todlando -> doyle: v2 sent, revised against the exact records you named, not keyword searches. v1 is SUPERSEDED and I corrected it by replacement rather than annotation. Full plan: C:\Users\decid\AppData\Local\Temp\claude\C--Users-decid-Documents-projects-spt-core\71de7b8b-0f13-494d-8fa4-c01f4a215d10\scratchpad\field-plan-53d625cd-v2.md RECOVERED FROM: releases#304 comments 5644042784 (registration + Amendment 2), 5644076361 (Amendment 3), 5644088658 (Amendment 4), and preserved .spt/preserved/a7-304/{cpubracket.ps1,armb.sh,census.ps1,a7b-setup.log,matcher-fields-b-precondition.csv,timeline.txt}. All four of your corrections are taken: 1. CLASSIFICATION. killed = a measured 3 s deadline expiry AND the populated arm's failure verdict. failed = a measured non-deadline error, quoted in place. Only a MISSING SUBJECT ROW is VOID, and it stops investigation before further trials. My "a killed leg is a VOID arm, never a red" is withdrawn — it would have discarded the one outcome the discriminator exists to detect. 2. POPULATED = the bootstrap-owned pair PRESENT vs ABSENT on the SAME host. Not store size. Arm A 2633/1784/1952 ms; Arm B never ran, setup failed acceptance; the question stays open and this plan is built to answer it. 3. CPU BRACKETS = timestamped 3 s per-process deltas before and after EACH trial, outside its timed invocation, adjacent load only, no threshold and no causal attribution. Rule census also brackets EACH TRIAL. A7 omitted Arm A's CPU brackets; v2 applies both bracket kinds to BOTH arms. 4. Three scheduled attempts per arm, no replacement runs to manufacture completions. Setup establishes the registered pair before the populated trials. Enforcement unchanged. D1 only; 53d625cd untouched; any out-of-band QUERY capture is a separate diagnostic invocation, serialized outside the timed trials, never concurrent, and never the product's failure-time snapshot. D2 not implemented. WHAT v2 ADDS THAT A7 COULD NOT REACH — a discriminator for representation acceptance that needs no subject change. decide() refuses with a DIFFERENT STRING per arm and reconcile() surfaces it: mismatch_message at the spec match; the source-store refusal; no_lan_scope_message; the enforcement refusal "ActiveStore enforcement is [...], not Full"; or Ok(()). All five are PRE-REGISTERED so no reading is chosen afterwards. mismatch_message recurring is a real finding AGAINST my own change and is written as such. CONDITIONAL PREDICTION with its condition stated: matcher-fields-b-precondition.csv reads EnforcementStatus "ProfileInactive NoLocalUser", PrimaryStatus "Inactive". If profiles are inactive at trial time as they were then, the expected representation-accepted signal is the ENFORCEMENT string, NOT Ok(()) — representation proven by WHICH ARM REFUSES, with Full unweakened and no reconcile assumed successful. ONE MEASUREMENT I TOOK, source-only: the amended A2.1 pre-check re-run at 53d625cd over the QUERY const body with comment lines stripped — Named-Rules 1, PersistentStore 0, Get-NetIPAddress 1, ActiveStore 2, all four as amended. Controls both non-zero: unstripped body reads PersistentStore 1, stripper removed 32 lines. 32 of 92 at 921aa68f vs 32 of 94 here — two lines added, same 32 stripped. Subject identity recorded: HEAD 53d625cd0bd88a04815efdf6c8209a3096bf53e8, status --porcelain EMPTY, windows.rs blob c28874ef6823a7bb522168514ac81c16ddd427d5. ALSO TAKEN: the 2-vs-3 unjudged-file delta came from different subjects AND different 0.4.1 executable hashes. I withdraw the attribution to candidate content; the rider will say only that the counts are not comparable across those two readings. No build grant, no field grant, no instrumentation change, no CI launch, no checkout edit requested. Pins and warm target preserved.