# Enterprise Action Requests — candidate 0.1.0 Read README.md, model-spec.md and adoption-limits.md before proposing use. This is a reviewable candidate, not a production authority service. Do not infer permission from ActionDefinition, a stewardship role, a WriteGrant, a capability, an obligation or the presence of a tool. Use current independently established host identity, principal/actor scopes, issuer-standing evidence, audience, purpose, time and read permission. An unresolved value is insufficient context, not permission. Proposed actions stay proposals. Never call an arbitrary command/URL or replace a failed retry key automatically. Recover a lost response by lookup/retry with the identical intent/key only when store continuity is trusted. After restore or uncertain continuity, obtain external latest-history reconciliation before dispatch. Epoch and content hashes cannot detect a coherent old database. Do not broaden the model's effect boundary or claims to compensate for missing production infrastructure. Treat the schema, code, definitions, policy inputs and export manifests as exact pinned artifacts. Run the explicit companion after native outer validation. Internal archive validity does not authorize import, prove latest history or grant disclosure. Preserve originals and append corrections. Never rewrite released versions or raw research/audit evidence. The package's normative code is generated action_bundle.py with sibling action.schema.json; action.py, history.py and native.py are its source components. Regenerate and rerun source/bundle tests after edits. Do not edit generated bundle independently. Actual frozen Claude/Grok implementation audits and three native installations are required before release; studies do not satisfy that gate.