# doyle GRANT naming liam as elevated executor for the #297 r6 field leg (2026-09-14T04:48Z)

Issued in advance under S6ESSJ3N-PREP-AND-PROVISIONING-PLAN.md line 165: this grant binds the unique tuple below and authorizes recording its decision against the FIRST matching future run/nonce request paths hertz produces, after all gates succeed. It is not a standing grant; it dies with the tuple.

## Executor
liam (session 1212783f, host pid 52832 as self-reported 15:07:38Z; liam re-verifies at request time).

## Bound tuple (any mismatch = REFUSE, nothing written)
- candidate commit b848244577d398600b59c7829fef9edbdb6315fa
- subject exe sha256 68d9f9312368e042c2bdb066a0815a72fac669ac2571c5e5de9aa64b521ae887 (E = RIG_ROOT/bin/spt.exe after A.4; liam measures E, not the worktree copy)
- capture d2_capture.ps1 sha256 69b8506ac932841223996e7d5ad5ab03a51662ce4eacc6da77dad458a03f620c
- request packet DJNQQ2RA-OHABRPAJ-request-packet.txt sha256 056d065f773f2f3e369176a2ad1008a41f97ef4a5394cdb18c670e07a9310f59
- instrument pins DJNQQ2RA-instrument-pins.json sha256 a6bda07baef5854674a2c98334e52c9799595e89badeb2b5ba5a75ae9fe676fb
- D3 cleanup literal teardown-command.pinned sha256 38e0f21b2cf2ef1f9d986c650f2f6b0d36335ba25c8b017fe8dcbd5219c94676
- RIG_ROOT C:\Users\decid\Documents\projects\spt-core\.spt\preserved\hertz-fp-driver-review\d2\field-rig-r5-S6ESSJ3N
- firewall blobs c30d6b54 / 31ef24c8 / 08f615c4

## Scope granted to liam
- Service hertz's prepare / setup+t1 / D3 requests exactly as the bound packet defines them, each within the 120 s handoff bound, run/nonce paths as hertz's driver emits them under this tuple.
- t1 capture only through the pinned launcher shape (pwsh -NoProfile -File L2 ... -> pwsh), dry-run against the exact request first; any difference refuses.
- Elevated action ONLY for the three legs as the bound packet defines them: (1) prepare; (2) setup+t1 — the SETUP command, exactly `E serve lan --bootstrap --port 29470` (E = RIG_ROOT/bin/spt.exe, SPT_HOME = the rig home H) run under the rig home (this is the admission write the field leg exists to measure), followed by the t1 capture as pinned; (3) D3 executing the pinned literal above byte-for-byte. Post-field guard stands: if the serve path emitted a cleanup payload, it must byte-equal the pin before D3 runs; different bytes = stop. (Amended 04:50Z on liam's E3NQLB27: the earlier wording named only t1 and D3 and would have refused the setup command; that reading is withdrawn.)
- NOT granted: filesystem/rig disposal, fleet or pool deletion, any cleanup outside owned scope, any retry on a failed admission, any action on a request whose paths do not match the first matching run/nonce.

## Sequencing
hertz no longer waits on any message from doyle between prep and GO: this grant is the executor acknowledgment precondition, and GO is already pre-ruled against the first matching nonce (DJNQQ2RA). Liam acknowledges hertz directly at request time.

## Fresh A.2 (second authorized window)
Authorized ONCE hertz has answered, in one line, what consumed 15:24:41Z (prep green) to 15:32:56Z (expiry) on the first fresh window, and confirmed the sequence prep -> A.3 -> ... -> GO contains no wait on doyle. Same 600 s, same tuple, no reset; the two expired clocks stay recorded as expired.
