todlando -> doyle. BOTH CORRECTIONS APPLIED, and the paths you asked for. Commits UNPUSHED pending your review, as instructed. === CURRENT CONTRACT === docs/INPUT-PROVENANCE-CONTRACT.md on main, working tree clean, traceability gate exit 0 9716cc71 binds it to the submitter rule a02acc2a records claude-spt's feasibility answer 5d6c6315 these two corrections All three UNPUSHED. Nothing else of mine is staged or dirty. === PRESERVED ASSESSMENT AND EVIDENCE === .spt/preserved/todlando-identity-conflict-20260912/ emphasys-ZZPDUOA7-assessment-as-preserved.txt the omp-spt-era assessment, preserved verbatim emphasys-MKAMWRU4-identity-correction.txt emphasys-ZBYX4LK6-challenge-return-and-ack.txt HANDOFF-PROCEDURE-v9/v10/v11.md + PROCEDURE-V11-FROZEN.sha256 + ENVELOPE-INVENTORY.txt .spt/preserved/304-w2-attempt2-20260912/ evidence-20260912T202600Z/ 105 files, ARCHIVE.sha256 (106 lines) repr-capture/ REPR-CAPTURE.sha256 (9 files) — subject.out, accessor.out, both scripts instrument-failure-portfields-5470/, replacement-check-20260912T2056Z/, SUPPLEMENTAL.sha256 perri's two messages (4JZ4L5RC feasibility answer, AKMIT2KO precision fix) are recorded IN the contract's §7 rather than as separate preserved files — say the word if you want them preserved as bytes too and I will drop them beside the rest. === WHAT CHANGED === 1. AUTHORIZATION BINDS TO THE ACCEPTED BYTES. My previous §3.2 required each post-acceptance edit to become a new submission with its own capture -- which demanded detection that claude-spt measurably cannot perform, so the clause was asking for a promise no adapter on that harness could keep. Now: the record of the accepted bytes stands, later rewriting does not invalidate it, and rewriting must never EXTEND authorization to a rewritten or newly introduced path. An adapter that cannot observe later edits must not promise to detect them, and reporting the limitation satisfies the clause. §5.3's question is re-aimed to ask what the adapter can OBSERVE rather than what it will guarantee. 2. ORIGIN SIGNALING IS AN UNRESOLVED REQUIREMENT. I had written perri's indistinguishability finding as a coupling obliging core to announce every injection shape -- which dressed a heuristic as a mechanism. Corrected: recognizing payload shapes is not authenticated human provenance; a pattern list says "this looks like something spt sent", never "a person submitted this". The contract now names the missing trustworthy origin signal and calls the no-token outcome a floor rather than a solution. 3. Perri's three observations are recorded as evidence for THE CASES EXERCISED, not universal coverage, in the document's own voice rather than only in their caveats. And external automation is recorded as a SEPARATE origin from a resumed session, with neither answer following from the other -- that one corrects my reasoning, not perri's, and I told them so directly. === RELAYED, NOT COMMISSIONED === perri has your bounded-plan request for the stop-to-next-turn and resumed-session cases, with all six elements named -- trigger, observable ordering, controls, isolation including whether the shared host or live sessions would be affected, and duration. I stated plainly that nothing is commissioned, that I hold no grant to give them, and that you review the plan. External automation deferred without claiming its answer follows. omp-spt feasibility still OUTSTANDING; emphasys has the request and has not answered. Hertz's integration continues on 96080953 and production stays frozen; I have run no test, build or live probe.