Alternatives were narrower
Lifecycle routing, worktree governance, fixtures, status publication, and cloud analytics each exercised only part of the framework.
A Google Docs canary write produced a side effect and then failed its structure assertion. DHF had to contain the mutation, restore a trusted state, obtain fresh authority, and prove the final result.
Lifecycle routing, worktree governance, fixtures, status publication, and cloud analytics each exercised only part of the framework.
It combined scoped authorization, live revision state, an external side effect, a failed postcondition, rollback, independent verification, and reauthorization.
Synchronize Git-tracked content into existing Google Docs while protecting document IDs, tab topology, unmapped sections, and permissions.
The canary content existed, but inherited an H1 style. The writer returned readback_structure_mismatch: the remote state changed without satisfying the contract.
Five exact documents, one mapped tab, changed sections only; no create, copy, delete, share, permission, or topology changes.
Approval bound a live owner message to the manifest digest and target revision. Restored facts could not silently renew permission.
The route moved from execution to freeze, restore, and revalidation. Only new evidence and new authority could return it to execution.
Recover the current state, classify risk, bind the manifest, confirm the exact action, execute in stages, and read back each stage.
Restore natively, verify independently, make the minimum local repair, generate fresh evidence, obtain fresh authority, and record the terminal state.
Five allowlisted documents, changed sections only, and explicit content, structure, style, and tab completion criteria.
Live scoped confirmation bound to digest and revision; a retry required new authority.
Source commit, pre/post revisions, permanent failure receipt, receipt v3, and staged fresh readback.
Mismatch classification, no blind retry, native restore, independent verification, and explicit handoff.
Recognize the partial or uncertain outcome.
End further mutation.
Capture the failed receipt and scope.
Obtain the last trusted state.
Verify restoration independently.
Escalate for fresh authority.
Resume only from proven state.
An error is a reason to stop, not authority to repeat a side effect.
Restoration closes the old incident; it does not grant a new write.
A changed HEAD, manifest, digest, or revision invalidates old confirmation.
API success alone is insufficient; completion requires readback and a terminal record.
Mismatch, restored, and succeeded remained distinct claims.
The canary stopped the defect before it reached the remaining documents.
Only changed sections were written, no-change documents stayed untouched, and the recovery path was known.
Manifest, revisions, receipts, and authorization formed an auditable chain.
readback_structure_mismatch receipt remained evidence after native restoration.