# Review and publication decision Decision: publish the bounded original Enterprise Assertion Provenance 0.1.0 companion as **reviewable-draft** under the owner's standing publication authorization. EM-XCT-03 remains partially covered. This is an engineering decision by Codex after preserving the independent evidence; neither provider grants publication authority. ## Evidence and disagreement Claude and Grok independently researched the same public boundary and synthetic cases. Six primary-source comparisons and three exact legacy specifications were recorded. Both later reviewed frozen implementation inputs separately. The first Claude audit returned **BLOCK**; the first Grok audit returned **ACCEPT WITH LIMITS**, while identifying a similar correction problem. The votes were not averaged: concrete defects were reproduced against the original source and corrected. Both follow-up audits accepted the revised candidate with limits. A final focused audit from each provider assessed the last label-change, field-pin and import-clock fixes and returned **ACCEPT WITH LIMITS**. All original responses, exact supplied prompts, content hashes, declared model identities and scope limits are preserved in the [research dossier](https://ver.cy/enterprise/research/em-xct-03/). No historical verdict has been rewritten. Earlier passes supplied code/schema/tests, full semantic contract, AGENTS, native harness and direct requirements. The compact closure pass supplies full current code and all 76 tests plus exact changed contract excerpts. The preceding Grok pass explicitly reported a truncated test file despite seeing the sentinel; its disclosure remains preserved. The closure response gives the actual completeness statement for the smaller input. The earlier follow-up additionally supplied the full 4-bundle/8-layer/20-question tree and per-type whole-object facets. The AP-ACT05 identity clarification was described in the final brief; the resulting tree was not independently reinspected. Provider reviews were static: they did not run the tests, recompute hashes, inspect every package file or ratify parent specifications. ## Disposition of concrete findings | Finding | Disposition | |---|---| | Metadata correction froze after a cited revision changed | Fixed: unchanged references retain exact historical pins within the same field; new references require active current heads | | Optional calendar support, fractional revision encodings and value-equal prefix rewrite | Fixed: strict independent ASCII/calendar parsing, checker availability, integer representation and exact encoded-byte comparisons | | Self-derivation through a prior revision of the same account | Fixed: transitive own-ID dependency rejected | | Current capture failure hidden behind a generic changed pin | Fixed: current availability/integrity disclosed separately from the historical basis | | Snapshot digests written without companion verification | Fixed: snapshot/predecessor/aggregate checks, separate native envelope validation, unique successor fact ID | | Raised confidence over stale/withdrawn basis | Fixed for non-insufficient genesis and label/basis/activity changes: current active dependency closure without unavailable/mismatched Captures. Corrections require a different review Activity ID recorded after the previous assessment; explicit basis receipts cannot follow review receipt. This closes new-ID/genesis, unchanged-label basis-swap and same-ID review-metadata bypasses | | Future-dated import could freeze receipts | Fixed: mandatory trusted now and valid current configuration in import/migration/snapshot checks; admit/view also reject future receipts | | Pin retained in one field reused as historical in another | Fixed: retention is keyed by reference field | | Unspecified canonical JSON; ambiguous relocation action; acquisition prose | Fixed: named exact vercy-python-json-v1 encoding, explicit external/source versus Capture identity and all-input acquisition rules | | Host API can return diagnostics/full ledger to a writer-only caller | Retained integration requirement: never expose this trusted-host API directly; authenticate and return only generic rejection or receipt | | Retrospective event input metadata and historical origin declaration | Explicitly scoped: not proof of actor knowledge; origin changes trigger review, not silent repinning | | Quadratic validation cost, size limit and no rollover | Explicit bounds: 10000 records/8 MiB are structural ceilings, not tested production capacity; host budgets and a migration plan are required | | Existing-Dimension migration, PKI, source truth/independence, probabilistic confidence, fine-grained disclosure | Deferred; no conformance or production-service claim | ## Executed validation 81 behavior tests passed locally. The native acceptance harness passed in three fresh synthetic Dimensions (startup, group, AI team), with exact own-companion pins, optional semantic-only WM-XCT-012, replayed admission, two successive snapshots, unchanged external claims, nested-malformed rejection, truncation rejection and snapshot-digest tamper rejection. These runs were performed by Codex tooling, independently of the static provider verdicts. The outer native validator accepts an arbitrary object-shaped value; explicit companion validation remains mandatory. The complete published ZIP is checked after deployment and its tests/native acceptance rerun from downloaded bytes; the resulting report belongs in the public dossier. This sentence is a required release check, not a claim that a prepublication candidate was already live. ## Adoption boundary Use this as a bounded declared-provenance reference with a trusted host, latest complete root, current configuration, reliable receipt clock, serialized updates and whole-register reader/purpose gate. It cannot verify source authenticity, assess people, establish proposition truth, prove independent sources, grant permissions, enforce retention/erasure, or act as an enterprise-scale evidence service. Assessment records preserve attributed judgements and dependency warnings; the reliance guard is not a universal confidence-quality oracle. Evidence relevance and real-world review execution remain external declarations. Published package lifecycle does not upgrade reviewable-draft assurance. A later compact closure audit again differed: Claude BLOCK, Grok ACCEPT WITH LIMITS. Claude demonstrated that a metadata correction could launder the receipt of an old alternate review. The final fix compares both timing guards to the review identity’s immutable revision-1 receipt. Three counterexamples now reject; a legitimately later review with corrected notes still admits. The final first-registration follow-up from both providers closes this specific finding with ACCEPT WITH LIMITS. The earlier blocking report and reproductions remain preserved.