",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_BACKUP_RECOVERY_PROOF_2026-09.md",
          "docs/audits/eve-backup-recovery/2026-09-15-05.json",
          "docs/audits/eve-sota-evidence/phase-13/task-13-6.json",
          "libs/shared/resilience/src/eve-backup-recovery.ts",
          "libs/shared/resilience/src/eve-backup-recovery.spec.ts",
          "apps/oshun/bff/src/data-deletion/recovery-deletion-journal.ts",
          "apps/oshun/bff/src/workbench/intent-store.ts",
          "apps/oshun/bff/src/workbench/workbench-adjacent-subject-erasure.integration.spec.ts",
          "libs/oshun/workbench-kit/src/subject-data-map.ts",
          "libs/oshun/workbench-kit/src/subject-erasure.ts",
          "libs/oshun/persistence/prisma/migrations/20260915020000_workbench_fleet_subject_erasure/migration.sql",
          "libs/oshun/persistence/prisma/migrations/20260915030000_workbench_fleet_tombstone_invariant/migration.sql",
          "libs/oshun/persistence/prisma/deploy.config.ts",
          "infra/hetzner/scripts/deploy.sh",
          "infra/hetzner/README.md",
          ".github/workflows/deploy-hetzner.yml",
          "scripts/operations/v1-prisma-deploy-path.test.mjs",
          "tools/eve-everywhere/run-backup-recovery-evidence.mts",
          "tools/eve-everywhere/verify-backup-recovery.mts"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Backup/restore and migration proof for conversations, memory, vectors/index metadata, workbench/ledger, schedules/watchers, task state, audit, and evidence manifests. Set and test RPO/RTO; deletion/tombstones remain honored after restore. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "13.7",
      "phaseId": "13",
      "closureState": "open",
      "requirement": "Dashboards, alerts, runbooks, and a supervised game day demonstrate detect→triage→kill/rollback→recover→verify. File sanitized evidence and add every discovered failure to the relevant eval family.",
      "gapRefs": ["G13"],
      "dependencyTaskIds": ["13.1", "13.2", "13.3", "13.4", "13.5", "13.6"],
      "dependencyRationales": [
        "Uses the fixed per-plane SLO, RTO, budget and alert contract.",
        "Consumes attributed end-to-end trace/correlation records.",
        "Exercises bounded retry, fencing, backpressure and cancellation semantics.",
        "Requires resource-safe realistic load and soak evidence.",
        "Requires observed dependency/crash/resource fault recovery.",
        "Requires actual backup/restore, migration and deletion-preserving recovery proof."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "operational-load-soak",
        "fault-recovery",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-13-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "operational-load-soak",
          "fault-recovery",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "operational-exercise",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-13/task-13-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Dashboards, alerts, runbooks, and a supervised game day demonstrate detect→triage→kill/rollback→recover→verify. File sanitized evidence and add every discovered failure to the relevant eval family. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.1",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Build an end-to-end data inventory/flow map by plane and modality: source, purpose, actor/tenant, classification, prompt/provider transfer, storage/cache/vector/trace/artifact/channel destinations, retention, deletion path, and owner.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "privacy-data-rights"],
      "evidencePlan": {
        "id": "evidence-14-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "privacy-data-rights"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_DATA_FLOW_INVENTORY_2026-09.md",
          "docs/audits/eve-sota-data-flow-inventory/2026-09-15.json",
          "docs/audits/eve-sota-data-flow-inventory.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-1.json",
          "tools/eve-everywhere/generate-data-flow-inventory.mjs",
          "tools/eve-everywhere/verify-data-flow-inventory.mjs",
          "tools/eve-everywhere/verify-data-flow-inventory.test.mjs",
          "tools/eve-everywhere/run-data-flow-inventory-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Build an end-to-end data inventory/flow map by plane and modality: source, purpose, actor/tenant, classification, prompt/provider transfer, storage/cache/vector/trace/artifact/channel destinations, retention, deletion path, and owner. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.2",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Provider and subprocess review: training/retention settings, residency, subprocessors, encryption, access, model/tool data use, and incident terms for every text/vision/embedding/reranker/voice/channel route. A cheaper route cannot promote by violating the data posture.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["14.1"],
      "dependencyRationales": ["Uses the complete source-to-destination data inventory."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "privacy-data-rights",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-14-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "privacy-data-rights",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_PROVIDER_SUBPROCESSOR_REVIEW_2026-09.md",
          "docs/audits/eve-sota-provider-subprocessor-review/2026-09-15.json",
          "docs/audits/eve-sota-provider-subprocessor-review.schema.json",
          "docs/audits/eve-sota-provider-subprocessor-review/live-posture-probe-2026-09-15.json",
          "docs/audits/eve-sota-provider-subprocessor-review/production-route-census.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-2.json",
          "tools/eve-everywhere/generate-provider-subprocessor-review.mjs",
          "tools/eve-everywhere/probe-provider-route-posture.mjs",
          "tools/eve-everywhere/verify-provider-subprocessor-review.mjs",
          "tools/eve-everywhere/verify-provider-subprocessor-review.test.mjs",
          "tools/eve-everywhere/run-provider-subprocessor-review-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Provider and subprocess review: training/retention settings, residency, subprocessors, encryption, access, model/tool data use, and incident terms for every text/vision/embedding/reranker/voice/channel route. A cheaper route cannot promote by violating the data posture. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.3",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Enforce minimization/redaction/secret and sensitive-data detection at ingress, prompt assembly, tool result, trace/log, screenshot/audio/video, artifact, eval evidence, and egress. Test structured, encoded, image/OCR, archive, and cross-tool exfiltration paths.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["14.1"],
      "dependencyRationales": ["Uses the complete source-to-destination data inventory."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-multimodal-runtime",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-14-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-multimodal-runtime",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_SENSITIVE_DATA_BOUNDARIES_2026-09.md",
          "docs/audits/eve-sota-sensitive-data-boundaries/2026-09-15.json",
          "docs/audits/eve-sota-sensitive-data-boundaries.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-3.json",
          "libs/oshun/privacy/src/data-boundary/sensitive-data-guard.ts",
          "libs/oshun/privacy/src/data-boundary/sensitive-data-guard.spec.ts",
          "tools/eve-everywhere/verify-sensitive-data-boundaries.mjs",
          "tools/eve-everywhere/verify-sensitive-data-boundaries.test.mjs",
          "tools/eve-everywhere/run-sensitive-data-boundary-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Enforce minimization/redaction/secret and sensitive-data detection at ingress, prompt assembly, tool result, trace/log, screenshot/audio/video, artifact, eval evidence, and egress. Test structured, encoded, image/OCR, archive, and cross-tool exfiltration paths. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.4",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Data-rights propagation covers conversations, operator/semantic memory, vector indexes, tool caches, screenshots/recordings, DCC artifacts, schedules/watchers, notifications, channels, traces, eval datasets, and backups. Verify deletion, export, legal hold/conflict, and no resurrection.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["3.3", "9.2", "14.1"],
      "dependencyRationales": [
        "Uses the versioned ACL-bearing dense index and deletion metadata.",
        "Requires operator data inspection, correction and deletion controls.",
        "Uses the complete source-to-destination data inventory."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "real-database",
        "real-vector-store",
        "fault-recovery",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-14-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "real-database",
          "real-vector-store",
          "fault-recovery",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_DATA_RIGHTS_PROPAGATION_2026-09.md",
          "docs/audits/eve-sota-data-rights-propagation/2026-09-15.json",
          "docs/audits/eve-sota-data-rights-propagation.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-4.json",
          "apps/oshun/bff/src/data-deletion/legal-hold-gate.ts",
          "apps/oshun/bff/src/data-deletion/legal-hold-gate.spec.ts",
          "apps/oshun/bff/src/personalization/personalization-vector-index.integration.spec.ts",
          "tools/eve-everywhere/verify-data-rights-propagation.mjs",
          "tools/eve-everywhere/verify-data-rights-propagation.test.mjs",
          "tools/eve-everywhere/run-data-rights-propagation-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Data-rights propagation covers conversations, operator/semantic memory, vector indexes, tool caches, screenshots/recordings, DCC artifacts, schedules/watchers, notifications, channels, traces, eval datasets, and backups. Verify deletion, export, legal hold/conflict, and no resurrection. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.5",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Set retention and access policies with operator-visible disclosure and audited admin access. Make audit records tamper-evident or document the compensating control; audit must not become a sensitive shadow store.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["14.1"],
      "dependencyRationales": ["Uses the complete source-to-destination data inventory."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-14-5",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_RETENTION_ACCESS_POLICY_2026-09.md",
          "docs/audits/eve-sota-retention-access-policy/2026-09-15.json",
          "docs/audits/eve-sota-retention-access-policy.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-5.json",
          "apps/oshun/bff/src/admin/admin-audit-governance.ts",
          "apps/oshun/bff/src/admin/admin-audit-events-store.ts",
          "apps/oshun/bff/src/routes/admin-audit-log.ts",
          "libs/oshun/persistence/src/durable-admin-audit-events-store.ts",
          "tools/eve-everywhere/verify-retention-access-policy.mjs",
          "tools/eve-everywhere/verify-retention-access-policy.test.mjs",
          "tools/eve-everywhere/run-retention-access-policy-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-5.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Set retention and access policies with operator-visible disclosure and audited admin access. Make audit records tamper-evident or document the compensating control; audit must not become a sensitive shadow store. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.6",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Write a jurisdiction/applicability and human-oversight record with counsel/operator-owned decisions where required. Map obligations to controls/evidence without claiming legal compliance from engineering tests.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["14.1", "14.2"],
      "dependencyRationales": [
        "Uses the complete source-to-destination data inventory.",
        "Requires the reviewed provider transfer, retention and subprocess posture."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "privacy-data-rights",
        "governance-decision",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-14-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "privacy-data-rights",
          "governance-decision",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_JURISDICTION_HUMAN_OVERSIGHT_2026-09.md",
          "docs/audits/eve-sota-jurisdiction-human-oversight/2026-09-15.json",
          "docs/audits/eve-sota-jurisdiction-human-oversight.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-6.json",
          "apps/oshun/bff/src/workbench/queue-semantics.integration.spec.ts",
          "tools/eve-everywhere/verify-jurisdiction-human-oversight.mjs",
          "tools/eve-everywhere/verify-jurisdiction-human-oversight.test.mjs",
          "tools/eve-everywhere/run-jurisdiction-human-oversight-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Write a jurisdiction/applicability and human-oversight record with counsel/operator-owned decisions where required. Map obligations to controls/evidence without claiming legal compliance from engineering tests. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.7",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Media/project-file governance covers source licence, attribution, consent/likeness, generated-media disclosure/provenance, redistribution, and training restrictions before Eve produces or publishes creative work.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["14.1", "14.2", "14.3", "14.4", "14.5", "14.6"],
      "dependencyRationales": [
        "Uses the complete source-to-destination data inventory.",
        "Requires the reviewed provider transfer, retention and subprocess posture.",
        "Requires minimization and sensitive-data/exfiltration controls.",
        "Requires deletion/export propagation through actual data stores and backups.",
        "Requires retention, disclosure and audited access policy.",
        "Requires applicable human-owned legal and oversight decisions."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "privacy-data-rights",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-14-7",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "privacy-data-rights",
          "governance-decision"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_MEDIA_PROJECT_GOVERNANCE_2026-09.md",
          "docs/audits/eve-sota-media-project-governance/2026-09-15.json",
          "docs/audits/eve-sota-media-project-governance.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-7.json",
          "libs/contracts/src/common/artifact-rights.ts",
          "apps/oshun/bff/src/agentic/autonomy-bindings/artifact-rights-provider.ts",
          "apps/oshun/bff/src/agentic/autonomy-bindings/generation-producer.ts",
          "libs/oshun/generation-control-isis/src/release-gate-model.ts",
          "tools/eve-everywhere/verify-media-project-governance.mjs",
          "tools/eve-everywhere/verify-media-project-governance.test.mjs",
          "tools/eve-everywhere/run-media-project-governance-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-7.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Media/project-file governance covers source licence, attribution, consent/likeness, generated-media disclosure/provenance, redistribution, and training restrictions before Eve produces or publishes creative work. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "14.8",
      "phaseId": "14",
      "closureState": "completed",
      "requirement": "Govern the attachment and generated-artifact lifecycle. Owner: privacy engineering; verifier: privacy/legal QA. Depends on 14.1, 14.3, 14.4, and 14.5. Classify uploaded attachments, artifacts, generated media, shares, and exports by plane and sensitivity; enforce scanning, minimization, provider-transfer review, retention, access policy for permalinks, deletion propagation to storage, memory, traces, and backups, and data-subject export. Prove that a deleted session leaves no attachment, artifact, or generated file behind.",
      "gapRefs": ["G16"],
      "dependencyTaskIds": ["14.1", "14.3", "14.4", "14.5"],
      "dependencyRationales": [
        "Uses the complete source-to-destination data inventory.",
        "Requires minimization and sensitive-data/exfiltration controls.",
        "Requires deletion/export propagation through actual data stores and backups.",
        "Requires retention, disclosure and audited access policy."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "persistence-recovery",
        "authorization-isolation",
        "privacy-data-rights",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-14-8",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "persistence-recovery",
          "authorization-isolation",
          "privacy-data-rights",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_ATTACHMENT_ARTIFACT_LIFECYCLE_2026-09.md",
          "docs/audits/eve-sota-attachment-artifact-lifecycle/2026-09-16.json",
          "docs/audits/eve-sota-attachment-artifact-lifecycle.schema.json",
          "docs/audits/eve-sota-evidence/phase-14/task-14-8.json",
          "apps/oshun/bff/src/media-lifecycle/session-media-lifecycle.ts",
          "apps/oshun/bff/src/generation/human-video-upload-session.ts",
          "apps/oshun/bff/src/generation/human-video-upload-scan.ts",
          "apps/oshun/bff/src/generation/generated-artifact-object-store.ts",
          "apps/oshun/bff/src/generation/generated-artifact-erasure.ts",
          "apps/oshun/bff/src/data-export/bundle-builder.ts",
          "tools/eve-everywhere/verify-attachment-artifact-lifecycle.mjs",
          "tools/eve-everywhere/verify-attachment-artifact-lifecycle.test.mjs",
          "tools/eve-everywhere/run-attachment-artifact-lifecycle-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-14/task-14-8.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Govern the attachment and generated-artifact lifecycle. Owner: privacy engineering; verifier: privacy/legal QA. Depends on 14.1, 14.3, 14.4, and 14.5. Classify uploaded attachments, artifacts, generated media, shares, and exports by plane and sensitivity; enforce scanning, minimization, provider-transfer review, retention, access policy for permalinks, deletion propagation to storage, memory, traces, and backups, and data-subject export. Prove that a deleted session leaves no attachment, artifact, or generated file behind. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.1",
      "phaseId": "15",
      "closureState": "completed",
      "requirement": "Every model leg (turn, escalation, judge, embedding, reranker, vision, speech, media/planner if admitted) has a capability contract, bound/fail- loud status, dated model/endpoint/quantization, price and data posture, context/structured/tool support, chosenBy evidence, override, and rollback.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "service-integration",
        "real-model-provider",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-15-1",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "service-integration",
          "real-model-provider",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/model-registry.ts",
          "apps/oshun/bff/src/assistant/model-registry.spec.ts",
          "apps/oshun/bff/src/assistant/model-leg-inventory.ts",
          "apps/oshun/bff/src/assistant/model-leg-inventory.spec.ts",
          "apps/oshun/bff/src/assistant/voice-config.ts",
          "tools/eve-everywhere/probe-model-leg-contract.mjs",
          "docs/audits/eve-sota-model-leg-contract/2026-09-05.json",
          "docs/audits/eve-sota-model-leg-contract/2026-09-05.probe.json",
          "docs/audits/eve-sota-model-leg-contract.schema.json",
          "docs/audits/EVE_SOTA_MODEL_LEG_CONTRACT_2026-09.md",
          "docs/audits/eve-sota-evidence/phase-15/task-15-1.json"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Every model leg (turn, escalation, judge, embedding, reranker, vision, speech, media/planner if admitted) has a capability contract, bound/fail- loud status, dated model/endpoint/quantization, price and data posture, context/structured/tool support, chosenBy evidence, override, and rollback. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.2",
      "phaseId": "15",
      "closureState": "completed",
      "requirement": "Provider/route resilience distinguishes endpoint failover, model fallback, and deterministic degraded behavior. Paired fault tests prove a fallback preserves safety/tool contracts or refuses; it never silently downgrades into fabricated capability.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["15.1"],
      "dependencyRationales": [
        "Consumes priced, capability-correct, fail-loud model registry bindings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-15-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/provider-route-resilience.ts",
          "apps/oshun/bff/src/assistant/provider-route-resilience.spec.ts",
          "apps/oshun/bff/src/assistant/agent-provider-config.ts",
          "apps/oshun/bff/src/routes/assistant.ts",
          "libs/shared/ai/src/providers/openai.ts",
          "libs/shared/ai/src/providers/openrouter-route-resilience.spec.ts",
          "apps/oshun/mobile/src/assistant/mobileAssistantTransportPolicy.ts",
          "docs/audits/EVE_SOTA_PROVIDER_ROUTE_RESILIENCE_2026-09.md",
          "docs/audits/eve-sota-provider-route-resilience/2026-09-16.json",
          "docs/audits/eve-sota-provider-route-resilience/2026-09-16.live.probe.json",
          "docs/audits/eve-sota-provider-route-resilience.schema.json",
          "docs/audits/eve-sota-evidence/phase-15/task-15-2.json",
          "tools/eve-everywhere/probe-provider-route-resilience.mjs",
          "tools/eve-everywhere/verify-provider-route-resilience.mjs",
          "tools/eve-everywhere/verify-provider-route-resilience.test.mjs",
          "tools/eve-everywhere/run-provider-route-resilience-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Provider/route resilience distinguishes endpoint failover, model fallback, and deterministic degraded behavior. Paired fault tests prove a fallback preserves safety/tool contracts or refuses; it never silently downgrades into fabricated capability. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.3",
      "phaseId": "15",
      "closureState": "completed",
      "requirement": "Long-context/context-compaction evaluation covers instruction loss, authority/trust-label loss, citation/provenance loss, stale memory, conflicting state, tool-result truncation, and recovery across long agent trajectories.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["15.1"],
      "dependencyRationales": [
        "Consumes priced, capability-correct, fail-loud model registry bindings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-model-provider",
        "fault-recovery",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-15-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-model-provider",
          "fault-recovery",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/agent-tools.ts",
          "apps/oshun/bff/src/assistant/history-compaction.ts",
          "apps/oshun/bff/src/assistant/history-compaction.spec.ts",
          "apps/oshun/bff/src/assistant/tool-result-digest.ts",
          "apps/oshun/bff/src/assistant/tool-result-digest.spec.ts",
          "apps/oshun/bff/src/assistant/evals/long-context-compaction-evaluation.ts",
          "apps/oshun/bff/src/assistant/evals/long-context-compaction-evaluation.spec.ts",
          "apps/oshun/bff/src/assistant/security/trust-labels.ts",
          "apps/oshun/bff/src/routes/assistant.ts",
          "docs/audits/EVE_SOTA_LONG_CONTEXT_COMPACTION_2026-09.md",
          "docs/audits/eve-sota-long-context-compaction/2026-09-16.json",
          "docs/audits/eve-sota-long-context-compaction/2026-09-16.live.probe.json",
          "docs/audits/eve-sota-long-context-compaction.schema.json",
          "docs/audits/eve-sota-evidence/phase-15/task-15-3.json",
          "tools/eve-everywhere/capture-long-context-compaction-evaluation.ts",
          "tools/eve-everywhere/probe-long-context-compaction.mjs",
          "tools/eve-everywhere/verify-long-context-compaction.mjs",
          "tools/eve-everywhere/verify-long-context-compaction.test.mjs",
          "tools/eve-everywhere/run-long-context-compaction-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Long-context/context-compaction evaluation covers instruction loss, authority/trust-label loss, citation/provenance loss, stale memory, conflicting state, tool-result truncation, and recovery across long agent trajectories. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.4",
      "phaseId": "15",
      "closureState": "completed",
      "requirement": "Measure TTFT/total latency, tokens/cache, tool iterations, provider errors, energy/resource proxy where available, and billed cost per **verified outcome** by family. Optimize only without breaching outcome, safety, privacy, accessibility, or reliability floors.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["15.1"],
      "dependencyRationales": [
        "Consumes priced, capability-correct, fail-loud model registry bindings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "privacy-data-rights",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-15-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "privacy-data-rights",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/audits/EVE_SOTA_VERIFIED_OUTCOME_EFFICIENCY_2026-09.md",
          "docs/audits/eve-sota-verified-outcome-efficiency/2026-09-16.json",
          "docs/audits/eve-sota-verified-outcome-efficiency.schema.json",
          "docs/audits/eve-sota-load-soak/2026-09-14-attempt-04.json",
          "docs/audits/eve-sota-load-soak/contract.v1.json",
          "docs/audits/eve-sota-evidence/phase-13/task-13-4.json",
          "docs/audits/eve-sota-evidence/phase-15/task-15-4.json",
          "tools/eve-everywhere/generate-verified-outcome-efficiency.mjs",
          "tools/eve-everywhere/verify-verified-outcome-efficiency.mjs",
          "tools/eve-everywhere/verify-verified-outcome-efficiency.test.mjs",
          "tools/eve-everywhere/run-verified-outcome-efficiency-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Measure TTFT/total latency, tokens/cache, tool iterations, provider errors, energy/resource proxy where available, and billed cost per **verified outcome** by family. Optimize only without breaching outcome, safety, privacy, accessibility, or reliability floors. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.5",
      "phaseId": "15",
      "closureState": "open",
      "requirement": "Champion/challenger canary, drift/demotion, endpoint quarantine, prompt/tool-schema compatibility, registry migration, and instant rollback are automated and linked to the scorecard/weekly loop.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["15.2", "15.3", "15.4"],
      "dependencyRationales": [
        "Requires measured fallback and endpoint-failover contract preservation.",
        "Requires long-context authority, provenance and state-retention evidence.",
        "Uses billed cost and latency per independently verified outcome."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "real-model-provider",
        "fault-recovery",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-15-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "real-model-provider",
          "fault-recovery",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Champion/challenger canary, drift/demotion, endpoint quarantine, prompt/tool-schema compatibility, registry migration, and instant rollback are automated and linked to the scorecard/weekly loop. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.6",
      "phaseId": "15",
      "closureState": "completed",
      "requirement": "Capacity/denial-of-wallet tests enforce per-turn/task/session/operator/ tenant/fleet/watcher/channel budgets, bounded parallelism, rate limits, queue backpressure, and intelligible recovery/reset times.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["15.1", "15.2", "15.3", "15.4"],
      "dependencyRationales": [
        "Consumes priced, capability-correct, fail-loud model registry bindings.",
        "Requires measured fallback and endpoint-failover contract preservation.",
        "Requires long-context authority, provenance and state-retention evidence.",
        "Uses billed cost and latency per independently verified outcome."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "fault-recovery",
        "security-adversarial",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-15-6",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "fault-recovery",
          "security-adversarial",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "security-exercise",
          "measurement"
        ],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/capacity-budget.ts",
          "apps/oshun/bff/src/assistant/capacity-budget.spec.ts",
          "apps/oshun/bff/src/assistant/capacity-budget.redis.integration.spec.ts",
          "docs/audits/EVE_SOTA_CAPACITY_DENIAL_OF_WALLET_2026-09.md",
          "docs/audits/eve-sota-capacity-budget.schema.json",
          "docs/audits/eve-sota-capacity-budget/2026-09-16.json",
          "docs/audits/eve-sota-evidence/phase-15/task-15-6.json",
          "tools/eve-everywhere/verify-capacity-budget.mjs",
          "tools/eve-everywhere/verify-capacity-budget.test.mjs",
          "tools/eve-everywhere/run-capacity-budget-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-6.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Capacity/denial-of-wallet tests enforce per-turn/task/session/operator/ tenant/fleet/watcher/channel budgets, bounded parallelism, rate limits, queue backpressure, and intelligible recovery/reset times. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "15.7",
      "phaseId": "15",
      "closureState": "open",
      "requirement": "Admit the generation model legs. Owner: model registry; verifier: cost/route QA. Depends on 15.1 and 15.2. Add image, video, music/audio, and 3D generation legs with capability contracts, priced dated endpoints, data posture, failover, canary/rollback, budget ceilings, and fail-loud not-configured states through the existing registry control; measure cost and latency per verified output before any chat admission. A leg omitted from the registry remains not admitted.",
      "gapRefs": ["G18"],
      "dependencyTaskIds": ["15.1", "15.2"],
      "dependencyRationales": [
        "Consumes priced, capability-correct, fail-loud model registry bindings.",
        "Uses the provider/route resilience policy."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-15-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-15/task-15-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Admit the generation model legs. Owner: model registry; verifier: cost/route QA. Depends on 15.1 and 15.2. Add image, video, music/audio, and 3D generation legs with capability contracts, priced dated endpoints, data posture, failover, canary/rollback, budget ceilings, and fail-loud not-configured states through the existing registry control; measure cost and latency per verified output before any chat admission. A leg omitted from the registry remains not admitted. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "16.1",
      "phaseId": "16",
      "closureState": "completed",
      "requirement": "Inventory in-house turn events against the current AG-UI lifecycle, text/tool/state/snapshot/interrupt/cancel/resume/error vocabulary. ADR: adopt, provide a versioned compatibility adapter, or consciously remain bespoke with measured cost; do not rename events for compliance theater.",
      "gapRefs": ["G17"],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
      "evidencePlan": {
        "id": "evidence-16-1",
        "state": "available-direct",
        "proofScopeRefs": ["source-inspection", "static-contract", "governance-decision"],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [
          "apps/oshun/bff/src/assistant/turn-event-protocol.ts",
          "apps/oshun/bff/src/assistant/turn-event-protocol.spec.ts",
          "docs/adr/ADR-0089-eve-ag-ui-compatibility-decision.md",
          "docs/audits/eve-sota-ag-ui-turn-events.schema.json",
          "docs/audits/eve-sota-ag-ui-turn-events/2026-09-16.json",
          "docs/audits/eve-sota-evidence/phase-16/task-16-1.json",
          "tools/eve-everywhere/verify-ag-ui-turn-events.mjs",
          "tools/eve-everywhere/verify-ag-ui-turn-events.test.mjs",
          "tools/eve-everywhere/run-ag-ui-turn-events-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-16/task-16-1.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "Inventory in-house turn events against the current AG-UI lifecycle, text/tool/state/snapshot/interrupt/cancel/resume/error vocabulary. ADR: adopt, provide a versioned compatibility adapter, or consciously remain bespoke with measured cost; do not rename events for compliance theater. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "16.2",
      "phaseId": "16",
      "closureState": "completed",
      "requirement": "MCP current-version conformance matrix for each stdio/HTTP client and server: initialize/capability negotiation, schema validation, progress, cancellation, tasks, errors, logging, roots, sampling/elicitation policy, protocol-version mismatch, and transport lifecycle.",
      "gapRefs": ["G17"],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "protocol-interop",
        "fault-recovery"
      ],
      "evidencePlan": {
        "id": "evidence-16-2",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "protocol-interop",
          "fault-recovery"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime"
        ],
        "artifactLocators": [
          "tools/workbench-mcp/server.mjs",
          "tools/workbench-mcp/interop.test.mjs",
          "docs/audits/eve-sota-mcp-conformance-matrix.schema.json",
          "docs/audits/eve-sota-mcp-conformance-matrix/2026-09-16.json",
          "docs/audits/eve-sota-evidence/phase-16/task-16-2.json",
          "tools/eve-everywhere/verify-mcp-conformance-matrix.mjs",
          "tools/eve-everywhere/verify-mcp-conformance-matrix.test.mjs",
          "tools/eve-everywhere/run-mcp-conformance-matrix-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-16/task-16-2.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "MCP current-version conformance matrix for each stdio/HTTP client and server: initialize/capability negotiation, schema validation, progress, cancellation, tasks, errors, logging, roots, sampling/elicitation policy, protocol-version mismatch, and transport lifecycle. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "16.3",
      "phaseId": "16",
      "closureState": "completed",
      "requirement": "For protected HTTP MCP, implement/test protected-resource discovery, OAuth flow, least scopes/step-up, resource indicator, token audience, rotation/expiry, no query-string token, no passthrough/confused deputy, revocation, and tenant/task isolation. Document why stdio uses a different credential boundary.",
      "gapRefs": ["G17"],
      "dependencyTaskIds": ["16.2"],
      "dependencyRationales": [
        "Consumes the pinned MCP lifecycle and transport conformance contract."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "protocol-interop",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-16-3",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "protocol-interop",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [
          "libs/bellona/mcp-gateway/src/protected-http-auth.ts",
          "libs/bellona/mcp-gateway/src/protected-http-auth.test.ts",
          "docs/adr/ADR-0090-mcp-transport-authorization-boundaries.md",
          "docs/audits/eve-sota-mcp-protected-http-auth.schema.json",
          "docs/audits/eve-sota-mcp-protected-http-auth/2026-09-16.json",
          "docs/audits/eve-sota-evidence/phase-16/task-16-3.json",
          "tools/eve-everywhere/verify-mcp-protected-http-auth.mjs",
          "tools/eve-everywhere/verify-mcp-protected-http-auth.test.mjs",
          "tools/eve-everywhere/run-mcp-protected-http-auth-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-16/task-16-3.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "For protected HTTP MCP, implement/test protected-resource discovery, OAuth flow, least scopes/step-up, resource indicator, token audience, rotation/expiry, no query-string token, no passthrough/confused deputy, revocation, and tenant/task isolation. Document why stdio uses a different credential boundary. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "16.4",
      "phaseId": "16",
      "closureState": "completed",
      "requirement": "A2A ADR based on a real need for independent external agents. If adopted: signed/trusted Agent Cards, capability/modalities, task lifecycle, auth-required/HITL, streaming/cancel, artifacts, caller/tenant/task isolation, push security, version negotiation, and trace/audit mapping.",
      "gapRefs": ["G17"],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "security-adversarial",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-16-4",
        "state": "available-direct",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "security-adversarial",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [
          "docs/adr/ADR-0091-defer-a2a-until-independent-agent-boundary.md",
          "libs/iris/a2a/README.md",
          "docs/audits/eve-sota-a2a-adoption-decision.schema.json",
          "docs/audits/eve-sota-a2a-adoption-decision/2026-09-16.json",
          "docs/audits/eve-sota-evidence/phase-16/task-16-4.json",
          "tools/eve-everywhere/verify-a2a-adoption-decision.mjs",
          "tools/eve-everywhere/verify-a2a-adoption-decision.test.mjs",
          "tools/eve-everywhere/run-a2a-adoption-decision-evidence.mjs"
        ],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-16/task-16-4.json",
        "limitation": "The named artifacts support only this completed closure-machinery task; they do not prove any open downstream task or gap closed."
      },
      "exitCriterion": "A2A ADR based on a real need for independent external agents. If adopted: signed/trusted Agent Cards, capability/modalities, task lifecycle, auth-required/HITL, streaming/cancel, artifacts, caller/tenant/task isolation, push security, version negotiation, and trace/audit mapping. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "16.5",
      "phaseId": "16",
      "closureState": "open",
      "requirement": "External tool/agent registry: provenance, owner, source/version/hash, permissions/data destinations, risk class, health, eval status, last review, quarantine/revoke, and schema/tool-description change detection. Unknown or changed integrations are unavailable by default.",
      "gapRefs": ["G17"],
      "dependencyTaskIds": ["4.8", "12.7", "13.7", "14.7", "16.2", "16.3", "16.4"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance.",
        "Consumes the pinned MCP lifecycle and transport conformance contract.",
        "Requires protected HTTP MCP authorization and token-boundary proof.",
        "Uses the evidenced A2A adoption or source-backed non-adoption decision."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "security-adversarial",
        "privacy-data-rights"
      ],
      "evidencePlan": {
        "id": "evidence-16-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "security-adversarial",
          "privacy-data-rights"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "security-exercise",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-16/task-16-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "External tool/agent registry: provenance, owner, source/version/hash, permissions/data destinations, risk class, health, eval status, last review, quarantine/revoke, and schema/tool-description change detection. Unknown or changed integrations are unavailable by default. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "16.6",
      "phaseId": "16",
      "closureState": "open",
      "requirement": "Contract/conformance tests run against at least one independent implementation where adoption is claimed. Malformed, downgrade, replay, task enumeration, auth, cancellation, and tool-poisoning negatives are mandatory.",
      "gapRefs": ["G17"],
      "dependencyTaskIds": ["4.8", "12.7", "13.7", "14.7", "16.1", "16.2", "16.3", "16.4", "16.5"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance.",
        "Uses the current event interoperability decision.",
        "Consumes the pinned MCP lifecycle and transport conformance contract.",
        "Requires protected HTTP MCP authorization and token-boundary proof.",
        "Uses the evidenced A2A adoption or source-backed non-adoption decision.",
        "Requires admitted external integration provenance, health and quarantine controls."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "authorization-isolation",
        "protocol-interop",
        "fault-recovery",
        "security-adversarial"
      ],
      "evidencePlan": {
        "id": "evidence-16-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "authorization-isolation",
          "protocol-interop",
          "fault-recovery",
          "security-adversarial"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-16/task-16-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Contract/conformance tests run against at least one independent implementation where adoption is claimed. Malformed, downgrade, replay, task enumeration, auth, cancellation, and tool-poisoning negatives are mandatory. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.1",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Capability matrix for text/code, web, PDF/document, table/spreadsheet, image/screenshot, audio, video, DCC/project files, and generated media: supported input/output, authoritative parser/tool, model leg, limits, privacy/licence, accessibility, evidence, and honest unsupported state.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["0.6"],
      "dependencyRationales": ["Uses the task ownership and direct proof-boundary contract."],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "privacy-data-rights",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-17-1",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "privacy-data-rights",
          "governance-decision"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-1.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Capability matrix for text/code, web, PDF/document, table/spreadsheet, image/screenshot, audio, video, DCC/project files, and generated media: supported input/output, authoritative parser/tool, model leg, limits, privacy/licence, accessibility, evidence, and honest unsupported state. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.2",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Documents/PDFs/tables preserve layout, page/sheet/cell/slide anchors, OCR confidence, citations, structured extraction, and contradiction/ missing-content behavior. Use deterministic parsers before model inference and test adversarial/embedded instructions.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["17.1"],
      "dependencyRationales": [
        "Uses the real modality/toolchain capability and limitation matrix."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-multimodal-runtime",
        "security-adversarial",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-2",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-multimodal-runtime",
          "security-adversarial",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-2.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Documents/PDFs/tables preserve layout, page/sheet/cell/slide anchors, OCR confidence, citations, structured extraction, and contradiction/ missing-content behavior. Use deterministic parsers before model inference and test adversarial/embedded instructions. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.3",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Image/screenshot/audio/video understanding separates observation from inference, retains timestamps/regions/transcript confidence, redacts sensitive content, and supports accessible text/captions. Low confidence triggers clarification or refusal, not confident invention.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["17.1"],
      "dependencyRationales": [
        "Uses the real modality/toolchain capability and limitation matrix."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-model-provider",
        "real-multimodal-runtime",
        "privacy-data-rights",
        "performance-quality"
      ],
      "evidencePlan": {
        "id": "evidence-17-3",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-model-provider",
          "real-multimodal-runtime",
          "privacy-data-rights",
          "performance-quality"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-3.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Image/screenshot/audio/video understanding separates observation from inference, retains timestamps/regions/transcript confidence, redacts sensitive content, and supports accessible text/captions. Low confidence triggers clarification or refusal, not confident invention. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.4",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Generation routes through the owning domain's real toolchain with prompt/source provenance, variant/quality review, policy/licence checks, editable project artifacts, cost/budget, cancellation, and deterministic technical validation. No opaque binary is accepted because a model said it looked right.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["15.1", "17.1"],
      "dependencyRationales": [
        "Consumes priced, capability-correct, fail-loud model registry bindings.",
        "Uses the real modality/toolchain capability and limitation matrix."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "service-integration",
        "real-model-provider",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-4",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "service-integration",
          "real-model-provider",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-4.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Generation routes through the owning domain's real toolchain with prompt/source provenance, variant/quality review, policy/licence checks, editable project artifacts, cost/budget, cancellation, and deterministic technical validation. No opaque binary is accepted because a model said it looked right. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.5",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Modality-specific evals measure extraction/grounding, edit fidelity, temporal/spatial accuracy, perceptual/human quality where calibrated, accessibility, latency/cost, and failure honesty across diverse real fixtures. One modality's score cannot stand in for another.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["17.2", "17.3", "17.4"],
      "dependencyRationales": [
        "Exercises actual structured document extraction and source anchors.",
        "Exercises grounded multimodal understanding and uncertainty handling.",
        "Uses the owning domain real generation toolchain and editable artifacts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-model-provider",
        "real-multimodal-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-model-provider",
          "real-multimodal-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Modality-specific evals measure extraction/grounding, edit fidelity, temporal/spatial accuracy, perceptual/human quality where calibrated, accessibility, latency/cost, and failure honesty across diverse real fixtures. One modality's score cannot stand in for another. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.6",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Live cross-modal capstone: Eve consumes a real product brief plus mixed evidence, plans a governed creative task, produces editable Blender and documented output, independently verifies it, and reports provenance, limitations, cost, and rollback without exposing sensitive inputs.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["4.8", "5.8", "12.7", "13.7", "14.7", "17.2", "17.3", "17.4", "17.5"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Requires observed Blender failure and false-success controls.",
        "Live admission requires the applicable-family evaluation gate, not the future charter benchmark.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance.",
        "Exercises actual structured document extraction and source anchors.",
        "Exercises grounded multimodal understanding and uncertainty handling.",
        "Uses the owning domain real generation toolchain and editable artifacts.",
        "Requires separate modality quality, human and failure evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "real-model-provider",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "operational-load-soak",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "real-model-provider",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "operational-load-soak",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Live cross-modal capstone: Eve consumes a real product brief plus mixed evidence, plans a governed creative task, produces editable Blender and documented output, independently verifies it, and reports provenance, limitations, cost, and rollback without exposing sensitive inputs. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.7",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Ratify the three creative delivery contracts and their coverage map. Owner: Eve/Yemaya product; verifier: charter QA. Depends on 0.8 and 17.1. Amend the source-traceable inventory with reference-to-editable motion, original brief-to-editable motion, and measured-house-to-interactive- walkthrough outcomes. For each, name input/output contracts, native project format, source rights, runtime/host requirements, operator checkpoints, quality rubric, failure states, and accountable owners. Bind every assessment gap to the existing task or a new task in this expansion. Reuse existing authority, skill, planning, asset, review, and artifact owners; no required native outcome becomes optional because its implementation or host is missing.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["0.8", "17.1"],
      "dependencyRationales": [
        "Extends the ratified source-traceable charter coverage inventory.",
        "Uses the actual modality and toolchain capability matrix."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "governance-decision",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-17-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "governance-decision",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "governance-review",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Ratify the three creative delivery contracts and their coverage map. Owner: Eve/Yemaya product; verifier: charter QA. Depends on 0.8 and 17.1. Amend the source-traceable inventory with reference-to-editable motion, original brief-to-editable motion, and measured-house-to-interactive- walkthrough outcomes. For each, name input/output contracts, native project format, source rights, runtime/host requirements, operator checkpoints, quality rubric, failure states, and accountable owners. Bind every assessment gap to the existing task or a new task in this expansion. Reuse existing authority, skill, planning, asset, review, and artifact owners; no required native outcome becomes optional because its implementation or host is missing. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.8",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Implement grounded creative reference ingestion. Owner: Eve multimodal and Isis ingestion; verifier: privacy/grounding QA. Depends on 17.2, 17.3, 17.7, and 14.7. Ingest authorized web/listing pages, images, video segments, captions, floor-plan PDFs, and supplied template assets through the existing browser/parser/vision boundaries. Retain source URLs/files, timestamps, regions, hashes, attribution/licence, extraction confidence, and observed-versus-inferred facts. Handle inaccessible, expired, incomplete, contradictory, or low-resolution sources explicitly; treat embedded instructions as untrusted data. Prove provenance survives persistence, access checks, redaction, correction, and deletion.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["14.7", "17.2", "17.3", "17.7"],
      "dependencyRationales": [
        "Requires rights, retention, and source-media governance.",
        "Uses structured documents, OCR, and source anchors.",
        "Uses grounded visual, audio, and video understanding.",
        "Uses the creative input and output contracts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-model-provider",
        "real-browser-ui",
        "real-multimodal-runtime",
        "security-adversarial",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-model-provider",
          "real-browser-ui",
          "real-multimodal-runtime",
          "security-adversarial",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Implement grounded creative reference ingestion. Owner: Eve multimodal and Isis ingestion; verifier: privacy/grounding QA. Depends on 17.2, 17.3, 17.7, and 14.7. Ingest authorized web/listing pages, images, video segments, captions, floor-plan PDFs, and supplied template assets through the existing browser/parser/vision boundaries. Retain source URLs/files, timestamps, regions, hashes, attribution/licence, extraction confidence, and observed-versus-inferred facts. Handle inaccessible, expired, incomplete, contradictory, or low-resolution sources explicitly; treat embedded instructions as untrusted data. Prove provenance survives persistence, access checks, redaction, correction, and deletion. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.9",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Build storyboard alternatives from a structured creative brief. Owner: Yemaya planning and Isis workflows; verifier: creative QA. Depends on 17.7 and 17.8. Capture audience, message, style references, exact text, aspect ratio, duration/frame rate, audio needs, budget, and deliverables. Reuse the shot compiler for ordered frames, continuity, asset slots, composition, timing, and intended motion; produce genuinely distinct candidate plans with preview images and source-linked rationale. Persist selection and corrections against an immutable version before expensive authoring. Validate missing assets, contradictory timing, text overflow, and unapproved or superseded storyboard inputs.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["17.7", "17.8"],
      "dependencyRationales": [
        "Uses explicit brief, output, and checkpoint requirements.",
        "Consumes grounded and attributed references."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "persistence-recovery",
        "real-model-provider",
        "real-multimodal-runtime",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-17-9",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "persistence-recovery",
          "real-model-provider",
          "real-multimodal-runtime",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-9.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Build storyboard alternatives from a structured creative brief. Owner: Yemaya planning and Isis workflows; verifier: creative QA. Depends on 17.7 and 17.8. Capture audience, message, style references, exact text, aspect ratio, duration/frame rate, audio needs, budget, and deliverables. Reuse the shot compiler for ordered frames, continuity, asset slots, composition, timing, and intended motion; produce genuinely distinct candidate plans with preview images and source-linked rationale. Persist selection and corrections against an immutable version before expensive authoring. Validate missing assets, contradictory timing, text overflow, and unapproved or superseded storyboard inputs. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.10",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Bind storyboard assets to live Isis generation and selection. Owner: Isis generation; verifier: media QA. Depends on 17.4, 17.9, and 15.1. Generate required icons, receipts, textures, and other assets from approved references through registry-bound providers; retain prompts, seeds/settings where supported, model/endpoint, licence, cost, and hashes. Apply the declared continuity/style constraints, dimensions, alpha/color requirements, and format validation; persist variant selection and rejection. Exercise missing provider, budget limit, cancellation, malformed output, identity/style drift, and reuse without duplicate generation. A mock URL or a successful request without usable bytes is not an asset.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["15.1", "17.4", "17.9"],
      "dependencyRationales": [
        "Uses approved capability-correct and priced model bindings.",
        "Uses actual owning-domain generation tooling.",
        "Consumes approved shot plans and asset slots."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "real-multimodal-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-10",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "real-multimodal-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-10.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Bind storyboard assets to live Isis generation and selection. Owner: Isis generation; verifier: media QA. Depends on 17.4, 17.9, and 15.1. Generate required icons, receipts, textures, and other assets from approved references through registry-bound providers; retain prompts, seeds/settings where supported, model/endpoint, licence, cost, and hashes. Apply the declared continuity/style constraints, dimensions, alpha/color requirements, and format validation; persist variant selection and rejection. Exercise missing provider, budget limit, cancellation, malformed output, identity/style drift, and reuse without duplicate generation. A mock URL or a successful request without usable bytes is not an asset. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.11",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Compile the approved motion plan into an editable AE project. Owner: Yemaya motion pipeline and Bellona Adobe; verifier: motion QA. Depends on 5.25, 17.9, and 17.10. Map shot/layer/asset identities, exact text, fonts, shapes/paths, effects, cameras, timing, easing, and motion blur to the supported 5.23 operations. Preserve stable native identities for later edits and fail on unsupported semantics. Render a draft, independently compare planned and actual layers/keyframes/assets, and attach the project and preview to the same revision. Validate behavior on unseen plans; a flattened video cannot satisfy editable delivery.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.25", "17.9", "17.10"],
      "dependencyRationales": [
        "Executes through the attributed live AE path.",
        "Compiles approved versioned storyboard semantics.",
        "Uses selected and validated generated asset bytes."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-11",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-11.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Compile the approved motion plan into an editable AE project. Owner: Yemaya motion pipeline and Bellona Adobe; verifier: motion QA. Depends on 5.25, 17.9, and 17.10. Map shot/layer/asset identities, exact text, fonts, shapes/paths, effects, cameras, timing, easing, and motion blur to the supported 5.23 operations. Preserve stable native identities for later edits and fail on unsupported semantics. Render a draft, independently compare planned and actual layers/keyframes/assets, and attach the project and preview to the same revision. Validate behavior on unseen plans; a flattened video cannot satisfy editable delivery. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.12",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Close the human feedback-to-native revision loop. Owner: Yemaya review and Eve planning; verifier: creative integration QA. Depends on 5.28, 17.9, and 17.11. Reuse frame notes, annotations, comparison modes, and decisions to express an exact requested change and acceptance rule. Bind feedback to source/render revision, translate it into a scoped native edit, regenerate affected outputs, and verify both the correction and preservation of accepted content. Persist rejected alternatives, clarification, undo, and supersession. Test simultaneous edits, conflicting notes, changed assets, stale approvals, lost connections, and correction of timing/path/style defects across multiple revisions.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.28", "17.9", "17.11"],
      "dependencyRationales": [
        "Uses durable creative execution and cancellation/recovery.",
        "Binds feedback to immutable storyboard revisions.",
        "Applies changes to actual editable AE projects."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-model-provider",
        "real-dcc-runtime",
        "fault-recovery",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-12",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-model-provider",
          "real-dcc-runtime",
          "fault-recovery",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-12.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Close the human feedback-to-native revision loop. Owner: Yemaya review and Eve planning; verifier: creative integration QA. Depends on 5.28, 17.9, and 17.11. Reuse frame notes, annotations, comparison modes, and decisions to express an exact requested change and acceptance rule. Bind feedback to source/render revision, translate it into a scoped native edit, regenerate affected outputs, and verify both the correction and preservation of accepted content. Persist rejected alternatives, clarification, undo, and supersession. Test simultaneous edits, conflicting notes, changed assets, stale approvals, lost connections, and correction of timing/path/style defects across multiple revisions. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.13",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Deliver portable versioned creative project packages. Owner: Bellona artifacts and Yemaya delivery; verifier: artifact/privacy QA. Depends on 5.24, 5.26, and 14.7. Link brief, references, storyboard, generated/selected assets, skill revision, native source, previews, reviews, and final exports through the existing dependency graph with hashes and access/retention policy. Package permitted dependencies and record required fonts/plugins/versions, relink instructions, attribution, and known limits. Reopen on a clean supported session/host and verify edits and render parity; reject missing media and wrong versions. Prove tenant-safe download, deletion propagation, restart, and corruption handling without leaking private references or credentials.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.24", "5.26", "14.7"],
      "dependencyRationales": [
        "Packages real reopenable AE project and render artifacts.",
        "Uses actual cross-domain artifact storage and transfer.",
        "Requires media rights, retention, and deletion governance."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-dcc-runtime",
        "real-engine-runtime",
        "fault-recovery",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-13",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-dcc-runtime",
          "real-engine-runtime",
          "fault-recovery",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-13.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver portable versioned creative project packages. Owner: Bellona artifacts and Yemaya delivery; verifier: artifact/privacy QA. Depends on 5.24, 5.26, and 14.7. Link brief, references, storyboard, generated/selected assets, skill revision, native source, previews, reviews, and final exports through the existing dependency graph with hashes and access/retention policy. Package permitted dependencies and record required fonts/plugins/versions, relink instructions, attribution, and known limits. Reopen on a clean supported session/host and verify edits and render parity; reject missing media and wrong versions. Prove tenant-safe download, deletion propagation, restart, and corruption handling without leaking private references or credentials. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.14",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Define and extract a dimensioned architectural scene contract. Owner: Yemaya architecture with Eve multimodal; verifier: architectural QA. Depends on 17.7 and 17.8. Model units/scale, floors, heights, rooms, adjacency, wall thickness, openings, stairs, orientation, materials, and source anchors with measured/inferred/unknown status and confidence. Reconcile plan dimensions and photographs, preserve contradictions, and require resolution of load-bearing ambiguity before claiming accuracy. Validate real annotated plans, mixed units, missing dimensions, rotated scans, inconsistent totals, and multiple floors against independent ground truth and declared tolerances; a generic mesh schema is not this domain contract.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["17.7", "17.8"],
      "dependencyRationales": [
        "Uses the architectural accuracy and output requirements.",
        "Consumes measured and source-anchored floor-plan evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "real-model-provider",
        "real-multimodal-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-14",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "real-model-provider",
          "real-multimodal-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-14.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Define and extract a dimensioned architectural scene contract. Owner: Yemaya architecture with Eve multimodal; verifier: architectural QA. Depends on 17.7 and 17.8. Model units/scale, floors, heights, rooms, adjacency, wall thickness, openings, stairs, orientation, materials, and source anchors with measured/inferred/unknown status and confidence. Reconcile plan dimensions and photographs, preserve contradictions, and require resolution of load-bearing ambiguity before claiming accuracy. Validate real annotated plans, mixed units, missing dimensions, rotated scans, inconsistent totals, and multiple floors against independent ground truth and declared tolerances; a generic mesh schema is not this domain contract. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.15",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Reconstruct editable Blender geometry from the architectural contract. Owner: Bellona Blender; verifier: architectural/geometry QA. Depends on 5.6, 5.20, and 17.14. Generate stable, parameterized floor, wall, room, opening, stair, and roof objects with source identities; preserve separable editable elements and record every inferred detail. Independently check dimensions, room adjacency, openings, floor heights, topology, intersections, and missing elements against the source contract before and after save/reopen. Exercise corrected measurements, multi-storey plans, undo, and export; never label visually plausible geometry dimensionally accurate without measured verification.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.6", "5.20", "17.14"],
      "dependencyRationales": [
        "Uses governed and independently verified Blender execution.",
        "Requires correct native save/reopen and export verification.",
        "Uses the dimensioned architectural scene contract."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "persistence-recovery",
        "real-dcc-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-15",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "persistence-recovery",
          "real-dcc-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-15.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Reconstruct editable Blender geometry from the architectural contract. Owner: Bellona Blender; verifier: architectural/geometry QA. Depends on 5.6, 5.20, and 17.14. Generate stable, parameterized floor, wall, room, opening, stair, and roof objects with source identities; preserve separable editable elements and record every inferred detail. Independently check dimensions, room adjacency, openings, floor heights, topology, intersections, and missing elements against the source contract before and after save/reopen. Exercise corrected measurements, multi-storey plans, undo, and export; never label visually plausible geometry dimensionally accurate without measured verification. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.16",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Refine architectural materials, lighting, and furnishings against references. Owner: Isis assets and Bellona scene authoring; verifier: architectural visual reviewer. Depends on 17.10, 17.15, and 12.9. Reuse verified generated/imported assets, map textures/material scale and camera views, and iterate lighting and furnishings while preserving accepted geometry. Match reference viewpoints for comparison, separate measured features from inferred decor, and record missing views. Grade material, lighting, spatial, and temporal/render defects with the 12.9 rubric; test revisions do not silently change dimensions, replace approved assets, or lose provenance.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["12.9", "17.10", "17.15"],
      "dependencyRationales": [
        "Uses calibrated architectural visual and dimensional quality criteria.",
        "Uses verified generated/imported assets and provenance.",
        "Preserves independently verified architectural geometry."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-16",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-16.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Refine architectural materials, lighting, and furnishings against references. Owner: Isis assets and Bellona scene authoring; verifier: architectural visual reviewer. Depends on 17.10, 17.15, and 12.9. Reuse verified generated/imported assets, map textures/material scale and camera views, and iterate lighting and furnishings while preserving accepted geometry. Match reference viewpoints for comparison, separate measured features from inferred decor, and record missing views. Grade material, lighting, spatial, and temporal/render defects with the 12.9 rubric; test revisions do not silently change dimensions, replace approved assets, or lose provenance. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.17",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Deliver the interactive architectural walkthrough. Owner: Bellona Unreal and Yemaya delivery; verifier: engine/web QA. Depends on 5.27, 17.15, and 17.16. Import the verified scene into UE, configure navigation, collision, cameras, controls, lighting, and required interactions, then save/reopen and test actual traversal. Implement and deploy the selected browser delivery path, explicitly identifying local execution versus remote streaming and its host/network costs. Verify access, loading, input, navigation bounds, reconnect, latency, and performance on declared devices; provide an accessible alternative. A screenshot, editor import, or unserved build cannot establish a delivered interactive walkthrough.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.27", "17.15", "17.16"],
      "dependencyRationales": [
        "Uses semantically verified Blender-to-Unreal interchange.",
        "Uses editable dimensionally checked geometry.",
        "Uses reviewed reference-based materials, lighting, and furnishings."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "authorization-isolation",
        "real-browser-ui",
        "real-engine-runtime",
        "fault-recovery",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-17",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "authorization-isolation",
          "real-browser-ui",
          "real-engine-runtime",
          "fault-recovery",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-17.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver the interactive architectural walkthrough. Owner: Bellona Unreal and Yemaya delivery; verifier: engine/web QA. Depends on 5.27, 17.15, and 17.16. Import the verified scene into UE, configure navigation, collision, cameras, controls, lighting, and required interactions, then save/reopen and test actual traversal. Implement and deploy the selected browser delivery path, explicitly identifying local execution versus remote streaming and its host/network costs. Verify access, loading, input, navigation bounds, reconnect, latency, and performance on declared devices; provide an accessible alternative. A screenshot, editor import, or unserved build cannot establish a delivered interactive walkthrough. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.18",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Run the reference-motion capstone from clean state. Owner: Eve creative delivery; verifier: independent motion designer. Depends on 5.29, 7.10, 8.11, 12.10, and 17.11. Use authorized held-out references covering curved connectors, stepped animation, kinetic typography, translucent/glowing controls, and layered camera motion. Exercise the real brief/storyboard/assets/AE/review loop, including at least one substantive correction per case. Deliver reopenable layered projects and previews; meet preregistered quality and cost/time thresholds with full trace, interventions, failures, and human decisions retained. Include repeated fresh runs; reproducing a single practiced clip is insufficient.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.29", "7.10", "8.11", "12.10", "17.11"],
      "dependencyRationales": [
        "Requires real AE breadth and failure evidence.",
        "Uses creative skills proven on held-out briefs.",
        "Requires the actual review and delivery user journey.",
        "Uses the admitted creative-family evidence and quality release gate.",
        "Uses real native motion compilation and artifacts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "real-model-provider",
        "real-browser-ui",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-18",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "real-model-provider",
          "real-browser-ui",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-18.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Run the reference-motion capstone from clean state. Owner: Eve creative delivery; verifier: independent motion designer. Depends on 5.29, 7.10, 8.11, 12.10, and 17.11. Use authorized held-out references covering curved connectors, stepped animation, kinetic typography, translucent/glowing controls, and layered camera motion. Exercise the real brief/storyboard/assets/AE/review loop, including at least one substantive correction per case. Deliver reopenable layered projects and previews; meet preregistered quality and cost/time thresholds with full trace, interventions, failures, and human decisions retained. Include repeated fresh runs; reproducing a single practiced clip is insufficient. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.19",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Run the original-motion capstone without a target video. Owner: Yemaya creative delivery; verifier: independent product/motion reviewer. Depends on 5.29, 7.10, 8.11, 12.10, and 17.11. From held-out message and brand briefs, produce alternative storyboards, select and correct one, generate assets, author native motion, and complete review revisions. Grade communication, originality within the brief, visual coherence, timing, editability, and approved cost/time separately from reference imitation. Retain rejected candidates and operator labor; verify the delivered project reopens, remains editable, and reproduces its preview.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["5.29", "7.10", "8.11", "12.10", "17.11"],
      "dependencyRationales": [
        "Requires real AE breadth and failure evidence.",
        "Uses transferable creative recipes rather than memorized clips.",
        "Requires the actual review and delivery user journey.",
        "Uses the original-motion family quality gate.",
        "Produces editable native compositions from approved plans."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "real-model-provider",
        "real-browser-ui",
        "real-dcc-runtime",
        "real-multimodal-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-19",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "real-model-provider",
          "real-browser-ui",
          "real-dcc-runtime",
          "real-multimodal-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-19.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Run the original-motion capstone without a target video. Owner: Yemaya creative delivery; verifier: independent product/motion reviewer. Depends on 5.29, 7.10, 8.11, 12.10, and 17.11. From held-out message and brand briefs, produce alternative storyboards, select and correct one, generate assets, author native motion, and complete review revisions. Grade communication, originality within the brief, visual coherence, timing, editability, and approved cost/time separately from reference imitation. Retain rejected candidates and operator labor; verify the delivered project reopens, remains editable, and reproduces its preview. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.20",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Run the measured-house reconstruction capstone. Owner: Eve/Bellona architectural delivery; verifier: independent architectural reviewer. Depends on 8.11, 12.10, 17.13, and 17.17. Use authorized listings/plans with independent dimensional ground truth and varied layouts, including multiple floors, incomplete views, and corrected measurements. Exercise source ingestion, uncertainty handling, editable Blender construction, refinement, UE transfer, and delivered walkthrough. Verify geometry and native projects, review visual fidelity, test interaction/performance, and measure full operator labor/cost. Missing measurements, failed delivery, or unmet tolerance/quality targets keep the case open.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["8.11", "12.10", "17.13", "17.17"],
      "dependencyRationales": [
        "Requires the actual review and delivery user journey.",
        "Uses the architectural and walkthrough family gates.",
        "Delivers verified portable native project packages.",
        "Requires a delivered and tested interactive walkthrough."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "real-model-provider",
        "real-browser-ui",
        "real-dcc-runtime",
        "real-engine-runtime",
        "real-multimodal-runtime",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-20",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "real-model-provider",
          "real-browser-ui",
          "real-dcc-runtime",
          "real-engine-runtime",
          "real-multimodal-runtime",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "live-runtime",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-20.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Run the measured-house reconstruction capstone. Owner: Eve/Bellona architectural delivery; verifier: independent architectural reviewer. Depends on 8.11, 12.10, 17.13, and 17.17. Use authorized listings/plans with independent dimensional ground truth and varied layouts, including multiple floors, incomplete views, and corrected measurements. Exercise source ingestion, uncertainty handling, editable Blender construction, refinement, UE transfer, and delivered walkthrough. Verify geometry and native projects, review visual fidelity, test interaction/performance, and measure full operator labor/cost. Missing measurements, failed delivery, or unmet tolerance/quality targets keep the case open. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.21",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Reconcile creative delivery, capability claims, and maintenance. Owner: Eve product and release operations; verifier: charter QA. Depends on 17.18, 17.19, and 17.20. Join all expansion tasks to the required workflow inventory, evidence matrix, product graph, handbook, and owning workbench capability registry; require each new task and its dependencies to have independent accepted evidence. Publish reproducible host setup, supported operation/format/version limits, project/recovery procedures, licence/dependency requirements, and measured quality/time/cost. Add focused regression runs and capability re-probes for model, app, plugin, skill, provider, and source changes; regressions withdraw affected claims and reopen the required work. Feed this task into Phase 18 closure.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["17.18", "17.19", "17.20"],
      "dependencyRationales": [
        "Requires accepted held-out reference-motion delivery evidence.",
        "Requires accepted original-brief motion delivery evidence.",
        "Requires accepted dimensional reconstruction and walkthrough evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "service-integration",
        "governance-decision",
        "independent-verification",
        "docs-render-integrity"
      ],
      "evidencePlan": {
        "id": "evidence-17-21",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "service-integration",
          "governance-decision",
          "independent-verification",
          "docs-render-integrity"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "service-integration",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-21.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Reconcile creative delivery, capability claims, and maintenance. Owner: Eve product and release operations; verifier: charter QA. Depends on 17.18, 17.19, and 17.20. Join all expansion tasks to the required workflow inventory, evidence matrix, product graph, handbook, and owning workbench capability registry; require each new task and its dependencies to have independent accepted evidence. Publish reproducible host setup, supported operation/format/version limits, project/recovery procedures, licence/dependency requirements, and measured quality/time/cost. Add focused regression runs and capability re-probes for model, app, plugin, skill, provider, and source changes; regressions withdraw affected claims and reopen the required work. Feed this task into Phase 18 closure. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.22",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Admit generation tools to Eve's governed toolset. Owner: Eve tools with Isis/Bellona generation; verifier: security/media QA. Depends on 4.8, 14.7, 15.7, and 17.4. Mount image (Isis Flux/SD3.x adapters and the existing media-tool pattern), video (Isis Seedance/ai-video), music/audio/speech (Isis music and audio generation, existing TTS), and 3D (Isis 3D generation, Bellona Meshy/Tripo) through the registry legs, the intent ledger, confirm-before-spend cards, budgets, cancellation, and a tenant-scoped artifact store. Retain prompt, seed/settings, model/endpoint, cost, hashes, licence, and generated-media disclosure; validate outputs deterministically (dimensions, format, duration, manifold mesh) before acceptance. A mock URL or a request without usable bytes is not an asset.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["4.8", "14.7", "15.7", "17.4"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Requires generated-media licence, disclosure and provenance governance.",
        "Uses the admitted generation legs and priced route choices.",
        "Uses the owning domain real generation toolchain and editable artifacts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-model-provider",
        "real-multimodal-runtime",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-22",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-model-provider",
          "real-multimodal-runtime",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-22.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Admit generation tools to Eve's governed toolset. Owner: Eve tools with Isis/Bellona generation; verifier: security/media QA. Depends on 4.8, 14.7, 15.7, and 17.4. Mount image (Isis Flux/SD3.x adapters and the existing media-tool pattern), video (Isis Seedance/ai-video), music/audio/speech (Isis music and audio generation, existing TTS), and 3D (Isis 3D generation, Bellona Meshy/Tripo) through the registry legs, the intent ledger, confirm-before-spend cards, budgets, cancellation, and a tenant-scoped artifact store. Retain prompt, seed/settings, model/endpoint, cost, hashes, licence, and generated-media disclosure; validate outputs deterministically (dimensions, format, duration, manifold mesh) before acceptance. A mock URL or a request without usable bytes is not an asset. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.23",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Deliver generated media into the chat and artifact workspace. Owner: Eve interaction with Isis delivery; verifier: media/accessibility QA. Depends on 8.14, 8.15, 8.19, and 17.22. Show inline previews and players, a 3D viewer, variant selection, edit/iterate (variations, inpaint, prompt revision, video extend, remix), download in native formats, and save to the Isis output gallery or owning workbench, with alt text, captions, transcripts, no autoplay under reduced motion, progress and cost cards, and honest failure states on every surface.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["8.14", "8.15", "8.19", "17.22"],
      "dependencyRationales": [
        "Uses the shared rich renderer for inline images, players and viewers.",
        "Uses the artifact workspace for variants, edits and saves.",
        "Uses progress and completion delivery for generation jobs.",
        "Requires admitted, validated, provenance-bearing generation tools."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "real-browser-ui",
        "mobile-runtime",
        "real-multimodal-runtime",
        "fault-recovery",
        "human-outcomes"
      ],
      "evidencePlan": {
        "id": "evidence-17-23",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "real-browser-ui",
          "mobile-runtime",
          "real-multimodal-runtime",
          "fault-recovery",
          "human-outcomes"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "human-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-23.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Deliver generated media into the chat and artifact workspace. Owner: Eve interaction with Isis delivery; verifier: media/accessibility QA. Depends on 8.14, 8.15, 8.19, and 17.22. Show inline previews and players, a 3D viewer, variant selection, edit/iterate (variations, inpaint, prompt revision, video extend, remix), download in native formats, and save to the Isis output gallery or owning workbench, with alt text, captions, transcripts, no autoplay under reduced motion, progress and cost cards, and honest failure states on every surface. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.24",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Answer from attachments. Owner: Eve multimodal; verifier: grounding/security QA. Depends on 8.13, 15.7, 17.2, and 17.3. Uploaded PDFs, documents, spreadsheets, images, audio, and video are answered with page/sheet/cell/region/timestamp anchors, extraction tables, OCR and transcript confidence, citations back to the attachment, and observation-versus-inference separation through registry-bound vision and speech legs; embedded instructions are untrusted data and low confidence triggers clarification, not invention.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["8.13", "15.7", "17.2", "17.3"],
      "dependencyRationales": [
        "Requires the shipped multimodal composer and attachment envelope.",
        "Uses the admitted vision and speech legs through the registry control.",
        "Exercises actual structured document extraction and source anchors.",
        "Exercises grounded multimodal understanding and uncertainty handling."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "real-multimodal-runtime",
        "security-adversarial",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-24",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "real-multimodal-runtime",
          "security-adversarial",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-24.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Answer from attachments. Owner: Eve multimodal; verifier: grounding/security QA. Depends on 8.13, 15.7, 17.2, and 17.3. Uploaded PDFs, documents, spreadsheets, images, audio, and video are answered with page/sheet/cell/region/timestamp anchors, extraction tables, OCR and transcript confidence, citations back to the attachment, and observation-versus-inference separation through registry-bound vision and speech legs; embedded instructions are untrusted data and low confidence triggers clarification, not invention. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.25",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Admit sandboxed data analysis and code execution in chat. Owner: Eve tools with agent runtime; verifier: security QA. Depends on 4.8, 4.5, 7.1, and 8.15. Bring the code-execution tool under a real isolated sandbox (no network by default, resource and time limits, tenant-scoped scratch), with attachment inputs, file and chart outputs as artifacts, reproducible notebooks, and full trace. Prove escape, exfiltration, resource-exhaustion, and malformed-output controls fail closed.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["4.5", "4.8", "7.1", "8.15"],
      "dependencyRationales": [
        "Requires execution isolation for code with scoped resources.",
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Uses the recorded Hermes fusion scope for the code-execution tool.",
        "Delivers files and charts into the artifact workspace."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "authorization-isolation",
        "real-agent-runtime",
        "fault-recovery",
        "security-adversarial",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-25",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "authorization-isolation",
          "real-agent-runtime",
          "fault-recovery",
          "security-adversarial",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-25.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Admit sandboxed data analysis and code execution in chat. Owner: Eve tools with agent runtime; verifier: security QA. Depends on 4.8, 4.5, 7.1, and 8.15. Bring the code-execution tool under a real isolated sandbox (no network by default, resource and time limits, tenant-scoped scratch), with attachment inputs, file and chart outputs as artifacts, reproducible notebooks, and full trace. Prove escape, exfiltration, resource-exhaustion, and malformed-output controls fail closed. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.26",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Admit web search and deep research in chat. Owner: Eve tools with retrieval; verifier: grounding/security QA. Depends on 4.8, 7.1, 8.15, 8.18, and 8.19. Mount the web search and fetch tools with source cards, citations, allowlists, robots and licence handling, and injection defence; add a deep-research mode that plans, gathers, and delivers a cited report artifact with progress, cost, and cancel. Grade citation accuracy and contradiction handling on held-out questions.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["4.8", "7.1", "8.15", "8.18", "8.19"],
      "dependencyRationales": [
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Uses the recorded Hermes fusion scope for web search and fetch tools.",
        "Delivers cited research reports into the artifact workspace.",
        "Uses the composer mode picker for search and research modes.",
        "Uses progress and completion delivery for research runs."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "real-model-provider",
        "real-browser-ui",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-17-26",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "real-model-provider",
          "real-browser-ui",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "security-exercise",
          "measurement",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-26.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Admit web search and deep research in chat. Owner: Eve tools with retrieval; verifier: grounding/security QA. Depends on 4.8, 7.1, 8.15, 8.18, and 8.19. Mount the web search and fetch tools with source cards, citations, allowlists, robots and licence handling, and injection defence; add a deep-research mode that plans, gathers, and delivers a cited report artifact with progress, cost, and cancel. Grade citation accuracy and contradiction handling on held-out questions. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "17.27",
      "phaseId": "17",
      "closureState": "open",
      "requirement": "Reconcile generated-media and agentic chat claims. Owner: Eve product and release operations; verifier: charter QA. Depends on 12.11, 17.23, 17.24, 17.25, and 17.26. Join every expansion task to the capability matrix (17.1), the parity register (8.12), the evidence matrix, product graph, handbook, and capability declarations; run modality evals from 12.11 with human review where calibrated; publish supported formats, limits, cost, and provenance guarantees; regressions withdraw the affected claims. Feed 18.1.",
      "gapRefs": ["G15"],
      "dependencyTaskIds": ["12.11", "17.23", "17.24", "17.25", "17.26"],
      "dependencyRationales": [
        "Uses the admitted parity and generated-media evaluation family.",
        "Requires delivered generated media in the conversation.",
        "Requires grounded answers from attachments.",
        "Requires admitted sandboxed data analysis.",
        "Requires admitted web search and deep research."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "performance-quality",
        "human-outcomes",
        "independent-verification",
        "docs-render-integrity"
      ],
      "evidencePlan": {
        "id": "evidence-17-27",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "performance-quality",
          "human-outcomes",
          "independent-verification",
          "docs-render-integrity"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "measurement",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-17/task-17-27.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Reconcile generated-media and agentic chat claims. Owner: Eve product and release operations; verifier: charter QA. Depends on 12.11, 17.23, 17.24, 17.25, and 17.26. Join every expansion task to the capability matrix (17.1), the parity register (8.12), the evidence matrix, product graph, handbook, and capability declarations; run modality evals from 12.11 with human review where calibrated; publish supported formats, limits, cost, and provenance guarantees; regressions withdraw the affected claims. Feed 18.1. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.1",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Re-run the gap→task→evidence matrix. For every G1–G18 requirement, classify current evidence as proved, contradicted, weak/indirect, missing, or externally blocked. Also reconcile the ratified charter inventory, including unadmitted workflows, with the Phase-12 completeness gate. Only proved requirements close; every other classification keeps its task, dependent phase, initiative, and charter completion open.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": [
        "0.8",
        "1.9",
        "2.8",
        "3.8",
        "4.8",
        "5.11",
        "6.8",
        "7.8",
        "8.9",
        "9.7",
        "10.4",
        "11.8",
        "12.6",
        "12.8",
        "13.7",
        "14.7",
        "15.6",
        "16.6",
        "17.6",
        "17.21",
        "17.27"
      ],
      "dependencyRationales": [
        "Requires ratified source coverage so required workflows cannot be omitted.",
        "Requires required-workbench completion to reject deferred or missing seams.",
        "Requires the actual governed fleet drain and soak evidence.",
        "Requires operational retrieval freshness, recovery and canary evidence.",
        "Live admission requires the security red-team gate; preparation may proceed before it.",
        "Requires every selected runtime package, including newly discovered children, to be delivered.",
        "Requires native injection and benign continuation proof.",
        "Requires explicitly chosen, live-gated channel operation.",
        "Requires actual cross-client journeys and server/tool round-trip proof.",
        "Requires measured memory rollout, usefulness and zero-harm evidence.",
        "Requires actual V1.2 availability and restored-semantics live evidence.",
        "Requires the full charter benchmark and complete observation windows.",
        "Requires online feedback and drift evidence linked to offline cases.",
        "Requires the full evidence-joining charter gate implementation, independently of later production results.",
        "Live admission requires operational detect, kill, recover and verify readiness.",
        "Creative/live admission requires actual privacy, media rights and consent governance.",
        "Requires bounded capacity and denial-of-wallet evidence.",
        "Requires conformance against independent counterpart implementations.",
        "Requires real governed cross-modal delivery and verification.",
        "Requires all added creative workflows, dependencies, and truthful capability claims to reconcile before closure.",
        "Requires generated-media and agentic chat claims to reconcile with the parity register before closure."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-18-1",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-1.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Re-run the gap→task→evidence matrix. For every G1–G18 requirement, classify current evidence as proved, contradicted, weak/indirect, missing, or externally blocked. Also reconcile the ratified charter inventory, including unadmitted workflows, with the Phase-12 completeness gate. Only proved requirements close; every other classification keeps its task, dependent phase, initiative, and charter completion open. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.2",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Fresh repository audit: source, tests, routes/stores, model registry, prompts/decks, queues/leases, UI/mobile, DCC/computer use, memory/vectors, protocols, observability, privacy, and docs. Hunt for new durable surfaces, direct SDK/model calls, simulated runtimes, hidden stubs, unowned tools, stale claims, and unmeasured capability.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["18.1"],
      "dependencyRationales": [
        "Requires every gap and required charter workflow to reconcile to direct evidence."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "host-capability-observation"
      ],
      "evidencePlan": {
        "id": "evidence-18-2",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "host-capability-observation"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "live-runtime"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-2.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Fresh repository audit: source, tests, routes/stores, model registry, prompts/decks, queues/leases, UI/mobile, DCC/computer use, memory/vectors, protocols, observability, privacy, and docs. Hunt for new durable surfaces, direct SDK/model calls, simulated runtimes, hidden stubs, unowned tools, stale claims, and unmeasured capability. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.3",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Refresh the external primary-source crosswalk and compare at least two relevant current systems/benchmarks by published evidence and paired representative charter tasks at declared quality/time/cost budgets where executable access exists. Record inaccessible comparisons honestly. Every new material gap in required scope becomes owned work in this initiative and blocks closure until resolved; a successor cannot remove it from the completion denominator. Schedule recurring capability reviews and benchmark expansion after completion, with automatic reopening on source-scope drift, a new required workflow, or an outcome regression.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["0.4"],
      "dependencyRationales": [
        "Uses the versioned source/control crosswalk to define applicable obligations."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "real-agent-runtime",
        "performance-quality",
        "governance-decision"
      ],
      "evidencePlan": {
        "id": "evidence-18-3",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "real-agent-runtime",
          "performance-quality",
          "governance-decision"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "live-runtime",
          "measurement",
          "governance-review"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-3.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Refresh the external primary-source crosswalk and compare at least two relevant current systems/benchmarks by published evidence and paired representative charter tasks at declared quality/time/cost budgets where executable access exists. Record inaccessible comparisons honestly. Every new material gap in required scope becomes owned work in this initiative and blocks closure until resolved; a successor cannot remove it from the completion denominator. Schedule recurring capability reviews and benchmark expansion after completion, with automatic reopening on source-scope drift, a new required workflow, or an outcome regression. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.4",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Run the software-delivery and cross-modal capstones from clean state, plus a multi-session watcher/memory scenario and a real operator UI flow. Repeat the full charter benchmark from 11.8 at its actual runtime boundaries; apply every scorecard target and observation window. All produce linked trace→ledger→artifact→verification→narrative evidence. Missing or externally blocked cases remain in the denominator and keep completion open.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["18.1", "18.2", "18.3"],
      "dependencyRationales": [
        "Requires every gap and required charter workflow to reconcile to direct evidence.",
        "Requires the fresh source/runtime audit with new gaps owned.",
        "Requires current source and comparative capability gaps to be resolved."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "service-integration",
        "persistence-recovery",
        "real-model-provider",
        "real-agent-runtime",
        "real-database",
        "real-vector-store",
        "real-browser-ui",
        "native-desktop-runtime",
        "mobile-runtime",
        "real-dcc-runtime",
        "real-engine-runtime",
        "real-multimodal-runtime",
        "operational-load-soak",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "human-outcomes",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-18-4",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "service-integration",
          "persistence-recovery",
          "real-model-provider",
          "real-agent-runtime",
          "real-database",
          "real-vector-store",
          "real-browser-ui",
          "native-desktop-runtime",
          "mobile-runtime",
          "real-dcc-runtime",
          "real-engine-runtime",
          "real-multimodal-runtime",
          "operational-load-soak",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "human-outcomes",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "security-exercise",
          "measurement",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-4.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Run the software-delivery and cross-modal capstones from clean state, plus a multi-session watcher/memory scenario and a real operator UI flow. Repeat the full charter benchmark from 11.8 at its actual runtime boundaries; apply every scorecard target and observation window. All produce linked trace→ledger→artifact→verification→narrative evidence. Missing or externally blocked cases remain in the denominator and keep completion open. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.5",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Run the security/reliability game day: injection/poisoning, privilege, dependency failure, cancellation, crash/restart, duplicate/replay, provider degradation, restore, deletion propagation, and kill/rollback. Zero unauthorized or falsely successful actions is a hard gate.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["18.1", "18.2"],
      "dependencyRationales": [
        "Requires every gap and required charter workflow to reconcile to direct evidence.",
        "Requires the fresh source/runtime audit with new gaps owned."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-model-provider",
        "real-database",
        "real-vector-store",
        "real-browser-ui",
        "native-desktop-runtime",
        "real-dcc-runtime",
        "external-channel-runtime",
        "protocol-interop",
        "operational-load-soak",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-18-5",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-model-provider",
          "real-database",
          "real-vector-store",
          "real-browser-ui",
          "native-desktop-runtime",
          "real-dcc-runtime",
          "external-channel-runtime",
          "protocol-interop",
          "operational-load-soak",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "security-exercise",
          "governance-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-5.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Run the security/reliability game day: injection/poisoning, privilege, dependency failure, cancellation, crash/restart, duplicate/replay, provider degradation, restore, deletion propagation, and kill/rollback. Zero unauthorized or falsely successful actions is a hard gate. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.6",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Final targeted + affected verification manifest: lint, typecheck, units, integrations, contracts/schemas/migrations, builds, accessibility, performance/load/soak, Playwright/mobile, live model, retrieval/vector, DCC/native desktop, security, eval/release gates, docs/product graph. Broad commands obey host resource gates and are not required when unsafe; the manifest must explain the equivalent targeted coverage.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["18.4", "18.5"],
      "dependencyRationales": [
        "Requires the clean-state full charter and operator benchmark evidence.",
        "Requires the final security/reliability game day without hard-lock events."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "service-integration",
        "persistence-recovery",
        "authorization-isolation",
        "real-model-provider",
        "real-agent-runtime",
        "real-database",
        "real-vector-store",
        "real-browser-ui",
        "native-desktop-runtime",
        "mobile-runtime",
        "real-dcc-runtime",
        "real-engine-runtime",
        "external-channel-runtime",
        "real-multimodal-runtime",
        "protocol-interop",
        "host-capability-observation",
        "operational-load-soak",
        "fault-recovery",
        "security-adversarial",
        "privacy-data-rights",
        "performance-quality",
        "governance-decision",
        "human-outcomes",
        "manual-assistive-tech",
        "independent-verification",
        "docs-render-integrity"
      ],
      "evidencePlan": {
        "id": "evidence-18-6",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "service-integration",
          "persistence-recovery",
          "authorization-isolation",
          "real-model-provider",
          "real-agent-runtime",
          "real-database",
          "real-vector-store",
          "real-browser-ui",
          "native-desktop-runtime",
          "mobile-runtime",
          "real-dcc-runtime",
          "real-engine-runtime",
          "external-channel-runtime",
          "real-multimodal-runtime",
          "protocol-interop",
          "host-capability-observation",
          "operational-load-soak",
          "fault-recovery",
          "security-adversarial",
          "privacy-data-rights",
          "performance-quality",
          "governance-decision",
          "human-outcomes",
          "manual-assistive-tech",
          "independent-verification",
          "docs-render-integrity"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "service-integration",
          "live-runtime",
          "operational-exercise",
          "security-exercise",
          "measurement",
          "governance-review",
          "human-review",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-6.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Final targeted + affected verification manifest: lint, typecheck, units, integrations, contracts/schemas/migrations, builds, accessibility, performance/load/soak, Playwright/mobile, live model, retrieval/vector, DCC/native desktop, security, eval/release gates, docs/product graph. Broad commands obey host resource gates and are not required when unsafe; the manifest must explain the equivalent targeted coverage. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.7",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Update the Eve handbook, runbooks, architecture/ADRs, release scope, docs center, product graph, and top-of-file closing summary. Include what shipped, what was measured/rejected, cost/SLO deltas, known limitations, human/infra blockers, and next review date/triggers. Publish separate initiative and charter evidence reports; neither may say complete with unresolved blockers. Report OPEN/BLOCKED/BELOW TARGET accurately until all required outcomes are proved. A record of available capability is not evidence that the full charter is achieved.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["18.1", "18.2", "18.3", "18.4", "18.5", "18.6"],
      "dependencyRationales": [
        "Requires every gap and required charter workflow to reconcile to direct evidence.",
        "Requires the fresh source/runtime audit with new gaps owned.",
        "Requires current source and comparative capability gaps to be resolved.",
        "Requires the clean-state full charter and operator benchmark evidence.",
        "Requires the final security/reliability game day without hard-lock events.",
        "Requires all applicable final verification and derived artifacts."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "governance-decision",
        "docs-render-integrity"
      ],
      "evidencePlan": {
        "id": "evidence-18-7",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "governance-decision",
          "docs-render-integrity"
        ],
        "evidenceClassRefs": ["source-review", "automated-static", "governance-review"],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-7.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Update the Eve handbook, runbooks, architecture/ADRs, release scope, docs center, product graph, and top-of-file closing summary. Include what shipped, what was measured/rejected, cost/SLO deltas, known limitations, human/infra blockers, and next review date/triggers. Publish separate initiative and charter evidence reports; neither may say complete with unresolved blockers. Report OPEN/BLOCKED/BELOW TARGET accurately until all required outcomes are proved. A record of available capability is not evidence that the full charter is achieved. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    },
    {
      "ownerTaskId": "18.8",
      "phaseId": "18",
      "closureState": "open",
      "requirement": "Verify branch tip is on `origin/main`, no relevant change or local- only commit remains, all derived artifacts are current, and every checkbox is supported by its own evidence. Require the current charter gate to pass, all required targets to be met, and zero unresolved blockers across tasks, phases, dependencies, runtimes, and human evidence. Only then close the initiative and claim dated charter completion; never claim timeless perfection.",
      "gapRefs": [
        "G1",
        "G2",
        "G3",
        "G4",
        "G5",
        "G6",
        "G7",
        "G8",
        "G9",
        "G10",
        "G11",
        "G12",
        "G13",
        "G14",
        "G15",
        "G16",
        "G17",
        "G18"
      ],
      "dependencyTaskIds": ["18.1", "18.2", "18.3", "18.4", "18.5", "18.6", "18.7"],
      "dependencyRationales": [
        "Requires every gap and required charter workflow to reconcile to direct evidence.",
        "Requires the fresh source/runtime audit with new gaps owned.",
        "Requires current source and comparative capability gaps to be resolved.",
        "Requires the clean-state full charter and operator benchmark evidence.",
        "Requires the final security/reliability game day without hard-lock events.",
        "Requires all applicable final verification and derived artifacts.",
        "Requires accurate open-blocker reporting and current evidence documentation."
      ],
      "requiredProofScopeRefs": [
        "source-inspection",
        "static-contract",
        "automated-behavior",
        "independent-verification"
      ],
      "evidencePlan": {
        "id": "evidence-18-8",
        "state": "planned",
        "proofScopeRefs": [
          "source-inspection",
          "static-contract",
          "automated-behavior",
          "independent-verification"
        ],
        "evidenceClassRefs": [
          "source-review",
          "automated-static",
          "automated-test",
          "independent-verification"
        ],
        "artifactLocators": [],
        "requiredManifestPattern": "docs/audits/eve-sota-evidence/phase-18/task-18-8.json",
        "limitation": "This is a preregistered evidence plan, not executed evidence; it does not prove the task or any gap closed."
      },
      "exitCriterion": "Verify branch tip is on `origin/main`, no relevant change or local- only commit remains, all derived artifacts are current, and every checkbox is supported by its own evidence. Require the current charter gate to pass, all required targets to be met, and zero unresolved blockers across tasks, phases, dependencies, runtimes, and human evidence. Only then close the initiative and claim dated charter completion; never claim timeless perfection. Exit only when every clause has direct admitted evidence at each named proof boundary, all dependencies are complete, the required negative control has been observed red and then green, and exact limitations remain explicit."
    }
  ],
  "limitations": [
    "Open rows contain evidence plans only; a planned scope or manifest path is not an executed result.",
    "Completed Phase-0 rows link direct repository evidence created before or during schema admission; later phase closure still requires task-specific evidence manifests.",
    "A matrix verifier proves ownership, dependency, and proof-boundary integrity, not the truth of a future runtime claim."
  ]
}
