{
  "schemaVersion": "eve-sota-governed-delivery-lifecycle.v1",
  "initiativeId": "eve-sota-gap-closure-2026-09-01",
  "taskId": "2.1",
  "evaluatedOn": "2026-09-02",
  "sourceEvidence": {
    "authoritative": [
      {
        "path": "EVE_SOTA_GAP_CLOSURE_TODOS_2026-09-01.md",
        "digestOf": "task-requirements",
        "sha256": "d7a8a531fcd4237a563360e98c57acf25196d8098f425311af586a70610d0a1c",
        "bytes": 55106
      },
      {
        "path": "docs/audits/eve-sota-gap-task-evidence-exit/2026-09-01.json",
        "digestOf": "file-bytes",
        "sha256": "6ef34a54cb8c89a4b48b474168901a2078a5a83ffa3a50e2ad43d76305d4e1dd",
        "bytes": 393835
      },
      {
        "path": "docs/agents/claude-workbench-agent.md",
        "digestOf": "file-bytes",
        "sha256": "22fbc724533a33318c310ba3f83e1d3294129d6b389dba603332fcbc3e62e7fe",
        "bytes": 7876
      },
      {
        "path": "libs/oshun/workbench-kit/src/stages.ts",
        "digestOf": "file-bytes",
        "sha256": "ca7e08102ccad6cbdfe3535ac81b3953d2c7a981dc2d9c6763c55657344ef102",
        "bytes": 35385
      },
      {
        "path": "apps/oshun/bff/src/workbench/intent-machines.ts",
        "digestOf": "file-bytes",
        "sha256": "7747c1063ef31130d370f97e01c70cfad0517531d7e419829796c8b0ae5b532c",
        "bytes": 13057
      },
      {
        "path": "apps/oshun/bff/src/workbench/intent-store.ts",
        "digestOf": "file-bytes",
        "sha256": "dda7eb6b9ba45e76682357c2da9af6eddf9d717f9bd8b635a83006279b8cfa27",
        "bytes": 85202
      },
      {
        "path": "apps/oshun/bff/src/workbench/work-queue.ts",
        "digestOf": "file-bytes",
        "sha256": "6a661859ca902b0ae7fb1eda47eab986c5d3589b6498ba3108a685fc040b08d2",
        "bytes": 25600
      },
      {
        "path": "apps/oshun/bff/src/workbench/artifact-verifier.ts",
        "digestOf": "file-bytes",
        "sha256": "8cfcc6af209a1b8950e7cbc5047f13ba48f3097c62ba81a0ff95e068d1f0ceb1",
        "bytes": 11718
      },
      {
        "path": "apps/oshun/bff/src/workbench/shipped-verification.ts",
        "digestOf": "file-bytes",
        "sha256": "19988353c2402e1a601a2c420315a726c6837ef11993a226e9443e0163a76d49",
        "bytes": 3134
      },
      {
        "path": "apps/oshun/bff/src/workbench/workbench-agent-tools.ts",
        "digestOf": "file-bytes",
        "sha256": "066fb616e4b4b0c7d023e5b43b6b3c65a2944417ae1eb54a4e37050558ad79dd",
        "bytes": 78410
      },
      {
        "path": "tools/eve-codex-agent.mjs",
        "digestOf": "file-bytes",
        "sha256": "c33a3425d4466385518058f26d5218904598b2c0b326a384140d25333d4be3b3",
        "bytes": 12462
      },
      {
        "path": "tools/eve-codex-agent-lib.mjs",
        "digestOf": "file-bytes",
        "sha256": "637d6b36eadc7fa1ab23eaac12f497fbd253da022fd54b8f419a6f5febdab953",
        "bytes": 2380
      },
      {
        "path": "tools/workbench-mcp/server.mjs",
        "digestOf": "file-bytes",
        "sha256": "b115fdaab072c5d1144d199455972a39e6bad87e371d0d82d4d6a0d06578b583",
        "bytes": 12035
      }
    ],
    "implementation": [
      {
        "path": "docs/audits/eve-sota-governed-delivery-lifecycle.schema.json",
        "digestOf": "file-bytes",
        "sha256": "ddaebe37391e0f2fe4d1ff1a46c87cbf8a6a6918bb837c0f1eed6e246a397772",
        "bytes": 16341
      },
      {
        "path": "tools/eve-everywhere/generate-governed-delivery-lifecycle.mjs",
        "digestOf": "file-bytes",
        "sha256": "f3a2972d9ed6b0fb67d2ea5b6534916b5feba1c39a7ffdb302cc0531b0df1297",
        "bytes": 35770
      },
      {
        "path": "tools/eve-everywhere/verify-governed-delivery-lifecycle.mjs",
        "digestOf": "file-bytes",
        "sha256": "d02b8c3b9ff351ae8a79cbaa6c5dde4298f140c9ebd0ad3b53eb1bc4380a6281",
        "bytes": 16218
      },
      {
        "path": "tools/eve-everywhere/verify-governed-delivery-lifecycle.test.mjs",
        "digestOf": "file-bytes",
        "sha256": "7fd1ff4227f6b3a2ec880f252b8b0018505c359023c24e83c6df461127c4f2bb",
        "bytes": 15001
      }
    ]
  },
  "observedBaseline": {
    "declaredEntityKinds": ["work-item", "decision", "thread"],
    "workItemStatuses": [
      "draft",
      "triaged",
      "ready",
      "leased",
      "in-progress",
      "in-review",
      "shipped",
      "verified",
      "parked",
      "rejected"
    ],
    "decisionStatuses": ["draft", "proposed", "accepted", "superseded", "rejected"],
    "workItemTransitionIds": [
      "triage",
      "make-ready",
      "lease",
      "release-lease",
      "start",
      "submit-review",
      "reopen-from-review",
      "ship",
      "verify",
      "park",
      "unpark",
      "reject"
    ],
    "decisionTransitionIds": ["propose", "accept", "reject-decision", "supersede"],
    "workItemEventTypes": [
      "work-item.created",
      "work-item.lease-renewed",
      "work-item.refs-orphaned",
      "work-item.report",
      "work-item.ship-verify-gap",
      "work-item.transitioned",
      "work-item.triaged",
      "work-item.updated"
    ],
    "decisionEventTypes": [
      "decision.created",
      "decision.refs-orphaned",
      "decision.report",
      "decision.transitioned",
      "decision.updated"
    ],
    "threadEventTypes": ["thread.message-posted", "thread.opened"],
    "queueOperationIds": [
      "recoverOrphans",
      "listReady",
      "lease",
      "killSwitch",
      "triage",
      "report",
      "markShipped"
    ],
    "mcpToolIds": [],
    "controls": {
      "appendOnlyEventLedger": true,
      "atomicAppendAndProjection": true,
      "machineOnlyVerification": true,
      "observedMainCommitCheck": true,
      "durableGoalRequirementPlanEntities": false,
      "dependencyReadiness": true,
      "monotonicFencingToken": true,
      "drainExecutable": true,
      "typedTriageEnforced": true,
      "operatorReadModelWithoutAuthority": true,
      "executionIsolationEnforced": true,
      "providerFreeModelAndParityProof": true
    }
  },
  "decision": {
    "status": "agent-adopted-pending-named-ratification",
    "implementationAuthorized": true,
    "liveAutonomousActivationAuthorized": false,
    "lifecycle": {
      "id": "eve.governed-delivery.v1",
      "sequence": [
        "goal",
        "requirements",
        "dependency-dag",
        "verification-plan",
        "work-items",
        "leases",
        "review",
        "ship",
        "verify"
      ],
      "planningRevisionRule": "Goal, requirement, dependency, verification-plan, and work-item decompositions are immutable versioned plan revisions. A change appends a successor with a new digest and preserves the superseded revision and its decision references.",
      "stages": [
        {
          "id": "goal",
          "durableOutput": "An actor-attributed goal revision with objective, non-goals, source provenance, authority boundary, risk class, ambiguity record, and accepted human-decision references.",
          "admissionGate": "Material ambiguity, conflicting human direction, or missing authority blocks decomposition until an explicit clarification or accepted decision is recorded.",
          "implementationOwnerTaskIds": ["11.2"]
        },
        {
          "id": "requirements",
          "durableOutput": "Stable requirement ids with statements, acceptance criteria, non-goals, source refs, decision refs, risk, and exact goal-revision provenance.",
          "admissionGate": "Every material goal clause maps to at least one requirement or an accepted human decision explaining its exclusion; an uncovered clause fails closed.",
          "implementationOwnerTaskIds": ["11.2"]
        },
        {
          "id": "dependency-dag",
          "durableOutput": "A versioned acyclic graph with stable node ids, typed edges, edge rationale, requirement coverage, and a canonical graph digest.",
          "admissionGate": "Unknown nodes, cycles, uncovered requirements, and a dependency bypass without a superseding accepted decision make the plan inadmissible.",
          "implementationOwnerTaskIds": ["2.2", "11.2"]
        },
        {
          "id": "verification-plan",
          "durableOutput": "A preregistered verification matrix binding each requirement and work item to proof boundaries, commands or human rubric, negative controls, expected outcomes, rollback evidence, and explicit limitations.",
          "admissionGate": "No work item becomes ready or leasable unless every requirement it owns has direct planned evidence and every high-risk claim has an applicable red control.",
          "implementationOwnerTaskIds": ["11.2", "12.2"]
        },
        {
          "id": "work-items",
          "durableOutput": "Atomic work items carrying goalRevisionId, planRevisionId, requirementRefs, dependencyRefs, verificationPlanRefs, scope, non-goals, risk, expected artifacts, and reversal or compensation boundary.",
          "admissionGate": "An item with an orphan reference, implicit scope, no owned requirement, no proof plan, or an unclassified irreversible effect cannot enter ready.",
          "implementationOwnerTaskIds": ["2.2", "11.2"]
        },
        {
          "id": "leases",
          "durableOutput": "An actor-attributed, TTL-bounded lease acquired through the canonical queue API and represented by the ordinary work-item lifecycle events.",
          "admissionGate": "Dependency readiness, concurrency, spend, fencing, idempotency, capability, and resource preflight all pass before acquisition; refusal emits no partial state.",
          "implementationOwnerTaskIds": ["2.2", "2.3", "2.6"]
        },
        {
          "id": "review",
          "durableOutput": "Append-only progress and completion reports, artifact and command evidence, an independently attributed review verdict, and either an in-review state or an evented reopen/triage outcome.",
          "admissionGate": "Completion does not imply approval. Review checks the pre-registered requirements and evidence; rejection or ambiguity returns through an explicit event rather than erasing history.",
          "implementationOwnerTaskIds": ["2.4", "11.4"]
        },
        {
          "id": "ship",
          "durableOutput": "A shipped transition containing the commit actually observed on origin/main plus repository and artifact provenance.",
          "admissionGate": "Only an approved in-review item may ship; configured repository verification fails closed when the commit is absent, unmerged, or unverifiable.",
          "implementationOwnerTaskIds": ["2.3", "2.6"]
        },
        {
          "id": "verify",
          "durableOutput": "A separately attributed verifier result per requirement and plan row: verified, ship-verify-gap, contradicted, or explicitly not-machine-checkable, with evidence and limitations.",
          "admissionGate": "The implementer cannot grant verified. Only direct evidence at the registered boundary closes a requirement; missing or indirect evidence stays open and triaged.",
          "implementationOwnerTaskIds": ["2.4", "2.7", "11.4"]
        }
      ]
    },
    "invariants": {
      "humanDecisions": {
        "agentMayDraftOrPropose": true,
        "agentMayAcceptForHuman": false,
        "acceptedDecisionRequiredFor": [
          "material-goal-or-non-goal-change",
          "requirement-removal-or-scope-reduction",
          "dependency-bypass",
          "verification-waiver",
          "irreversible-action-authorization",
          "cloud-spend-or-live-autonomy-activation"
        ],
        "preservation": "Decision events, rejected options, rationale, actor, timestamp, and supersedes chain are append-only. A plan revision references the exact decisions it consumed; summaries never replace the source record.",
        "conflictRule": "Conflicting current human decisions stop planning and name the conflict; recency, model confidence, or drain priority cannot silently choose one."
      },
      "requirementTraceability": {
        "stableIdsRequired": true,
        "bidirectionalLinksRequired": true,
        "directEvidenceRequiredForClosure": true,
        "noOrphanRefs": true,
        "requiredChain": [
          "goalRevisionId",
          "requirementId",
          "dependencyNodeId",
          "verificationPlanRowId",
          "workItemId",
          "leaseEventSeq",
          "reviewEventSeq",
          "shippedCommitSha",
          "verificationResultId"
        ],
        "notMachineCheckableClosesRequirement": false,
        "scopeReductionRequiresAcceptedDecision": true
      },
      "reversibleBoundaries": {
        "planningChangesAppendSuccessorRevision": true,
        "activeLeaseCanReturnOnlyByEventedReleaseOrTriage": true,
        "reviewRejectionReopensByEvent": true,
        "shippedFactCanBeUndoneInPlace": false,
        "verifiedFactCanBeUndoneInPlace": false,
        "postShipRecovery": "Create a linked repair or revert work item and new commit; never rewrite the shipped or verification event.",
        "irreversibleEffectRule": "Before lease, name the effect, exact confirmation, blast radius, and compensation or explicit irreversibility. After execution, reversal is a new attributed action with its own evidence."
      }
    },
    "leasePathParity": {
      "invariantId": "drain-hand-lease-ledger-state-parity",
      "handLeasedOperations": [
        "listReady",
        "lease",
        "buildTaskBrief",
        "report:progress",
        "report:completion",
        "markShipped",
        "runArtifactDiffVerifier"
      ],
      "drainedOperations": [
        "listReady",
        "lease",
        "buildTaskBrief",
        "report:progress",
        "report:completion",
        "markShipped",
        "runArtifactDiffVerifier"
      ],
      "drainIsSelectionAndSupervisionOnly": true,
      "drainDirectProjectionMutationAllowed": false,
      "drainDirectLedgerAppendAllowed": false,
      "drainSpecificLifecycleTransitionAllowed": false,
      "drainMayInferShipOrVerifyFromProcessExit": false,
      "foldedStateExactFields": [
        "kind",
        "title",
        "body",
        "status",
        "priority",
        "expectation",
        "graphRefs",
        "orphanedRefs",
        "lease"
      ],
      "semanticEventExactFields": [
        "entityKind",
        "eventType",
        "payload.phase",
        "payload.from",
        "payload.to",
        "payload.transitionId",
        "payload.lease",
        "payload.branch",
        "payload.commits",
        "payload.prUrl",
        "payload.observedCommitSha",
        "payload.outcome",
        "payload.graphVersion"
      ],
      "normalizedNonStateFields": ["seq", "createdAt", "conversationRef"],
      "provenanceRule": "Actual actor identity is never normalized away. A parity comparison uses the same logical item, actor, clock, TTL, reports, commit, artifact, and verifier result; drain-run selection metadata lives on its own orchestration record and cannot alter work-item reduction.",
      "equivalenceRule": "For identical logical inputs, folding the hand-leased and drained work-item event streams yields equal state on every foldedStateExactField and equal ordered semantic events on every semanticEventExactField after only normalizedNonStateFields are removed.",
      "requiredExecutableProofOwnerTaskId": "2.7"
    },
    "implementationGates": [
      {
        "id": "queue-dependency-and-fencing-contract",
        "state": "implemented",
        "ownerTaskId": "2.2",
        "exactCondition": "Queue semantics enforce dependency readiness, concurrency and spend admission, priority fairness, TTL renewal, monotonic fencing, idempotency, retry bounds, poison quarantine, orphan recovery, and terminal ownership."
      },
      {
        "id": "bounded-resumable-drain",
        "state": "implemented",
        "ownerTaskId": "2.3",
        "exactCondition": "A bounded dry-runnable drain invokes only the canonical queue operations, persists its run/checkpoints, supervises process groups and resources, resumes safely, and has no unbounded loop."
      },
      {
        "id": "typed-triage",
        "state": "implemented",
        "ownerTaskId": "2.4",
        "exactCondition": "Every verifier gap, test failure, conflict, ambiguity, budget exhaustion, and refusal becomes a distinct evidence-bearing triage record; none silently requeues or closes."
      },
      {
        "id": "operator-read-model",
        "state": "implemented",
        "ownerTaskId": "2.5",
        "exactCondition": "The attributed fleet read model exposes queue/dependency/lease/triage/run/outcome/kill-switch state and trace links without granting mutation authority."
      },
      {
        "id": "execution-isolation",
        "state": "implemented",
        "ownerTaskId": "2.6",
        "exactCondition": "Branch/worktree, dirty-tree, remote divergence, credentials, command roots, egress, secrets, artifacts, and implementer/verifier identity are fail-closed."
      },
      {
        "id": "provider-free-model-and-parity-proof",
        "state": "implemented",
        "ownerTaskId": "2.7",
        "exactCondition": "A provider-free state model proves the drain/hand parity rule and duplicate, expiry, renewal, stale-fence, crash, cycle, poison, cancellation, and restart properties."
      },
      {
        "id": "gated-live-drain-and-soak",
        "state": "not-implemented",
        "ownerTaskId": "2.8",
        "exactCondition": "Only after Security, Evaluation, and Reliability admission, a diverse real backlog drain and supervised soak meet preregistered success, intervention, retry, duplicate-action, time, cost, and verification floors."
      }
    ],
    "rejectedOptions": [
      {
        "id": "queue-only-lifecycle",
        "reason": "A queue without durable goals, requirements, dependencies, and proof plans scales implementation throughput while losing whether the right work was selected."
      },
      {
        "id": "drain-specific-state-machine",
        "reason": "A second transition or persistence path makes drained work semantically different from an operator lease and creates an unreviewed shortcut around the intent ledger."
      },
      {
        "id": "mutable-plan-document",
        "reason": "Overwriting a plan erases prior human decisions, scope changes, and the requirement chain needed to explain an outcome or recover safely."
      },
      {
        "id": "completion-or-merge-means-verified",
        "reason": "An agent report or merged commit proves activity, not that requirements or registered evidence passed; verification stays separately attributed and fail-closed."
      },
      {
        "id": "manual-path-exception",
        "reason": "Letting hand-leased work bypass the drain contract would make the parity invariant vacuous and preserve an ungoverned path for high-impact actions."
      }
    ],
    "ratification": {
      "implementationPosture": "effective-on-merge",
      "liveAutonomyPosture": "blocked-pending-named-ratification-and-cross-phase-gates",
      "reviewers": [
        { "role": "Product owner", "status": "pending" },
        { "role": "Eve workbench/platform owner", "status": "pending" },
        { "role": "Security owner", "status": "pending" },
        { "role": "Evaluation owner", "status": "pending" },
        { "role": "Reliability owner", "status": "pending" }
      ],
      "crossPhaseGate": "Task 2.8 remains blocked until the Phase 4 Security, Phase 12 Evaluation, and Phase 13 Reliability gates admit live autonomy."
    },
    "limitations": [
      "This decision closes task 2.1 only. It defines an implementation contract; it does not add durable goal, requirement, dependency, verification-plan, or drain records.",
      "The observed workbench baseline is source inspection of the current repository, not a live Postgres, MCP, coding-agent, or provider execution.",
      "The current event ledger and queue already provide useful work-item, decision, lease, ship, and artifact-verification behavior, but they do not yet enforce the complete governed-delivery chain or drain/hand parity proof.",
      "Tasks 2.2 through 2.7 own the missing runtime contracts and executable parity/fault proof; task 2.8 owns gated live backlog and soak evidence.",
      "Named human ratification is pending, live autonomous activation is forbidden, Phase 2 remains open, and gaps G1 and G12 remain open for final task 18.1 reclassification."
    ]
  },
  "outcome": {
    "taskClosed": true,
    "phaseClosed": false,
    "gapRefs": ["G1", "G12"],
    "gapStatus": "open",
    "finalReclassificationTaskId": "18.1",
    "reason": "The lifecycle and parity contract are now explicit and fail-closed, but their runtime implementation, model, live drain, and soak remain owned by later tasks."
  },
  "recordDigestSha256": "b0029d9df8179287204e006b55cd4e9410898127b9ac89eb0ce6cbf5cd632418"
}
