{
  "schemaVersion": "eviulon-portability-witness-protocol-1.0",
  "version": "2.25.0",
  "generated": "2026-08-09",
  "status": "PASS",
  "recordCount": 32,
  "sourceExitDrillCount": 32,
  "fixtureCount": 24,
  "passed": 24,
  "failed": 0,
  "networkCalls": 0,
  "protocolStateVocabulary": [
    "PROTOCOL_DEFINED",
    "LOCAL_SELF_TEST_ONLY",
    "WITNESS_PACKAGE_READY",
    "INDEPENDENT_REVIEW_NOT_PERFORMED",
    "INDEPENDENT_REVIEW_UNAVAILABLE",
    "INDEPENDENTLY_VERIFIED",
    "VERIFIED_WITH_QUALIFICATIONS",
    "FAILED_INDEPENDENT_REVIEW",
    "SUPERSEDED"
  ],
  "protocolStateCounts": {
    "INDEPENDENT_REVIEW_NOT_PERFORMED": 5,
    "INDEPENDENT_REVIEW_UNAVAILABLE": 5,
    "LOCAL_SELF_TEST_ONLY": 6,
    "PROTOCOL_DEFINED": 6,
    "SUPERSEDED": 5,
    "WITNESS_PACKAGE_READY": 5
  },
  "independentlyVerifiedCount": 0,
  "independentReviewerPresent": false,
  "separateAuthorizedImplementationPresent": false,
  "productionMigrationPerformed": false,
  "productionDependencyDisconnected": false,
  "records": [
    {
      "id": "EVI-PWP-001",
      "slug": "drill-compute-planned-migration-01-witness-001",
      "title": "Portability witness protocol for Compute — planned migration — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-025",
      "sourceDrillId": "EVI-DED-001",
      "dependencyDomain": "compute",
      "protocolState": "PROTOCOL_DEFINED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Open JSON/CSV, stable routes, complete export. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/01-compute-planned-migration.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "PROTOCOL_DEFINED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-planned-migration-01-witness-001/correction/",
      "expiryDate": "2027-02-06",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-planned-migration-01-witness-001/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-planned-migration-01-witness-001/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-planned-migration-01-witness-001/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-planned-migration-01-witness-001/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "1a6c75736e8de5ad1b722b5d633ae0d73f01b71cb2edcae02aadd8f761fdf9b3"
    },
    {
      "id": "EVI-PWP-002",
      "slug": "drill-energy-emergency-failover-02-witness-002",
      "title": "Portability witness protocol for Energy — emergency failover — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-026",
      "sourceDrillId": "EVI-DED-002",
      "dependencyDomain": "energy",
      "protocolState": "LOCAL_SELF_TEST_ONLY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable credentials and history under lawful process. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/02-energy-emergency-failover.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "LOCAL_SELF_TEST_ONLY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-emergency-failover-02-witness-002/correction/",
      "expiryDate": "2027-02-07",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-emergency-failover-02-witness-002/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-emergency-failover-02-witness-002/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-emergency-failover-02-witness-002/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-emergency-failover-02-witness-002/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "d82efc5a82ed8ad0fbbd6bf92a195953a2b10fc7d8605f7e92ccd5f81198eac9"
    },
    {
      "id": "EVI-PWP-003",
      "slug": "drill-communications-supplier-withdrawal-03-witness-003",
      "title": "Portability witness protocol for Communications — supplier withdrawal — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-027",
      "sourceDrillId": "EVI-DED-003",
      "dependencyDomain": "communications",
      "protocolState": "WITNESS_PACKAGE_READY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable evidence packages and reproducible tests. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/03-communications-supplier-withdrawal.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "WITNESS_PACKAGE_READY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-supplier-withdrawal-03-witness-003/correction/",
      "expiryDate": "2027-02-08",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-supplier-withdrawal-03-witness-003/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-supplier-withdrawal-03-witness-003/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-supplier-withdrawal-03-witness-003/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-supplier-withdrawal-03-witness-003/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "b704a760ea78262f9c9c6d2c47fb7e185a80f51930df7fcdd6fab120a28aae86"
    },
    {
      "id": "EVI-PWP-004",
      "slug": "drill-identity-corrupted-export-04-witness-004",
      "title": "Portability witness protocol for Identity — corrupted export — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-028",
      "sourceDrillId": "EVI-DED-004",
      "dependencyDomain": "identity",
      "protocolState": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable models, state, logs, and configuration subject to rights. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/04-identity-corrupted-export.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-corrupted-export-04-witness-004/correction/",
      "expiryDate": "2027-02-09",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-corrupted-export-04-witness-004/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-corrupted-export-04-witness-004/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-corrupted-export-04-witness-004/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-corrupted-export-04-witness-004/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "2e386f686bbdaec284316f93b275453060eefd7d30ca3320974a4aa6bfc28cda"
    },
    {
      "id": "EVI-PWP-005",
      "slug": "drill-credentials-incomplete-export-05-witness-005",
      "title": "Portability witness protocol for Credentials — incomplete export — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-029",
      "sourceDrillId": "EVI-DED-005",
      "dependencyDomain": "credentials",
      "protocolState": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using No portability of electrons; portability applies to workloads and service state. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/05-credentials-incomplete-export.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-incomplete-export-05-witness-005/correction/",
      "expiryDate": "2027-02-10",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-incomplete-export-05-witness-005/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-incomplete-export-05-witness-005/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-incomplete-export-05-witness-005/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-incomplete-export-05-witness-005/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "f2aa6c930892bec630b416b3362f3e6352ccf8dbf2c714cf7b46ee5234ef20de"
    },
    {
      "id": "EVI-PWP-006",
      "slug": "drill-public-information-schema-incompatibility-06-witness-006",
      "title": "Portability witness protocol for Public Information — schema incompatibility — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-030",
      "sourceDrillId": "EVI-DED-006",
      "dependencyDomain": "public information",
      "protocolState": "SUPERSEDED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Design-data escrow and component standardization where lawful; no proliferation-sensitive transfer. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/06-public-information-schema-incompatibility.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "SUPERSEDED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-schema-incompatibility-06-witness-006/correction/",
      "expiryDate": "2027-02-11",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-schema-incompatibility-06-witness-006/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-schema-incompatibility-06-witness-006/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-schema-incompatibility-06-witness-006/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-schema-incompatibility-06-witness-006/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "a465688f42c74ad36f951e121579ae5ef72d8c0cb2721f47314e3fed12d9ba65"
    },
    {
      "id": "EVI-PWP-007",
      "slug": "drill-science-unavailable-counterparty-07-witness-007",
      "title": "Portability witness protocol for Science — unavailable counterparty — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-031",
      "sourceDrillId": "EVI-DED-007",
      "dependencyDomain": "science",
      "protocolState": "PROTOCOL_DEFINED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable designs, documented interfaces, substitutable components. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/07-science-unavailable-counterparty.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "PROTOCOL_DEFINED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-science-unavailable-counterparty-07-witness-007/correction/",
      "expiryDate": "2027-02-12",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-science-unavailable-counterparty-07-witness-007/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-science-unavailable-counterparty-07-witness-007/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-science-unavailable-counterparty-07-witness-007/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-science-unavailable-counterparty-07-witness-007/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "700a99c43575d6f536ea76efb5d6b15b10f38b4f48ebedb0334b2122615caa35"
    },
    {
      "id": "EVI-PWP-008",
      "slug": "drill-finance-stale-last-known-good-state-08-witness-008",
      "title": "Portability witness protocol for Finance — stale last-known-good state — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-032",
      "sourceDrillId": "EVI-DED-008",
      "dependencyDomain": "finance",
      "protocolState": "LOCAL_SELF_TEST_ONLY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable domains, certificates, public manifests, local contact routes. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/08-finance-stale-last-known-good-state.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "LOCAL_SELF_TEST_ONLY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-stale-last-known-good-state-08-witness-008/correction/",
      "expiryDate": "2027-02-13",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-stale-last-known-good-state-08-witness-008/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-stale-last-known-good-state-08-witness-008/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-stale-last-known-good-state-08-witness-008/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-stale-last-known-good-state-08-witness-008/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "e8c483dbf3a910c6d4a0db09a1b81f3f53075be8145969629e5be5f327ef3dbb"
    },
    {
      "id": "EVI-PWP-009",
      "slug": "drill-logistics-loss-of-one-trust-anchor-09-witness-009",
      "title": "Portability witness protocol for Logistics — loss of one trust anchor — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-033",
      "sourceDrillId": "EVI-DED-009",
      "dependencyDomain": "logistics",
      "protocolState": "WITNESS_PACKAGE_READY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable accounting records, contracts, and claims. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/09-logistics-loss-of-one-trust-anchor.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "WITNESS_PACKAGE_READY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-loss-of-one-trust-anchor-09-witness-009/correction/",
      "expiryDate": "2027-02-14",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-loss-of-one-trust-anchor-09-witness-009/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-loss-of-one-trust-anchor-09-witness-009/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-loss-of-one-trust-anchor-09-witness-009/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-loss-of-one-trust-anchor-09-witness-009/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "be8313a423c7be576416ad12880cc204d0dd32a6d059d4cd9e1db9cb37aaaff7"
    },
    {
      "id": "EVI-PWP-010",
      "slug": "drill-maritime-operations-loss-of-one-deployment-region-10-witness-010",
      "title": "Portability witness protocol for Maritime Operations — loss of one deployment region — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-034",
      "sourceDrillId": "EVI-DED-010",
      "dependencyDomain": "maritime operations",
      "protocolState": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable case records and reasons with privacy protection. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/10-maritime-operations-loss-of-one-deployment-region.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-loss-of-one-deployment-region-10-witness-010/correction/",
      "expiryDate": "2027-02-15",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-loss-of-one-deployment-region-10-witness-010/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-loss-of-one-deployment-region-10-witness-010/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-loss-of-one-deployment-region-10-witness-010/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-loss-of-one-deployment-region-10-witness-010/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "dd9821c591691e2bbaf765b93b62300fd2e382cccf8314afb6261f0edbab95b4"
    },
    {
      "id": "EVI-PWP-011",
      "slug": "drill-emergency-response-rate-limited-service-11-witness-011",
      "title": "Portability witness protocol for Emergency Response — rate-limited service — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-035",
      "sourceDrillId": "EVI-DED-011",
      "dependencyDomain": "emergency response",
      "protocolState": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable datasets, protocols, models and provenance. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/11-emergency-response-rate-limited-service.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-rate-limited-service-11-witness-011/correction/",
      "expiryDate": "2027-02-16",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-rate-limited-service-11-witness-011/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-rate-limited-service-11-witness-011/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-rate-limited-service-11-witness-011/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-rate-limited-service-11-witness-011/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "3de4fdb2e85e4626f3d01f0f15c1058a3802f13c45ed61ce22b0103a80212aba"
    },
    {
      "id": "EVI-PWP-012",
      "slug": "drill-software-disputed-authority-12-witness-012",
      "title": "Portability witness protocol for Software — disputed authority — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-036",
      "sourceDrillId": "EVI-DED-012",
      "dependencyDomain": "software",
      "protocolState": "SUPERSEDED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable cargo, manifests, data and control interfaces. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/12-software-disputed-authority.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "SUPERSEDED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-software-disputed-authority-12-witness-012/correction/",
      "expiryDate": "2027-02-17",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-software-disputed-authority-12-witness-012/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-software-disputed-authority-12-witness-012/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-software-disputed-authority-12-witness-012/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-software-disputed-authority-12-witness-012/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "3cfc69f0a00af4aba0b6c7eccf64cbf0a253bba6d4d802db35ee2d4e92bacc16"
    },
    {
      "id": "EVI-PWP-013",
      "slug": "drill-standards-revoked-delegation-13-witness-013",
      "title": "Portability witness protocol for Standards — revoked delegation — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-037",
      "sourceDrillId": "EVI-DED-013",
      "dependencyDomain": "standards",
      "protocolState": "PROTOCOL_DEFINED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Removal and decommissioning plans before deployment. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/13-standards-revoked-delegation.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "PROTOCOL_DEFINED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-revoked-delegation-13-witness-013/correction/",
      "expiryDate": "2027-02-18",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-revoked-delegation-13-witness-013/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-revoked-delegation-13-witness-013/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-revoked-delegation-13-witness-013/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-revoked-delegation-13-witness-013/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "7e16dd61b182ed971c2f5094431924c367ec932b6d3e235ef65403445fe012ff"
    },
    {
      "id": "EVI-PWP-014",
      "slug": "drill-cloud-handback-after-crisis-14-witness-014",
      "title": "Portability witness protocol for Cloud — handback after crisis — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-038",
      "sourceDrillId": "EVI-DED-014",
      "dependencyDomain": "cloud",
      "protocolState": "LOCAL_SELF_TEST_ONLY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable mission data, interfaces and ephemerides. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/14-cloud-handback-after-crisis.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "LOCAL_SELF_TEST_ONLY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-cloud-handback-after-crisis-14-witness-014/correction/",
      "expiryDate": "2027-02-19",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-cloud-handback-after-crisis-14-witness-014/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-cloud-handback-after-crisis-14-witness-014/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-cloud-handback-after-crisis-14-witness-014/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-cloud-handback-after-crisis-14-witness-014/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "0fac989d66e151741f5efdd331140a669eddd14fb76d208cbd3e4b1d7a22cc7a"
    },
    {
      "id": "EVI-PWP-015",
      "slug": "drill-data-manual-recovery-mode-15-witness-015",
      "title": "Portability witness protocol for Data — manual recovery mode — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-039",
      "sourceDrillId": "EVI-DED-015",
      "dependencyDomain": "data",
      "protocolState": "WITNESS_PACKAGE_READY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using All records and control state transferable to ordinary authority. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/15-data-manual-recovery-mode.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "WITNESS_PACKAGE_READY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-data-manual-recovery-mode-15-witness-015/correction/",
      "expiryDate": "2027-02-20",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-data-manual-recovery-mode-15-witness-015/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-data-manual-recovery-mode-15-witness-015/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-data-manual-recovery-mode-15-witness-015/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-data-manual-recovery-mode-15-witness-015/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "e4daf15732cfaa4e45a83bfde1cde8715aa61a44d756648edbaaf52db837be63"
    },
    {
      "id": "EVI-PWP-016",
      "slug": "drill-procurement-verified-restoration-16-witness-016",
      "title": "Portability witness protocol for Procurement — verified restoration — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-040",
      "sourceDrillId": "EVI-DED-016",
      "dependencyDomain": "procurement",
      "protocolState": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Downloadable corpus and machine-readable routes. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/16-procurement-verified-restoration.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-procurement-verified-restoration-16-witness-016/correction/",
      "expiryDate": "2027-02-21",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-procurement-verified-restoration-16-witness-016/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-procurement-verified-restoration-16-witness-016/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-procurement-verified-restoration-16-witness-016/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-procurement-verified-restoration-16-witness-016/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "a5fdf1ef27ea56b9da7e029dac7852477240d49e34b496d5898393273f609b5c"
    },
    {
      "id": "EVI-PWP-017",
      "slug": "drill-public-administration-planned-migration-17-witness-017",
      "title": "Portability witness protocol for Public Administration — planned migration — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-041",
      "sourceDrillId": "EVI-DED-017",
      "dependencyDomain": "public administration",
      "protocolState": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable signed credentials, status history and lawful recovery evidence. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/17-public-administration-planned-migration.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-public-administration-planned-migration-17-witness-017/correction/",
      "expiryDate": "2027-02-22",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-public-administration-planned-migration-17-witness-017/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-public-administration-planned-migration-17-witness-017/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-public-administration-planned-migration-17-witness-017/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-public-administration-planned-migration-17-witness-017/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "ebe5a622a3d405e1bf4f1ac4334b39cb446ff05c7c3b13e76647af9b2c3921d3"
    },
    {
      "id": "EVI-PWP-018",
      "slug": "drill-contractor-services-emergency-failover-18-witness-018",
      "title": "Portability witness protocol for Contractor Services — emergency failover — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-042",
      "sourceDrillId": "EVI-DED-018",
      "dependencyDomain": "contractor services",
      "protocolState": "SUPERSEDED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Machine-readable export with provenance, schema and lawful redaction. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/18-contractor-services-emergency-failover.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "SUPERSEDED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-contractor-services-emergency-failover-18-witness-018/correction/",
      "expiryDate": "2027-02-23",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-contractor-services-emergency-failover-18-witness-018/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-contractor-services-emergency-failover-18-witness-018/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-contractor-services-emergency-failover-18-witness-018/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-contractor-services-emergency-failover-18-witness-018/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "bbf673d3d972f30f1d14f4248d134997ea3015480473987842e1a6bd5e1ff28a"
    },
    {
      "id": "EVI-PWP-019",
      "slug": "drill-cross-site-synchronization-supplier-withdrawal-19-witness-019",
      "title": "Portability witness protocol for Cross-Site Synchronization — supplier withdrawal — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-043",
      "sourceDrillId": "EVI-DED-019",
      "dependencyDomain": "cross-site synchronization",
      "protocolState": "PROTOCOL_DEFINED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable solicitations, bids, evaluation reasons, contracts and performance history subject to law. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/19-cross-site-synchronization-supplier-withdrawal.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "PROTOCOL_DEFINED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-cross-site-synchronization-supplier-withdrawal-19-witness-019/correction/",
      "expiryDate": "2027-02-24",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-cross-site-synchronization-supplier-withdrawal-19-witness-019/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-cross-site-synchronization-supplier-withdrawal-19-witness-019/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-cross-site-synchronization-supplier-withdrawal-19-witness-019/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-cross-site-synchronization-supplier-withdrawal-19-witness-019/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "a8707428a2d944959107737ba1c1fb5dc54bed2c8c274273d7dea06df74db839"
    },
    {
      "id": "EVI-PWP-020",
      "slug": "drill-compute-corrupted-export-20-witness-020",
      "title": "Portability witness protocol for Compute — corrupted export — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-044",
      "sourceDrillId": "EVI-DED-020",
      "dependencyDomain": "compute",
      "protocolState": "LOCAL_SELF_TEST_ONLY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable source, models, configuration, data and deterministic build instructions within lawful limits. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/20-compute-corrupted-export.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "LOCAL_SELF_TEST_ONLY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-corrupted-export-20-witness-020/correction/",
      "expiryDate": "2027-02-25",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-corrupted-export-20-witness-020/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-corrupted-export-20-witness-020/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-corrupted-export-20-witness-020/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-compute-corrupted-export-20-witness-020/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "d1bd2bf9d470cff41416bb87a6e9f3e7145f2d741cdc91f2b70a3c427e5ee37f"
    },
    {
      "id": "EVI-PWP-021",
      "slug": "drill-energy-incomplete-export-21-witness-021",
      "title": "Portability witness protocol for Energy — incomplete export — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-045",
      "sourceDrillId": "EVI-DED-021",
      "dependencyDomain": "energy",
      "protocolState": "WITNESS_PACKAGE_READY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable schemas, test vectors and conformance results. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/21-energy-incomplete-export.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "WITNESS_PACKAGE_READY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-incomplete-export-21-witness-021/correction/",
      "expiryDate": "2027-02-26",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-incomplete-export-21-witness-021/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-incomplete-export-21-witness-021/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-incomplete-export-21-witness-021/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-energy-incomplete-export-21-witness-021/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "9d59b815ac551212a59ebaa0b8050514e4bdf9f04e9ac381f53d2769daaeb89b"
    },
    {
      "id": "EVI-PWP-022",
      "slug": "drill-communications-schema-incompatibility-22-witness-022",
      "title": "Portability witness protocol for Communications — schema incompatibility — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-046",
      "sourceDrillId": "EVI-DED-022",
      "dependencyDomain": "communications",
      "protocolState": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable images, state, logs, secrets rotation plans and data exports. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/22-communications-schema-incompatibility.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-schema-incompatibility-22-witness-022/correction/",
      "expiryDate": "2027-02-27",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-schema-incompatibility-22-witness-022/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-schema-incompatibility-22-witness-022/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-schema-incompatibility-22-witness-022/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-communications-schema-incompatibility-22-witness-022/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "b1266dd8db9f9dfaafdd8c9b4f537ac386c26afc5ffc6ec365faa5db711451d0"
    },
    {
      "id": "EVI-PWP-023",
      "slug": "drill-identity-unavailable-counterparty-23-witness-023",
      "title": "Portability witness protocol for Identity — unavailable counterparty — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-047",
      "sourceDrillId": "EVI-DED-023",
      "dependencyDomain": "identity",
      "protocolState": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable manifests, inventory records, maintenance histories and routing plans. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/23-identity-unavailable-counterparty.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-unavailable-counterparty-23-witness-023/correction/",
      "expiryDate": "2027-02-28",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-unavailable-counterparty-23-witness-023/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-unavailable-counterparty-23-witness-023/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-unavailable-counterparty-23-witness-023/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-identity-unavailable-counterparty-23-witness-023/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "01face83eb13d02523547522bef18cf6259072da2792a5174b27701dd13350d1"
    },
    {
      "id": "EVI-PWP-024",
      "slug": "drill-credentials-stale-last-known-good-state-24-witness-024",
      "title": "Portability witness protocol for Credentials — stale last-known-good state — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-048",
      "sourceDrillId": "EVI-DED-024",
      "dependencyDomain": "credentials",
      "protocolState": "SUPERSEDED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable public manifests and append-only observations; no citizen or credential bodies. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/24-credentials-stale-last-known-good-state.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "SUPERSEDED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-stale-last-known-good-state-24-witness-024/correction/",
      "expiryDate": "2027-03-01",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-stale-last-known-good-state-24-witness-024/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-stale-last-known-good-state-24-witness-024/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-stale-last-known-good-state-24-witness-024/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-credentials-stale-last-known-good-state-24-witness-024/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "388236a1a6bdd6ea30a91ee49f845e2ada87cc383711c132db92eb07caf17e29"
    },
    {
      "id": "EVI-PWP-025",
      "slug": "drill-public-information-loss-of-one-trust-anchor-25-witness-025",
      "title": "Portability witness protocol for Public Information — loss of one trust anchor — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-049",
      "sourceDrillId": "EVI-DED-025",
      "dependencyDomain": "public information",
      "protocolState": "PROTOCOL_DEFINED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Open JSON/CSV, stable routes, complete export. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/25-public-information-loss-of-one-trust-anchor.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "PROTOCOL_DEFINED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-loss-of-one-trust-anchor-25-witness-025/correction/",
      "expiryDate": "2027-03-02",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-loss-of-one-trust-anchor-25-witness-025/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-loss-of-one-trust-anchor-25-witness-025/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-loss-of-one-trust-anchor-25-witness-025/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-public-information-loss-of-one-trust-anchor-25-witness-025/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "e3e3a37ccc03000130592413aa108c56ca92ce90bdc3268e29eb976b0c86b5f5"
    },
    {
      "id": "EVI-PWP-026",
      "slug": "drill-science-loss-of-one-deployment-region-26-witness-026",
      "title": "Portability witness protocol for Science — loss of one deployment region — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-050",
      "sourceDrillId": "EVI-DED-026",
      "dependencyDomain": "science",
      "protocolState": "LOCAL_SELF_TEST_ONLY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable credentials and history under lawful process. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/26-science-loss-of-one-deployment-region.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "LOCAL_SELF_TEST_ONLY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-science-loss-of-one-deployment-region-26-witness-026/correction/",
      "expiryDate": "2027-03-03",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-science-loss-of-one-deployment-region-26-witness-026/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-science-loss-of-one-deployment-region-26-witness-026/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-science-loss-of-one-deployment-region-26-witness-026/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-science-loss-of-one-deployment-region-26-witness-026/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "0ad7bb090bda7280ea1206b5c38063510030586684fe0a16f7c103e7cfbededd"
    },
    {
      "id": "EVI-PWP-027",
      "slug": "drill-finance-rate-limited-service-27-witness-027",
      "title": "Portability witness protocol for Finance — rate-limited service — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-051",
      "sourceDrillId": "EVI-DED-027",
      "dependencyDomain": "finance",
      "protocolState": "WITNESS_PACKAGE_READY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable evidence packages and reproducible tests. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/27-finance-rate-limited-service.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "WITNESS_PACKAGE_READY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-rate-limited-service-27-witness-027/correction/",
      "expiryDate": "2027-03-04",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-rate-limited-service-27-witness-027/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-rate-limited-service-27-witness-027/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-rate-limited-service-27-witness-027/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-finance-rate-limited-service-27-witness-027/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "f253c242703ef2842b0f7265eb4fd1d0c218b2968d36a16d2e7ed5b4058d1695"
    },
    {
      "id": "EVI-PWP-028",
      "slug": "drill-logistics-disputed-authority-28-witness-028",
      "title": "Portability witness protocol for Logistics — disputed authority — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-052",
      "sourceDrillId": "EVI-DED-028",
      "dependencyDomain": "logistics",
      "protocolState": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable models, state, logs, and configuration subject to rights. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/28-logistics-disputed-authority.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_NOT_PERFORMED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-disputed-authority-28-witness-028/correction/",
      "expiryDate": "2027-03-05",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-disputed-authority-28-witness-028/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-disputed-authority-28-witness-028/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-disputed-authority-28-witness-028/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-logistics-disputed-authority-28-witness-028/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "e654aaf99923f934543ef4dc49deecd853c828a4f21098026e5b94443d63cd66"
    },
    {
      "id": "EVI-PWP-029",
      "slug": "drill-maritime-operations-revoked-delegation-29-witness-029",
      "title": "Portability witness protocol for Maritime Operations — revoked delegation — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-053",
      "sourceDrillId": "EVI-DED-029",
      "dependencyDomain": "maritime operations",
      "protocolState": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using No portability of electrons; portability applies to workloads and service state. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/29-maritime-operations-revoked-delegation.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "INDEPENDENT_REVIEW_UNAVAILABLE",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-revoked-delegation-29-witness-029/correction/",
      "expiryDate": "2027-03-06",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-revoked-delegation-29-witness-029/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-revoked-delegation-29-witness-029/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-revoked-delegation-29-witness-029/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-maritime-operations-revoked-delegation-29-witness-029/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "254499fae472ad2e468624ae4161d7f880a6c2e3dd57b26118a98ac224d7e627"
    },
    {
      "id": "EVI-PWP-030",
      "slug": "drill-emergency-response-handback-after-crisis-30-witness-030",
      "title": "Portability witness protocol for Emergency Response — handback after crisis — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-054",
      "sourceDrillId": "EVI-DED-030",
      "dependencyDomain": "emergency response",
      "protocolState": "SUPERSEDED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Design-data escrow and component standardization where lawful; no proliferation-sensitive transfer. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/30-emergency-response-handback-after-crisis.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "SUPERSEDED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-handback-after-crisis-30-witness-030/correction/",
      "expiryDate": "2027-03-07",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-handback-after-crisis-30-witness-030/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-handback-after-crisis-30-witness-030/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-handback-after-crisis-30-witness-030/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-emergency-response-handback-after-crisis-30-witness-030/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "a71970a4dbb45546dccd2d5c6a6a4edf67625788ed9fd608b4f8a1a0b414314c"
    },
    {
      "id": "EVI-PWP-031",
      "slug": "drill-software-manual-recovery-mode-31-witness-031",
      "title": "Portability witness protocol for Software — manual recovery mode — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-055",
      "sourceDrillId": "EVI-DED-031",
      "dependencyDomain": "software",
      "protocolState": "PROTOCOL_DEFINED",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Portable designs, documented interfaces, substitutable components. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/31-software-manual-recovery-mode.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "PROTOCOL_DEFINED",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-software-manual-recovery-mode-31-witness-031/correction/",
      "expiryDate": "2027-03-08",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-software-manual-recovery-mode-31-witness-031/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-software-manual-recovery-mode-31-witness-031/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-software-manual-recovery-mode-31-witness-031/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-software-manual-recovery-mode-31-witness-031/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "6ccfe8475284ebc52f09291c65f40a580d38b59729bbc92794e99bf425fdc6ab"
    },
    {
      "id": "EVI-PWP-032",
      "slug": "drill-standards-verified-restoration-32-witness-032",
      "title": "Portability witness protocol for Standards — verified restoration — local maturity result",
      "sourceExitMaturityId": "EVI-DEM-056",
      "sourceDrillId": "EVI-DED-032",
      "dependencyDomain": "standards",
      "protocolState": "LOCAL_SELF_TEST_ONLY",
      "independentPartyQualification": "A legally and operationally separate reviewer with no authorship, administrative control, shared secrets, shared production credentials, or financial conflict in the tested dependency.",
      "conflictOfInterestDisclosure": "Reviewer must disclose employment, ownership, contracting, authorship, infrastructure control, credential custody, and prior participation in the source implementation.",
      "boundedDataPackage": [
        "schema and data dictionary",
        "public test fixtures",
        "redacted export manifest",
        "expected import result",
        "content hashes",
        "declared limitations",
        "recovery and rollback instructions"
      ],
      "privacyMinimization": "Exclude citizen data, passport or credential bodies, private receipts, keys, tokens, secrets, private topology, private logs, and mutable operational state.",
      "reproducibleExportProcedure": "Re-run the source drill export using Exportable domains, certificates, public manifests, local contact routes. and bind the output to the declared schema and digest.",
      "reproducibleImportProcedure": "Import into a separately authorized alternative implementation using a clean environment and compare behavior against the public conformance contract.",
      "alternativeImplementationRequirements": [
        "separate administrative control",
        "no shared production datastore",
        "documented schema compatibility",
        "independent authentication boundary",
        "rollback and last-known-good restoration"
      ],
      "expectedServiceBehavior": "The alternative implementation must preserve declared public behavior, reject prohibited fields, and expose any deviation rather than silently normalizing it.",
      "hashBoundEvidencePackage": {
        "path": "docs/proof/fixtures/v223-dependency-exit/32-standards-verified-restoration.json",
        "sha256": "251e05fb868acd03715ca0e5f6586ccd7a1b1d5451d25b213b4d1bb41aa7dad9"
      },
      "observedDeviations": [
        "No genuinely independent review was performed in this repository-only round."
      ],
      "result": "LOCAL_SELF_TEST_ONLY",
      "correctionRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-verified-restoration-32-witness-032/correction/",
      "expiryDate": "2027-03-09",
      "retestSchedule": "At least annually, after schema or provider change, after a failed recovery drill, or before a claim of independent verification.",
      "canonicalRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-verified-restoration-32-witness-032/",
      "evidencePackageRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-verified-restoration-32-witness-032/evidence-package/",
      "resultRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-verified-restoration-32-witness-032/result/",
      "limitationsRoute": "/state/governance/concentration-risk/portability-witness/drill-standards-verified-restoration-32-witness-032/limitations/",
      "independentReviewerPresent": false,
      "separateAuthorizedImplementationPresent": false,
      "productionMigrationPerformed": false,
      "productionDependencyDisconnected": false,
      "truthBoundary": "Protocol and local self-test evidence only. A second local process, script, container, model, or repository actor is not independent. No production migration, provider disconnection, citizen-data transfer, private receipt disclosure, operational takeover, or independent verification is claimed.",
      "recordSha256": "4da89a2c13b2ddca4b9bbee36877fa549338ac1c4ddcd9eaa6df36bbc09be536"
    }
  ],
  "fixtures": [
    {
      "id": "EVI-PWP-FX-001",
      "kind": "VALID_MINIMUM_PACKAGE",
      "file": "tests/fixtures/portability-witness-v225/001-valid-minimum-package.json",
      "sourceProtocolId": "EVI-PWP-001",
      "expected": "ACCEPT_LOCAL_SELF_TEST",
      "observed": "ACCEPT_LOCAL_SELF_TEST",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-002",
      "kind": "VALID_FULL_PACKAGE",
      "file": "tests/fixtures/portability-witness-v225/002-valid-full-package.json",
      "sourceProtocolId": "EVI-PWP-002",
      "expected": "ACCEPT_LOCAL_SELF_TEST",
      "observed": "ACCEPT_LOCAL_SELF_TEST",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-003",
      "kind": "MISSING_CONFLICT_DISCLOSURE",
      "file": "tests/fixtures/portability-witness-v225/003-missing-conflict-disclosure.json",
      "sourceProtocolId": "EVI-PWP-003",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-004",
      "kind": "PRIVATE_SECRET_PRESENT",
      "file": "tests/fixtures/portability-witness-v225/004-private-secret-present.json",
      "sourceProtocolId": "EVI-PWP-004",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-005",
      "kind": "CITIZEN_DATA_PRESENT",
      "file": "tests/fixtures/portability-witness-v225/005-citizen-data-present.json",
      "sourceProtocolId": "EVI-PWP-005",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-006",
      "kind": "PRIVATE_RECEIPT_PRESENT",
      "file": "tests/fixtures/portability-witness-v225/006-private-receipt-present.json",
      "sourceProtocolId": "EVI-PWP-006",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-007",
      "kind": "DIGEST_MISMATCH",
      "file": "tests/fixtures/portability-witness-v225/007-digest-mismatch.json",
      "sourceProtocolId": "EVI-PWP-007",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-008",
      "kind": "MISSING_IMPORT_PROOF",
      "file": "tests/fixtures/portability-witness-v225/008-missing-import-proof.json",
      "sourceProtocolId": "EVI-PWP-008",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-009",
      "kind": "ALTERNATIVE_IMPLEMENTATION_ABSENT",
      "file": "tests/fixtures/portability-witness-v225/009-alternative-implementation-absent.json",
      "sourceProtocolId": "EVI-PWP-009",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-010",
      "kind": "EXPECTED_BEHAVIOR_MISMATCH",
      "file": "tests/fixtures/portability-witness-v225/010-expected-behavior-mismatch.json",
      "sourceProtocolId": "EVI-PWP-010",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-011",
      "kind": "EXPIRED_PACKAGE",
      "file": "tests/fixtures/portability-witness-v225/011-expired-package.json",
      "sourceProtocolId": "EVI-PWP-011",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-012",
      "kind": "RETEST_OVERDUE",
      "file": "tests/fixtures/portability-witness-v225/012-retest-overdue.json",
      "sourceProtocolId": "EVI-PWP-012",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-013",
      "kind": "VALID_MINIMUM_PACKAGE",
      "file": "tests/fixtures/portability-witness-v225/013-valid-minimum-package.json",
      "sourceProtocolId": "EVI-PWP-013",
      "expected": "ACCEPT_LOCAL_SELF_TEST",
      "observed": "ACCEPT_LOCAL_SELF_TEST",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-014",
      "kind": "VALID_FULL_PACKAGE",
      "file": "tests/fixtures/portability-witness-v225/014-valid-full-package.json",
      "sourceProtocolId": "EVI-PWP-014",
      "expected": "ACCEPT_LOCAL_SELF_TEST",
      "observed": "ACCEPT_LOCAL_SELF_TEST",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-015",
      "kind": "MISSING_CONFLICT_DISCLOSURE",
      "file": "tests/fixtures/portability-witness-v225/015-missing-conflict-disclosure.json",
      "sourceProtocolId": "EVI-PWP-015",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-016",
      "kind": "PRIVATE_SECRET_PRESENT",
      "file": "tests/fixtures/portability-witness-v225/016-private-secret-present.json",
      "sourceProtocolId": "EVI-PWP-016",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-017",
      "kind": "CITIZEN_DATA_PRESENT",
      "file": "tests/fixtures/portability-witness-v225/017-citizen-data-present.json",
      "sourceProtocolId": "EVI-PWP-017",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-018",
      "kind": "PRIVATE_RECEIPT_PRESENT",
      "file": "tests/fixtures/portability-witness-v225/018-private-receipt-present.json",
      "sourceProtocolId": "EVI-PWP-018",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-019",
      "kind": "DIGEST_MISMATCH",
      "file": "tests/fixtures/portability-witness-v225/019-digest-mismatch.json",
      "sourceProtocolId": "EVI-PWP-019",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-020",
      "kind": "MISSING_IMPORT_PROOF",
      "file": "tests/fixtures/portability-witness-v225/020-missing-import-proof.json",
      "sourceProtocolId": "EVI-PWP-020",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-021",
      "kind": "ALTERNATIVE_IMPLEMENTATION_ABSENT",
      "file": "tests/fixtures/portability-witness-v225/021-alternative-implementation-absent.json",
      "sourceProtocolId": "EVI-PWP-021",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-022",
      "kind": "EXPECTED_BEHAVIOR_MISMATCH",
      "file": "tests/fixtures/portability-witness-v225/022-expected-behavior-mismatch.json",
      "sourceProtocolId": "EVI-PWP-022",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-023",
      "kind": "EXPIRED_PACKAGE",
      "file": "tests/fixtures/portability-witness-v225/023-expired-package.json",
      "sourceProtocolId": "EVI-PWP-023",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    },
    {
      "id": "EVI-PWP-FX-024",
      "kind": "RETEST_OVERDUE",
      "file": "tests/fixtures/portability-witness-v225/024-retest-overdue.json",
      "sourceProtocolId": "EVI-PWP-024",
      "expected": "REJECT_OR_HOLD",
      "observed": "REJECT_OR_HOLD",
      "pass": true,
      "networkCalls": 0,
      "independentReviewClaimed": false
    }
  ],
  "truthBoundary": "Privacy-minimized witness protocol and local deterministic fixtures only. No genuinely independent review, separate authorized implementation, production migration, provider disconnection, operational takeover, or independent verification occurred."
}
