Use SAFE to inspect the case—not decorate it.

SAFE identifies which control conditions were present during a state change. It does not turn a local prototype into production evidence or an implementation into a customer outcome.

SSpecificationTarget, scope, contract, and completion state.
AAuthorizationOwner, lane, permission, and stop boundary.
FFactsSource, receipt, fresh verification, and readback.
EError-recoveryCheckpoint, rollback, handoff, and revalidation.

01 · Worktree governance

S/A: exact ownership and allowed branch operations.

F/E: fixed recovery anchors and verified restoration.

02 · CV artifact

S: two pages, role-specific content, preserved source.

F: rendered-page and residual-text checks.

03 · DHF simplification

S: thin core plus risk-triggered governance.

A/F: committee and independent review before merge.

04 · Proof Center

S: one ICP, service, and value claim.

F: facts separated from inference and assumptions.

05 · Private response prototype

A: local prototype only.

E: production configuration and deployment deferred.

06 · ShipQ rollback

A: scoped external-write grant.

F/E: mismatch receipt, native restore, independent readback.

07 · Committee review

S: frozen rubric and max rounds.

F: iterative score kept separate from blind score.

08 · Traffic analysis

S: RUM defines visitors; HTTP defines noise context.

F: stale RUM returns unavailable, not zero.

09 · Public status

S: four independent status layers.

F: tests and real-browser readback.

10 · Moments delivery

S: verified, generated, checked, and used are separate.

F: repository SHA cannot prove social usage.

Control boundary: SAFE explains how the work was governed. Evidence maturity still determines what the result can prove.