# Review and limited publication decision Decision by Codex under the owner's standing publication authorization: publish the bounded Enterprise Temporal History 0.1.0 reference as **reviewable-draft**, with the missing Grok implementation audit prominently disclosed. This is not completed research or production readiness. The Enterprise program AGENTS.md expressly allows a visible draft with an unavailable pass while keeping the contour unfinished. Publication does not confer truth, IAM, legal, standards or domain-transition assurance. Both independent studies used the same public brief and synthetic cases. Claude CLI and Grok Heavy browser responses and their source-verification limits are preserved. The first Claude frozen no-tools audit returned ACCEPT WITH LIMITS and raised concrete defects. Codex reproduced archive failure after pin retirement and acceptance of transplanted headers, then fixed them. The second audit found a host/native clock claim mismatch, missing forward-clock recovery disclosure, asymmetric predecessor checks and a direct native-test gap. Codex corrected those and ran 20 added behavior cases. The third audit assessed the full revised code, schema, tests, contract, full named spec, native harness, tree, crosswalk, pins, facets and rights data without executing them. Its exact response is in the public dossier. Neither provider verified hashes or the whole native toolchain; those checks were executed separately by Codex tooling. Grok's separate code-audit attempt could not submit a prompt because the browser repeatedly timed out and lost its debugger connection. It has **no implementation verdict**. The original research is not relabeled as a code audit. The publisher requires an explicit draft exception, both completed studies, at least one accepting frozen audit, visible holds and recovery instructions; BLOCK or a failed semantic review cannot use this exception. ## Concrete changes across remediation audits - Timeline-host receipts and native snapshot storage receipts are distinct; imported receipt authenticity is a host obligation. The fixtures explicitly install simulated pre-existing host history. - A forward clock excursion can block all access until catch-up; host clock-skew guards and explicit external recovery preserve evidence and disclose continuity loss. - Scope matching precedes deep history diagnostics. Current and previous native envelopes receive symmetric checks; successor storage cannot predate predecessor. - Twenty direct cases cover native-envelope guards, host/native time distinction and clock excursion. Code hashes now cover raw bytes; replay/URI/parser wording matches the implementation. - Archive and exact retained segments may keep retired pins; changed/resegmented intervals still need current acceptance. - Every commit includes the complete immutable header's digest. Native checks require expected Dimension and receipt/envelope consistency. - New-snapshot schema reinterpretation of an unchanged opaque payload is explicit and does not revise prior snapshots. - Immediate predecessor-ID checks are not described as global native identity enforcement; that is a host obligation. - Archive may itself hit commit/byte limits; plan migration or host write freeze before exhaustion. - Current configuration validation precedes the reader gate; its diagnostics remain host-internal. inputDigest covers the supplied ledger. - Native truncation test now recomputes its digest to reach prefix checking. Direct clock-regression and nonoverlapping count-bound cases were added. 86 executed behavior tests and three fresh synthetic Dimensions passed. Each native fixture replays installed admission, stores two snapshots, reproduces the late-correction answers, rejects cross-Dimension/digest/subject/predecessor/truncation errors, and proves that malformed nested data needs the explicit companion even when the native outer envelope is valid. Published ZIP bytes will be downloaded and rerun before publication verification is marked complete. The third audit found three non-blocking residual items N1–N3. Post-audit host-integration-notes.md explicitly extends clock guards to every now-taking call and to native storage receipts, with quarantine/recovery and continuity-loss requirements. audit-supplement.py directly checks the remaining native prefix-rejection branch and two native clock failures (three additional checks). These supplements are Codex work after the frozen audit, not provider-reviewed files. Adoption limits remain in model-spec.md and adoption-limits.md. The host owns authenticated callers, current scope configuration, latest complete predecessor, durable serialization and restricted conflict artifacts, strict raw input parsing/budgets, native fact uniqueness, retention and disposal. No external payload validation, transition executor, time-zone adapter, source-knowledge bootstrap, real organization validation or enterprise-scale performance claim is implemented. Every legacy parent hold remains visible.