# Publication and adoption qualifications — frozen R3 candidate This addendum makes the reviewed reference's remaining limits explicit. It does not change its code, schema, semantic fields, fixture installer or frozen test reports. Original candidate files retain their capture-time wording; the eventual `profile-manifest.json` establishes published lifecycle and the eventual `review.json` establishes release disposition. A candidate/simulationOnly fixture lock is not publication evidence. ## Useful scope Adopt a descriptive ActionDefinition to catalog a governed operation. Description, guidance actions and the question field named `permittedActionId` confer no execution or disclosure right. That field is a navigation reference to guidance only. Questions are host guidance with evidence requirements, not machine-verified truth or authority decisions. The executable companion is an isolated synthetic example: replacement of ordered opaque labels in one SQLite store. It is not a production workflow/authorization service. The owner of an adopting host must independently supply authentication, legitimate principal/actor authority and issuer standing, time, disclosure, database/file isolation, rate/admission controls and recovery continuity. The finite event budget is shared across actors. Any current right holder can consume it through event-producing calls. It supports at most about 3,333 pending submissions or 2,500 first commits before other events; no quota, fair sharing or rollover exists. The final empty policy row reserves global revocation, not execution capacity. ## History and disclosure The engine enforces a nondecreasing host clock for every transaction. Archive replay checks control order, operation completeness, policy selection and effect consistency. Policy and event times are monotonic within their tables; definition and resource creation times are bounded only by the cut clock and use-time checks. Replay does not impose one globally monotonic recorded-time sequence across all administrative tables. A consistently rewritten snapshot with a backdated administrative row can pass. This is a known validator limit, not evidence that the engine emitted it. Neither archive validity nor matching epoch proves authenticity, latest state or safe restoration. After uncertain recovery, halt dispatch and reconcile against an external trusted latest-history anchor. Callers receive only receipt or observation projections with global sequence/controlSequence omitted; they do not receive Submission, Delivery, Try, Disposition or KeyRetirement records through these endpoints. Those are privileged evidence requiring separate host projections. A receipt includes beforeLabels and afterLabels of the shared synthetic resource, potentially reflecting earlier work under another purpose/audience. Current request read permission in this fixture exposes that whole receipt; a production host needs an independently reviewed resource/disclosure boundary. No per-field confidentiality or cross-context noninterference is claimed. Retired-key cancel, like lookup/dispatch, returns key-retired and retained receipt to a current reader without a new event. Observe on a retired key is withheld. Same-pin definition retirement or expiry blocks compensation. Resource revision zero is host administration; later revisions belong to the local executor's guarded effect. Native projections never become an execution master. ## Installation and evidence qualifications The test installer copies nine frozen assets including its required adoption documents and dependency declaration. It does not itself run a scenario or produce an execution snapshot; the acceptance workflow creates the cut and stores snapshot/manifest/records inside each fresh synthetic Dimension. It tests one cut, not incremental installation or existing-Dimension migration. Published WM-XCT-040 generic composition remains unsupported for this empty fact-path binding. The candidate fixture lock includes canonical release URLs together with candidate/simulationOnly labels and exact local hashes. Do not resolve that candidate URL and substitute returned bytes for the installed pin. Resolve a released package separately and verify its actual published digest before adoption. The nine-file fixture does not install review.json or this addendum. Its README also links to model-fields.md, whole-object-coverage.yaml, mastership-and-rights.yaml, composition.yaml, crosswalk.json, invariants.md and migration.md, which are not installed. Claims about all adoption documentation mean only the nine listed assets; consult the complete released package and retain its documents locally for offline use. The installer is a test helper, not the recommended production rollout path. The 69 source tests and the same 69 on the standalone bundle are distinct behavioral cases, not 138 independent requirements. Three native installations use the pinned toolchain and exact installed bytes. Capacity cases seed valid histories with SQL before replay/rollback tests; they do not demonstrate 10,000 public API calls or load performance. The intent half of the newline test is not independently discriminating because authentication/scope also reject those modified intents; definition/policy halves and static source analysis support the grammar correction. Generated-ID collision, snapshot-level newline identifiers and cross-table backdating have no dedicated R3 tests. Neither hardware faults nor timing-channel resistance was tested. Unit reports record Python/SQLite versions; the native report records exact source/tool pins but does not independently record runtime versions. Do not attribute an unrecorded runtime inventory to that report. The dependency declaration is jsonschema==4.26.0; it is externally installed and not bundled. ## Further work Future pinned revisions should strengthen cross-table historical clock validation, add the missing discriminating edge tests, normalize standalone parse's oversized-integer ValueError, improve resource/event mastership wording and guidance reference naming, retain release review documents in installation, and record native runtime versions. Native multi-cut support, external continuity, real authority integration, stronger disclosure, quotas/rollover and broader action parameter/effect contracts require separate design and acceptance. EM-XCT-07 remains a partially covered research contour after this bounded increment. ## Documentation precision Frozen field-table prose is informative; closed schema and the semantic contract govern the bounded reference. Resource references can name a resource absent at admission. An allowed try rejects the precondition only if the resource is still absent or at a different revision at that try; a pending request can commit after later creation. Rule issuerId denotes the policy issuer, not an event issuer. Pin.revision has no auxiliary host sequence implementation. The field tables omit Policy array cardinality (0 to 128 Rules), the standalone Labels definition, and code-validated snapshot/manifest/resource rows; they are not a complete replacement for schema and code. README wording about attempts means effect execution needs current execute permission; another retained right can still produce a denied try. Historical “R2 adds” wording remains capture-time history. The acceptance workflow executes the installed companion; tests themselves are not installed. The separate action.py, history.py and native.py sources linked by the README also remain in the full package; the fixture installs action_bundle.py. Editorial provenance: both providers reviewed the original supplement and its wording delta. The two final sentences concerning later resource creation and uninstalled source modules implement Claude's final nonblocking wording recommendations; they were applied by Codex without another provider round. No executable or frozen semantic file changed.