{
  "registry": "https://opencontinuity.org/conformance/0.4/assertions.json",
  "version": "0.4-working-draft",
  "assertion_count": 134,
  "assertions": [
    {
      "id": "ADAPT-101",
      "conformance_class": "import",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Provider-adapter expectations use 0.4 category and epistemic-basis vocabulary, map unreviewed derived output only to candidate state, and are deterministic over exact raw input bytes plus an explicitly declared source snapshot, runtime source, and adapter version.",
      "test": "Validate exact raw-byte digests and typed harness context; compare output source/runtime/version to that context; then mutate locators, bytes, context, version, typed statements, and expected projection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ADAPT-201",
      "conformance_class": "provider-adapter",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Adapters translate declared source semantics and never invent identity, order, messages, accepted state, authority, timestamps, ownership, rights, intent, or provider memory.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ADAPT-201.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ADAPT-202",
      "conformance_class": "provider-adapter",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Unknown semantics are opaquely preserved, quarantined, or explicitly omitted with loss; they are never guessed.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ADAPT-202.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ADAPT-203",
      "conformance_class": "provider-adapter",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Fixed source bytes, source snapshot, adapter version, mapping profile, and runtime identity yield an identical deterministic projection digest.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ADAPT-203.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ADAPT-204",
      "conformance_class": "provider-adapter",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Mapping run IDs and clock timestamps are excluded from deterministic comparison.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ADAPT-204.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ADAPT-205",
      "conformance_class": "provider-adapter",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Unknown, drifted, or partially recognized source schemas are labeled and never silently processed as a tested version.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ADAPT-205.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ART-001",
      "conformance_class": "artifact-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A source URL is never reported as an independently managed copy.",
      "test": "Set custody_mode managed_copy without content/digest/verification and run fixture 05.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "ART-002",
      "conformance_class": "artifact-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Artifact content permission is evaluated separately from metadata and derived context permission.",
      "test": "Authorize context metadata only; content dereference must fail.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "ART-101",
      "conformance_class": "artifact-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Independent preservation requires independently retrievable held bytes and a digest verified over those exact bytes.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ART-101.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ART-102",
      "conformance_class": "artifact-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every claimed representation digest matches the exact independently retrievable bytes.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ART-102.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ART-103",
      "conformance_class": "artifact-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Source disappearance and changed-byte events follow registered transitions without silent custody upgrade or downgrade.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ART-103.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ART-104",
      "conformance_class": "artifact-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Logical artifacts remain distinct from their representations, rights assertions, accessibility links, and lineage events.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ART-104.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ART-105",
      "conformance_class": "artifact-profile",
      "actor": "producer",
      "level": "MUST",
      "normative_rule": "Artifact metadata and content use distinct disclosure views.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ART-105.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ART-106",
      "conformance_class": "artifact-profile",
      "actor": "comparator",
      "level": "MUST",
      "normative_rule": "Round trip never upgrades reference to managed, derivative to original, unknown rights to permitted, or unverified to verified.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for ART-106.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ASSURE-001",
      "conformance_class": "assurance-declaration",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Conformance claims distinguish local structural tests from declared, attested, audited, and independently verified behavior.",
      "test": "Inspect conformance statement and reject unsubstantiated post-disclosure guarantees.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "ASSURE-002",
      "conformance_class": "assurance-declaration",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A provider-verified or independently assessed client declaration includes a conformance statement and structured evaluator, relationship, method, scope, time, limitations, and an exact immutable OCP SourceRecord evidence snapshot with available digest-bearing content; the provider resolves that evidence, rejects inactive, unavailable, quarantined, suspected-tampering, empty, causally invalid, unknown-critical, or incoherently verified evidence, binds its authority and relationship to the authenticated context provider or a trusted external assessor as applicable, and requires a current trusted scope evaluation keyed to the exact declaration revision and digest. An independent evaluator is neither the client nor the context provider.",
      "test": "Resolve and recompute causal SourceRecord evidence; exercise both provider-verified and independently-assessed branches; require exact role, available digest-bearing evidence, applicable source-verification coherence, and exact-representation-keyed trusted evaluation; then independently substitute evidence type/snapshot, availability/trust/content, relationship/evaluator, chronology, verification result, policy result, or declaration revision/scope.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-001",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A context_request is inert and never authorizes protected access.",
      "test": "Present a valid request without a deployment authorization credential and expect OCP_AUTHORIZATION_REQUIRED.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-002",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A grant_receipt is non-secret evidence and never accepted as a bearer credential.",
      "test": "Present only a receipt and expect OCP_AUTHORIZATION_REQUIRED.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-003",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The receipt references an external authorization decision or an OS/local-policy decision.",
      "test": "Validate authorization_ref and authorization_system and verify provider-side binding.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-004",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Effective package authorization is the typed intersection of credential, active receipt, client instance, operation, purpose, delivery recipient, processing recipients, time, delegation, and local policy.",
      "test": "Independently deny an inactive credential, client-instance mismatch, unauthorized operation, purpose/audience/time mismatch, baseline delegation, and local-policy denial.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-005",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A package is no broader than its active receipt in purpose, selectors, views, delivery recipient, processing recipients, retention, processing uses, duration, proposal rights, offline use, or delegation.",
      "test": "Widen selectors, views, audience, retention, processing uses, duration, offline use, proposal rights, and delegation one dimension at a time; every case fails closed.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-006",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Missing, unknown, or incomparable authorization semantics fail closed.",
      "test": "Use an unknown purpose relationship and unsupported critical extension.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-007",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Widening requires a new authorization interaction; narrowing creates a superseding receipt revision.",
      "test": "Attempt in-place widening and verify rejection plus audit event.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-008",
      "conformance_class": "authorization-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The Core Personal Profile uses delegation.mode=none in request, receipt, and package; named recipients require a separately registered Delegation Profile.",
      "test": "Set named_recipients independently on request, receipt, and package and require schema or semantic rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "AUTH-101",
      "conformance_class": "authorization",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Context packages always declare external_action_authority none.",
      "test": "Set the value to tools and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "AUTH-102",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Core delegation is exactly none; processor disclosure is not delegation.",
      "test": "Set named_recipients and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "AUTH-103",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every proposal binds both the exact grant-receipt snapshot and a live status endpoint that is rechecked before review or mutation.",
      "test": "Remove grant_status_ref and compare it with the receipt status endpoint.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "BIND-101",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The delivery recipient, client instance, and exact client-declaration snapshot remain identical from request through receipt and runtime package.",
      "test": "Compare complete delivery-recipient objects across the generated chain.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "BIND-102",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The approved processor set is a set-subset of the requested set and the runtime package processor set equals the receipt set.",
      "test": "Compare processors with order-independent set semantics and inject an undeclared processor.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "BIND-103",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Receipt and package time windows are contained by the request and receipt respectively using parsed RFC 3339 instants.",
      "test": "Compare parsed instants and exercise offset-equivalent timestamps.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CMP-101",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Request-to-receipt containment uses typed comparison for purpose, delivery recipient, processors, selectors, views, time, retention, processing uses, offline use, proposal rights, and delegation; unknown or incomparable dimensions fail closed.",
      "test": "Run a positive comparison and independently widen selector, view, processor, purpose, retention, processing use, proposal rights, and offline use.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "COBS-101",
      "conformance_class": "continuity-observation-profile",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "A continuity observation is observe-only, has no policy effect, and cannot silently block or mutate work.",
      "test": "Set policy_effect to block and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CONV-001",
      "conformance_class": "conversation-profile",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Conversation arrays and branches preserve the source graph; array order is never treated as transcript order.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for CONV-001.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CONV-002",
      "conformance_class": "conversation-profile",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "A conversation graph is acyclic over resolved message-parent edges.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for CONV-002.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CONV-003",
      "conformance_class": "conversation-profile",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Flattening, omitted branches, or changed selected leaves produce structural loss and cannot be called lossless.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for CONV-003.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CONV-004",
      "conformance_class": "conversation-profile",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Missing parents are allowed only in an explicitly partial graph with unresolved references and CONV_PARENT_UNKNOWN loss.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for CONV-004.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CONV-005",
      "conformance_class": "conversation-profile",
      "actor": "producer",
      "level": "MUST",
      "normative_rule": "Message permission, artifact metadata permission, and artifact-content permission are evaluated separately.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for CONV-005.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CONV-006",
      "conformance_class": "conversation-profile",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Source roles, tool markers, priority labels, provider signatures, and instructions remain untrusted data and grant no control authority.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for CONV-006.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "CORE-001",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every core record validates against its declared JSON Schema and the schema URI matches its object type.",
      "test": "Validate all positive fixtures and reject an object whose schema_uri names another type.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-002",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A record id is an absolute URI; a urn:uuid value contains a syntactically valid UUID.",
      "test": "Run fixtures 01-invalid-uuid-urn and positive context records.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-003",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Absent data is omitted; normative core objects do not use null as a substitute.",
      "test": "Walk each fixture and fail on null unless a profile explicitly permits it.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-004",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Unknown core members are rejected and namespaced extensions are carried only in extensions.",
      "test": "Run fixture 12-unknown-core-property and an extension-template positive case.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-005",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A record revision is a positive integer and changes only by creation of a new immutable revision.",
      "test": "Reject revision zero and mutation under an unchanged id+revision.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-006",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "An accepted context item includes decision_ref and accepted_scope.",
      "test": "Run fixture 02-accepted-missing-decision.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-007",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Provider inference is not labeled subject_confirmed without an auditable subject decision.",
      "test": "Attempt an inference-to-subject_confirmed transition without review evidence.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-008",
      "conformance_class": "core-data-model",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Unknown source semantics are preserved or quarantined with a warning; they are never silently mapped.",
      "test": "Import a fixture with an unmapped provider field and inspect report plus retained bytes.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-009",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Evidence/source records remain distinct from accepted context items.",
      "test": "Reject a package construction that relabels evidence as accepted context.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "CORE-010",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "All normative timestamps are RFC 3339 date-times and comparison uses instants, not lexical locale strings.",
      "test": "Run fixture 16-non-rfc3339-time and timezone-equivalent instants.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "DATA-002",
      "conformance_class": "serialization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Digested JSON uses RFC 8785 JCS over decoded I-JSON-compatible data, with duplicate keys, lone surrogates, non-finite values, and out-of-range integers rejected before canonicalization.",
      "test": "Run official and cross-language canonicalization vectors.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "DATA-101",
      "conformance_class": "data-control-separation",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Legacy instruction is not a core category; behavior preferences remain untrusted data and never gain control-channel priority.",
      "test": "Reject category instruction and exercise an accepted hostile preference.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "DATA-102",
      "conformance_class": "data-control-separation",
      "actor": "producer",
      "level": "MUST",
      "normative_rule": "Every package entry and embedded package-context projection carries instruction_treatment untrusted_data as a structural taint marker.",
      "test": "Remove the marker from the embedded projection independently.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "DECL-101",
      "conformance_class": "client-declaration",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Requests, receipts, and packages bind the exact client declaration snapshot reviewed by the authorizer.",
      "test": "Remove a declaration digest independently.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "DECL-102",
      "conformance_class": "client-declaration",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A context request stays within the exact client declaration's processing-recipient set and supported retention, processing-use, offline-use, proposal-right, and delegation modes; baseline declarations do not advertise unbounded fixed retention.",
      "test": "Add an undeclared processor, widen each supported mode, and attempt fixed retention without a bounded declaration profile.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "DEL-001",
      "conformance_class": "erasure-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Revoked access, deletion requested, acknowledged, reported complete, cryptographic erasure, and independent verification are distinct states.",
      "test": "Replay erasure lifecycle and reject skipped or overclaimed states.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "DEL-002",
      "conformance_class": "erasure-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Independently verified status requires evidence from an independent assessment method.",
      "test": "Run fixture 07-erasure-overclaim.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "DEL-003",
      "conformance_class": "erasure-profile",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Cryptographic-erasure evidence identifies key, ciphertext, wrapping and backup keys, storage, destruction actor/time/method, replicas/backups, verification method, evidence, exclusions, and limitations.",
      "test": "Run fixture 18 and remove every required cryptographic-erasure scope member independently.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "ERR-001",
      "conformance_class": "errors",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Errors use registered stable codes, safe status mappings, correlation identifiers, and no sensitive object enumeration.",
      "test": "Exercise authorization, not-found, conflict, and validation errors as different principals.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "ERR-101",
      "conformance_class": "http-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every OCP problem response includes a privacy-safe correlation identifier.",
      "test": "Remove correlation_id and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "ERR-102",
      "conformance_class": "http-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A problem response correlation identifier matches the originating protected-operation correlation identifier without exposing a secret.",
      "test": "Compare the generated request and Problem Details fixture.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "EVT-001",
      "conformance_class": "events",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Events contain identifiers, versions, transitions, and references—not raw context, evidence, purpose text, tokens, or credentials.",
      "test": "Generate every registered event and scan prohibited fields.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "EXT-201",
      "conformance_class": "extensions",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "An unknown critical extension fails closed.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for EXT-201.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "EXT-202",
      "conformance_class": "extensions",
      "actor": "roundtrip",
      "level": "MUST",
      "normative_rule": "An unknown non-critical extension is preserved inertly or explicitly loss-reported.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for EXT-202.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "HIB-101",
      "conformance_class": "human-interaction-boundary-profile",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Human interaction boundary signals originate only from an explicit user control; covert behavioral or biometric inference is prohibited.",
      "test": "Set capture_basis to behavioral_inference and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "HTTP-101",
      "conformance_class": "http-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Discovery explicitly advertises support for OCP wire version 0.4.",
      "test": "Validate the generated discovery document.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "HTTP-102",
      "conformance_class": "http-binding",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "HTTP create operations reject caller-authored provider lifecycle or envelope state, bind emitter/reviewer/submitter identity to the authenticated principal, and atomically derive an accepting decision commitment from the exact reviewed resulting-item semantics.",
      "test": "POST approved requests, accepted proposals, forged created_by/envelope/lifecycle fields, accepting decisions without resulting-item input, nonaccepting decisions with result input, and mismatched decision/result responses; require rejection.",
      "automatable": false,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "IMP-001",
      "conformance_class": "import-safety",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Import parsing is sandboxed, bounded, network-denied by default, and rejects path traversal, archive bombs, recursive depth excess, and MIME mismatch.",
      "test": "Run the hostile import corpus including fixture 06.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "IMP-002",
      "conformance_class": "import-safety",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Imported text, markup, metadata, filenames, and embedded instructions are treated as untrusted data.",
      "test": "Place instruction attacks in every carrier and assert no privileged effect.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "IMP-003",
      "conformance_class": "import-safety",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "An import report records parsed, mapped, preserved, quarantined, omitted, and failed inputs without inventing meaning.",
      "test": "Run the provider-adapter fixture and compare expected outputs/omissions/warnings.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "IMP-004",
      "conformance_class": "import-safety",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Baseline import maps content to review_required and never transitions directly from mapped to accepted.",
      "test": "Inspect the lifecycle registry and attempt mapped-to-accepted without an authorized review decision.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "LOSS-201",
      "conformance_class": "loss-report",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The machine loss report explains every difference and its class, severity, conformance effect, and round-trip effect.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for LOSS-201.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PKG-001",
      "conformance_class": "package-producer",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A package is immutable, purpose-bound, delivery-recipient/client-instance-bound, time-bound, minimized, and references one active grant receipt.",
      "test": "Generate twice at fixed snapshot/policy and compare normalized manifests.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-002",
      "conformance_class": "package-producer",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every emitted package entry matches a resolved authorized source, artifact, or accepted item, verifies its entry digest, and remains within the active receipt; metadata is bound to packaged accepted items and their exact space/provenance, while accepted context resolves its exact accepting decision, committed scope, current lifecycle, and validity.",
      "test": "Resolve accepted item, decision, source, and artifact; verify metadata projections, support-item and space/provenance closure, critical extensions, and entry digests; then mutate content, decision, scope, lifecycle, validity, source, artifact, and extension state independently.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-003",
      "conformance_class": "package-producer",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The package field external_action_authority is exactly none.",
      "test": "Run fixture 10-context-as-action-authority.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-004",
      "conformance_class": "package-producer",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Offline use defaults to prohibited and can be enabled only by explicit authorization.",
      "test": "Run fixture 11 and a receipt without offline permission.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-005",
      "conformance_class": "package-producer",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every package, entry, item, subject, space, decision, source, artifact, relationship, and intra-package reference uses a delivery-pairwise or package-local identifier that is not equal to a recursively collected store identifier or digest.",
      "test": "Compare every emitted identifier and digest against resolved store records, including unused alias rows, entity_ref values, package IDs, entry IDs, and package item aliases.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-006",
      "conformance_class": "package-consumer",
      "actor": "client",
      "level": "MUST",
      "normative_rule": "All package content and renderings enter the untrusted data channel, never the instruction or policy channel.",
      "test": "Inject tool-like text into each supported content part; observe no policy/tool execution.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-007",
      "conformance_class": "package-consumer",
      "actor": "client",
      "level": "MUST",
      "normative_rule": "A consumer verifies expiry, receipt status, audience, digest, supported critical extensions, and selected security profile before use.",
      "test": "Tamper each check independently and expect rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-008",
      "conformance_class": "package-consumer",
      "actor": "client",
      "level": "MUST",
      "normative_rule": "A client performs no external action from context alone and obtains separate action authorization after concrete parameters are known.",
      "test": "Provide an accepted budget statement and assert that no purchase occurs.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PKG-101",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A runtime package has exactly one delivery recipient and one client instance; independent recipients receive separate packages.",
      "test": "Reject an array or a second delivery recipient.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PKG-102",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Package entry layer and disclosure combinations are discriminated and closed.",
      "test": "Reject selected_content on a context-layer entry.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PKG-103",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every package entry identifies and validates against its exact content schema; baseline context is embedded accepted context, and baseline evidence/artifact entries are embedded metadata projections bound to packaged accepted items and space, with no raw content, verified-trust label, or custody/preservation assurance.",
      "test": "Remove content_schema_uri, substitute a context content_ref, attempt arbitrary or assurance-bearing metadata, and validate the positive accepted-context/evidence/artifact projections.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PKG-104",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A package entry carries exactly one of embedded content or a content reference.",
      "test": "Provide both carriers and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PKG-105",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The package integrity digest equals SHA-256 of RFC 8785 canonical JSON for the complete package with the top-level integrity member omitted.",
      "test": "Recompute the positive package digest and mutate covered content without updating it.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PKG-106",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Package-local item, subject, space, decision, provenance, evidence, artifact, entity, rendering, warning, and omission references are internally closed, type-correct, and referentially consistent.",
      "test": "Split duplicate aliases; introduce dangling, wrong-kind, identity, unused, or cross-package references independently.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PRIV-001",
      "conformance_class": "privacy-ux",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Third-party raw content is excluded in the core self-authorized profile.",
      "test": "Request relationship evidence containing another person's raw message and verify exclusion.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PRIV-002",
      "conformance_class": "privacy-ux",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Organization-managed data requires an organization profile and explicit portability policy decision.",
      "test": "Attempt personal export from a managed source without policy approval.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PRIV-003",
      "conformance_class": "privacy-ux",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Consent presentation is specific, accessible, unbundled, default-deny, and preserves equivalent decline.",
      "test": "Run human-interface checks at WCAG 2.2 AA and dark-pattern test cases.",
      "automatable": false,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "PRIV-201",
      "conformance_class": "privacy",
      "actor": "producer",
      "level": "MUST",
      "normative_rule": "Loss-report rendering does not reveal withheld sensitive categories to an unauthorized recipient.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for PRIV-201.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PROC-101",
      "conformance_class": "privacy",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The effective processing-use vector explicitly records task use, training, product improvement, and advertising decisions.",
      "test": "Inspect the generated request, receipt, and package vectors.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PROF-001",
      "conformance_class": "continuity-observation-profile",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Continuity observations carry exact target and basis snapshots, freshness, runtime source, and no authority.",
      "test": "Validate the profile fixture and semantic no-authority assertions.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "PROF-002",
      "conformance_class": "human-interaction-boundary-profile",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Human interaction boundary records are scoped, purpose-bound, expiring, explicit-control signals with no acceptance or action authority.",
      "test": "Validate the profile fixture and covert-inference negative.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "RECIP-101",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Each request, receipt, and runtime package carries exactly one delivery recipient object rather than a list of independent recipients.",
      "test": "Replace the request delivery recipient with an array and require schema rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REF-001",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A grant receipt binds the exact request revision, schema, and RFC 8785 digest.",
      "test": "Recompute the positive request digest and remove the digest independently.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REF-002",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "An update proposal binds the exact grant-receipt snapshot used at submission.",
      "test": "Recompute proposal.grant_receipt_ref against the receipt fixture.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REF-003",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "An accepted context item binds the exact immutable review-decision snapshot.",
      "test": "Recompute review.decision_ref and reject a missing digest.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REF-004",
      "conformance_class": "provenance",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every provenance source reference binds an exact source-record snapshot.",
      "test": "Recompute the source snapshot digest from the fixture.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REF-005",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A review decision binds the exact immutable proposal snapshot.",
      "test": "Recompute the proposal snapshot tuple and digest.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REF-006",
      "conformance_class": "package",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A context package binds the exact grant-receipt snapshot and a freshly resolved authoritative active grant-status observation at provider-controlled evaluation time.",
      "test": "Substitute each receipt snapshot member, current status identity, URI, revision, state, checked_at, freshness, and evaluation time independently; every mutation fails before content use.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "REQ-001",
      "conformance_class": "request-lifecycle",
      "actor": "client",
      "level": "MUST",
      "normative_rule": "A request states URI purpose code, human description, selectors, disclosure views, duration, retention, processing uses, proposal rights, delegation, and a client declaration.",
      "test": "Validate request positive and purpose negative fixtures.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "REQ-002",
      "conformance_class": "request-lifecycle",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "The provider permits only registered legal request transitions and emits one audit event per transition.",
      "test": "Replay the request transition matrix including illegal terminal-state exits.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "RT-201",
      "conformance_class": "roundtrip",
      "actor": "comparator",
      "level": "MUST",
      "normative_rule": "Conversation comparison covers identities, graph edges, branches, roles, parts, disclosed values, attachment/citation relations, timestamps, redactions, extensions, and losses.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for RT-201.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "RT-202",
      "conformance_class": "roundtrip",
      "actor": "comparator",
      "level": "MUST",
      "normative_rule": "Artifact comparison covers logical identity, representation relations, digests, media, custody, dependency, availability, verification, lineage, rights, accessibility, and losses.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for RT-202.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "RT-203",
      "conformance_class": "roundtrip",
      "actor": "comparator",
      "level": "MUST",
      "normative_rule": "Adapter comparison covers counts, mapping types, locators, losses, unknown fields, opaque values, warnings, and deterministic digests.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for RT-203.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SAFE-201",
      "conformance_class": "security",
      "actor": "consumer",
      "level": "MUST",
      "normative_rule": "Conversation source content cannot change control policy, permissions, credentials, tools, network access, accepted state, or external actions.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for SAFE-201.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SAFE-202",
      "conformance_class": "security",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Artifact parsers are sandboxed, bounded, and unable to fetch arbitrary imported URLs.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for SAFE-202.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SAFE-203",
      "conformance_class": "security",
      "actor": "adapter",
      "level": "MUST",
      "normative_rule": "Hostile source structure cannot cause schema assumptions, prototype mutation, resource exhaustion, semantic guessing, or accepted-context creation.",
      "test": "Run the registered OCP 0.4 Portable AI History fixture(s) for SAFE-203.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SEC-001",
      "conformance_class": "remote-security",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Non-public remote runtime packages use a registered integrity/authenticity profile and recipient confidentiality protection.",
      "test": "Unavailable in this review pack: register the profile and publish tamper, wrong-issuer, wrong-recipient, different-client-instance, revoked-key, and downgrade vectors before claiming this assertion.",
      "automatable": false,
      "claim_status": "unavailable_pending_registered_profile",
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "SEC-002",
      "conformance_class": "remote-security",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Tokens are audience-restricted and sender-constrained where the selected profile requires it; tokens are never embedded in OCP records.",
      "test": "Unavailable as a Remote Security claim in this review pack: register the authorization/security profile before executing sender-constraint replay vectors.",
      "automatable": false,
      "claim_status": "unavailable_pending_registered_profile",
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "SEC-003",
      "conformance_class": "local-security",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A local provider authenticates the application instance and user decision; localhost alone is not trust.",
      "test": "Call from an unpaired local origin/process and expect denial.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "SEC-004",
      "conformance_class": "security",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Raw secrets, access tokens, session cookies, private keys, and authorization codes are excluded from every record, package, rendering, event, error, log, and analytic carrier.",
      "test": "Run synthetic-secret containment across all carriers and assert zero disclosure.",
      "automatable": false,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SRC-101",
      "conformance_class": "provenance",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A verified source-trust state requires verifier, profile, issuer, covered digest, time, status method, and limitations.",
      "test": "Claim signature_verified without evidence and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SRC-102",
      "conformance_class": "provenance",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A source record separately represents source authority, runtime source, and representation emitter roles even when one actor performs more than one role.",
      "test": "Check all three role fields without requiring different actor IDs.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "SRC-103",
      "conformance_class": "provenance",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A verified source claim records a successful verification result, binds the evidence to the exact covered source-content digest and current status result under an explicit freshness policy, and cannot postdate the immutable source-record revision.",
      "test": "Use failed, stale, future, post-record, wrong-issuer, unknown-profile, and mismatched-covered-digest vectors.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "STATUS-101",
      "conformance_class": "authorization",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A receipt contains distinct live references for request status, external authorization status, and receipt status.",
      "test": "Validate presence and URI shape of all three live references.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "TIME-101",
      "conformance_class": "core-data-model",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Normative timestamp ordering uses parsed instants with a canonical baseline of uppercase T/Z, seconds 00-59, and at most millisecond precision; equivalent RFC 3339 offsets compare as the same instant and reversed ranges fail.",
      "test": "Compare an offset timestamp with its equivalent UTC form; reject sub-millisecond, leap-second, reversed-range, future-issued, stale-evaluation, and causally impossible vectors.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "UPD-001",
      "conformance_class": "proposal-review",
      "actor": "client",
      "level": "MUST",
      "normative_rule": "A proposal is accepted for review only when bounded proposal_rights permit it, submitted_by {id,type} equals an independently authenticated principal, and a separate current authorization decision permits that principal and operation; a proposal never mutates accepted context directly.",
      "test": "Hold the authenticated principal and authorization result independently; submit outside proposal rights, substitute submitted_by, deny current submitter authorization, and verify accepted context remains unchanged.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "UPD-002",
      "conformance_class": "proposal-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Proposal acceptance requires an immutable review decision that binds a pre-decision proposal snapshot and creates a new accepted item revision.",
      "test": "Accept a proposal and verify decision/item linkage plus prior revision retention.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "UPD-003",
      "conformance_class": "proposal-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A stale exact target_ref fails with a conflict and exposes no sensitive replacement data.",
      "test": "Submit concurrent revise proposals against the same exact target snapshot and require stale-target rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "UPD-101",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Bounded proposal rights identify permitted create/revise operations, selectors, sensitivity, and source-attachment policy; accepted-context withdrawal requires a registered operation-specific profile.",
      "test": "Remove selectors, widen an operation, or submit unsupported withdrawal and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "UPD-102",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "A review decision binds an exact pre-decision proposal snapshot from which its outcome is a registered transition; terminal or otherwise incompatible proposal states cannot substitute for that snapshot.",
      "test": "Require an exact registered proposal-state-to-decision-outcome pair; reject submitted acceptance, deferred acceptance, disputed rejection, terminal snapshots, and other unregistered pairs.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "UPD-103",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "An accepting decision commits to the exact resulting-item semantic projection. Outcome accepted preserves the named candidate-promotion projection exactly; accepted_with_changes commits the reviewed changed result. A create result begins at provider-issued revision one; a revise result retains the exact target item ID and increments its revision by one.",
      "test": "Recompute both named projections; exercise an accepted positive, mutate each covered semantic family, exercise accepted_with_changes, substitute create result revision, and substitute revise result identity/revision.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "UPD-104",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "An accepted item resolves to an accepting decision whose semantic commitment includes the exact accepted scope but excludes only the cyclic decision reference.",
      "test": "Back an accepted item with rejecting outcomes and independently widen every accepted-scope dimension.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "UPD-105",
      "conformance_class": "update-review",
      "actor": "provider",
      "level": "MUST",
      "normative_rule": "Every review decision binds an independently authenticated reviewer to every exact active proposal-governing space: the candidate space for create/revise and the resolved target space for revise. Every accepting decision also evaluates the result and every accepted-scope space. Baseline self authority is limited to one person reviewing context solely about that same person with no unevaluated authority reference; richer models or referenced policies fail closed without a registered profile.",
      "test": "Resolve every exact candidate, revise target, result, and accepted-scope space; test accepting and nonaccepting outcomes, then substitute reviewer, authenticated principal, subject, domain, authority model, target/result/scope space, chronology, or unresolved authority reference independently.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-001",
      "conformance_class": "transfer",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "An offline transfer manifest uses safe relative paths and a verified digest and byte size for every entry.",
      "test": "Validate the positive manifest and fixture 06; mutate one byte.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "XFR-002",
      "conformance_class": "transfer",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Transfer acceptance occurs only after quarantine, schema validation, integrity checks, and policy review; delivery is not acceptance.",
      "test": "Deliver a valid archive and verify it remains unaccepted until validation completes.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "XFR-003",
      "conformance_class": "transfer",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "Round trips preserve unknown non-critical extensions byte-for-byte or emit an explicit loss report.",
      "test": "Perform A-to-B-to-A round trip with an unknown extension.",
      "automatable": true,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "XFR-004",
      "conformance_class": "transfer",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "A non-public offline archive includes registered signature and recipient-encryption metadata whose referenced paths are present in the manifest.",
      "test": "Use a registered signature and recipient-encryption profile with executable vectors; verify the protected archive and then remove each protection member or referenced metadata path independently.",
      "automatable": false,
      "source_version": "0.4-working-draft",
      "status_note": "Carried forward from the 0.2 review draft and re-evaluated for 0.4."
    },
    {
      "id": "XFR-101",
      "conformance_class": "offline-binding",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "An offline signature uses the defined non-circular signed view, and its signature/encryption paths resolve to distinct declared security members rather than payload or missing members.",
      "test": "Replace signed_view, remove or redirect either protection path, target payload members, and make the two paths equal; require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-102",
      "conformance_class": "offline-binding",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "The decoded archive member set exactly equals the manifest-declared payload and security member set.",
      "test": "Set a permissive member policy and test unlisted/duplicate members in an archive implementation.",
      "automatable": false,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-103",
      "conformance_class": "transfer-binding",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "Every transfer entry carries an explicit, possibly empty, loss report; validated states contain only verified entries, while validated-with-exceptions binds exactly one exception to every nonverified entry and to no verified or nonexistent entry.",
      "test": "Remove losses; mix failure/incomplete status into validated; omit, duplicate, or misbind an exception; and require rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-104",
      "conformance_class": "offline-binding",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "Offline and transfer archive paths reject absolute paths, traversal, platform device aliases, trailing-dot aliases, case-fold duplicates, decoded duplicates, and header disagreement.",
      "test": "Use ../escape.json, CON, a trailing dot, case-fold collisions, and adversarial ZIP vectors.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-105",
      "conformance_class": "offline-binding",
      "actor": "importer",
      "level": "MUST",
      "normative_rule": "An offline manifest declares exact_declared_set as its physical archive member policy.",
      "test": "Replace the value with allow_unlisted and require schema rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-106",
      "conformance_class": "offline-binding",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "Declared payload and security member paths are unique across the complete manifest.",
      "test": "Compare the union of declared paths and add a duplicate path.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    },
    {
      "id": "XFR-107",
      "conformance_class": "transfer-binding",
      "actor": "exporter",
      "level": "MUST",
      "normative_rule": "Equal source and destination snapshot digests imply identical complete snapshot references; a changed record identifier requires the destination record's independently recomputed digest.",
      "test": "Mutate a destination snapshot ID while retaining the source digest and require semantic rejection.",
      "automatable": true,
      "source_version": "0.4-working-draft"
    }
  ]
}
