01 · Pre-mutation
Bind source, document, section, revision, and digest.
When a canary write has already changed the remote document and structure validation fails, the system must stop, restore facts, obtain fresh authority, and prove the final state.
Bind source, document, section, revision, and digest.
Remote content changes; structure assertion fails; preserve the receipt.
Freeze remaining targets and prohibit blind retry.
Owner restores native history; agent performs read-only verification.
New code and state require a new manifest, digest, and confirmation.
Changed targets succeed with full readback; no-change targets remain untouched.
Approves the canary, restores native history, and grants fresh authority.
Builds the manifest, freezes continuation, verifies restoration, and summarizes evidence.
Performs only the authorized write and must not retry after mismatch.
Exposes revisions, records the side effect, and supports native restoration and readback.
MISMATCH ─X→ RETRY
RESTORED ─X→ EXECUTE
OLD DIGEST ─X→ WRITE
Bind target, section, structure, and completion before mutation.
Bind owner confirmation to the current digest and revision.
Preserve mismatch receipts and independently read back restored and final state.
Freeze, restore, verify, repair, and reauthorize before a new canary.
Retry the write, continue other documents, reuse stale authority, and enlarge the uncertain state.
Freeze, restore natively, verify independently, bind new state, obtain fresh authority, and close with full readback.
Repeated remote mutation can compound damage.
Restoration closes the incident; it does not authorize a new write.
HEAD, digest, manifest, or revision change requires new confirmation.
An API 200 is not enough; verify the full result and terminal record.
Stop remaining writes and preserve the failed receipt.
Restoration proves trusted old state; it does not renew authority.
A changed HEAD, manifest, digest, or target revision.
The terminal receipt and full readback of written and no-write targets.