A bad write is recoverable. Uncontrolled continuation is the real incident.

When a canary write has already changed the remote document and structure validation fails, the system must stop, restore facts, obtain fresh authority, and prove the final state.

LockCanaryStopNative rollbackHarden + reauthorizeFull readback

Six-beat memory sequence

01 · Pre-mutation

Bind source, document, section, revision, and digest.

02 · Canary write

Remote content changes; structure assertion fails; preserve the receipt.

03 · Fail closed

Freeze remaining targets and prohibit blind retry.

04 · Rollback

Owner restores native history; agent performs read-only verification.

05 · Harden + reauthorize

New code and state require a new manifest, digest, and confirmation.

06 · Final state

Changed targets succeed with full readback; no-change targets remain untouched.

Roles: decision authority is not execution ability

OWNER

Approves the canary, restores native history, and grants fresh authority.

AGENT

Builds the manifest, freezes continuation, verifies restoration, and summarizes evidence.

WRITER

Performs only the authorized write and must not retry after mismatch.

DOCS API

Exposes revisions, records the side effect, and supports native restoration and readback.

State-machine memory

PREPARED → AUTHORIZED → MUTATED → MISMATCH → FROZEN → RESTORED → VERIFIED → REPAIRED → REAUTHORIZED → SUCCEEDED

No mismatch retry

MISMATCH ─X→ RETRY

No restored execution

RESTORED ─X→ EXECUTE

No stale confirmation

OLD DIGEST ─X→ WRITE

SAFE stop-point matrix

S · Specification

Bind target, section, structure, and completion before mutation.

A · Authorization

Bind owner confirmation to the current digest and revision.

F · Facts

Preserve mismatch receipts and independently read back restored and final state.

E · Error-recovery

Freeze, restore, verify, repair, and reauthorize before a new canary.

Same error, two business outcomes

Uncontrolled path

Retry the write, continue other documents, reuse stale authority, and enlarge the uncertain state.

Controlled path

Freeze, restore natively, verify independently, bind new state, obtain fresh authority, and close with full readback.

Four rules to recall

Stop before retry

Repeated remote mutation can compound damage.

Recovery is not permission

Restoration closes the incident; it does not authorize a new write.

Changed state expires approval

HEAD, digest, manifest, or revision change requires new confirmation.

Readback closes success

An API 200 is not enough; verify the full result and terminal record.

Thirty-second recall check

Q1 · First action after mismatch?

Stop remaining writes and preserve the failed receipt.

Q2 · Why not write after rollback?

Restoration proves trusted old state; it does not renew authority.

Q3 · What expires approval?

A changed HEAD, manifest, digest, or target revision.

Q4 · What proves final success?

The terminal receipt and full readback of written and no-write targets.

Memory boundary: this page helps recall the sequence. It does not establish current facts or grant execution authority.