# Agent use Read model-spec.md, provenance.schema.json and provenance.py before using the register. Read spec.json for the normative Bundle/Layer/Finding/Question/Artifact/Action tree. Unknown context stays unknown. A source assertion or AI inference never becomes direct observation from repetition or human approval. Use only a trusted host that authenticates callers, owns the complete current root/configuration and supplies the receipt clock. Static validation/import do not authenticate history. Invoke admit on every new row, validate_extension against the latest trusted root, and the companion on every nested native snapshot. Do not expose the full returned ledger or diagnostics to a write-only caller. Denial is all-register; partial views are unsupported. Preserve withdrawn records, conflicting evidence, changed-dependency warnings and distinct role attribution. A digest is not truth, consent or verified authorship. Do not infer independence, average qualitative labels, contact people, fetch sources or change external claims automatically. The package grants no operational permission. Native storage operator is distinct from source authors/assessors. No Python -O requirement is needed for enforcement: production require() checks do not use assert. Runtime dependency: Python 3.11+ and jsonschema with URI/date-time format support. Resolve methods and external claims under separately governed host policies. The acceptance harness itself requires normal non-optimized execution. The companion explicitly fails closed if URI/date-time checkers are missing, parses every timestamp as canonical ASCII UTC, and rejects fractional revision encodings. Enforce request limits before parsing; the companion also caps serialized JSON at 8 MiB. Retained historical pins remain valid for metadata corrections; only newly introduced/changed immediate references must name current active heads. Historical dependencies stay visible as requiring review. Call validate_snapshot on native facts to check aggregate identity, exact snapshot digest and predecessor linkage, then perform native V3 validation separately. A new snapshot still requires the host's trusted latest predecessor. Import/migration/native snapshot checks require explicit trusted `now`; offline validation without it is not live admission. Retained pins must stay in the same reference field. Genesis and changes to label/basis/activity of a non-insufficient assessment require a current active dependency closure without unavailable/mismatched Captures. Corrections need a different review Activity ID first registered after the prior assessment; its revision 1 receipt must not predate explicit basis receipts. Import/snapshot configuration must be valid at trusted now. Read the exact vercy-python-json-v1 encoding and operational bounds in model-spec.md.