{
  "application_version": "7.35.0",
  "version": "6.54.0",
  "generated_at": "2026-06-15T00:00:00Z",
  "source_control_import": {
    "profile": "sanitized-v7.35.0-baseline",
    "note": "Minimal seed for local boot and source-control review only. Historical runtime data was removed.",
    "live_apis_connected": false,
    "dns_connected": false,
    "deployment_active": false,
    "production_approved": false
  },
  "mission": {
    "company_name": "NexaMarketAI",
    "owner_name": "placeholder-operator",
    "status": "source-control-safe-seed",
    "ethics_pack_installed": true,
    "autopilot_level": 0,
    "mission_note": "Safe placeholder state. No customer data, credentials, provider secrets, or private identifiers.",
    "permission_budget": {
      "max_emails_per_day": 0,
      "max_dms_per_day": 0,
      "max_meetings_per_week": 0,
      "allowed_meeting_window": "manual-review-only",
      "max_followups_per_contact": 0,
      "allow_auto_negotiation": false,
      "allow_share_pitch_deck": false,
      "allow_pricing_discussion": false,
      "allow_sensitive_data_sharing": false
    },
    "stats": {
      "tasks_total": 2,
      "tasks_completed": 0,
      "meetings_booked": 0,
      "approvals_pending": 1,
      "proof_receipts": 0,
      "auto_actions": 0,
      "blocked_actions": 0,
      "crm_leads": 0,
      "crm_deals": 1,
      "pipeline_value": 0.0,
      "weighted_pipeline": 0.0,
      "quotes_pending": 0,
      "contracts_pending": 0,
      "open_invoices": 0,
      "paid_invoices": 0,
      "onboarding_active": 0,
      "closed_won": 0,
      "documents_total": 0,
      "meetings_scheduled": 0,
      "tail_cases": 0,
      "commission_earned": 0,
      "active_products": 3,
      "catalog_changes_pending": 1,
      "redlines_pending": 0,
      "signature_exceptions": 0,
      "provider_connections": 5,
      "provider_alerts": 1,
      "open_procurement_cases": 0,
      "deferred_revenue": 0,
      "renewals_due": 0,
      "at_risk_customers": 0,
      "mfa_gaps": 1,
      "open_access_reviews": 0,
      "credential_rotations_due": 0,
      "event_delivery_failures": 0,
      "legal_holds": 0,
      "backup_snapshots": 0,
      "release_blockers": 3,
      "open_incidents": 0,
      "quality_issues": 0,
      "sla_breaches": 2,
      "deployments": 0,
      "cutover_runs": 0,
      "live_feature_flags": 0,
      "crm_bridge_batches": 0,
      "crm_system_of_record_profiles": 0,
      "recovery_drills": 0,
      "provider_certifications": 0,
      "settlement_batches": 0,
      "uat_runs": 0,
      "vault_archives": 0,
      "tenants": 0,
      "unverified_domains": 0,
      "open_security_reviews": 0,
      "open_dpa_requests": 0,
      "pending_ai_reviews": 0,
      "failed_ai_evaluations": 0,
      "customer_entitlements": 0,
      "estimated_mrr": 0,
      "open_support_tickets": 0,
      "over_limit_usage": 0,
      "pending_sla_credits": 0,
      "qbr_packets": 0,
      "external_subscriptions": 0,
      "open_subscription_balance": 0,
      "open_dunning_cases": 0,
      "pending_metered_amount": 0,
      "pending_credit_memos": 0,
      "blocked_entitlement_checks": 0,
      "channel_partners": 2,
      "partner_pipeline": 0,
      "partner_conflicts": 0,
      "pending_mdf_requests": 0,
      "pending_partner_payout_amount": 0,
      "growth_campaigns": 0,
      "growth_pipeline": 0,
      "growth_revenue": 0,
      "sales_ready_leads": 0,
      "revenue_intelligence_score": 30,
      "executive_open_alerts": 0,
      "executive_weighted_forecast": 0.0,
      "analytics_data_quality_score": 100,
      "analytics_open_contract_violations": 0,
      "analytics_latest_forecast": 0,
      "modelops_readiness_score": 84,
      "modelops_open_drift_alerts": 0,
      "modelops_pending_deployments": 0,
      "agentops_readiness_score": 100,
      "agentops_open_guardrail_incidents": 0,
      "agentops_pending_releases": 0,
      "observability_readiness_score": 100,
      "observability_open_escalations": 0,
      "observability_active_kill_switches": 0,
      "observability_failed_slos": 0,
      "runtime_readiness_score": 100,
      "runtime_queued_jobs": 0,
      "runtime_failed_jobs": 0,
      "runtime_blocked_invocations": 0,
      "orchestration_readiness_score": 100,
      "orchestration_active_runs": 0,
      "orchestration_blocked_runs": 0,
      "orchestration_pending_handoffs": 0,
      "orchestration_open_compensation": 0
    }
  },
  "tasks": [
    {
      "id": "task_521be1cd49",
      "title": "enterprise saas leads",
      "icon": "\ud83e\udde9",
      "category": "marketing",
      "description": "Find me enterprise saas leads",
      "status": "blocked",
      "priority": 1,
      "progress": 10,
      "result": "No qualified counterparties were found.",
      "proof_ids": [],
      "approval_ids": [],
      "deal_room_ids": [],
      "matches": []
    },
    {
      "id": "task_4948846ce8",
      "title": "lead pull",
      "icon": "\ud83e\udde9",
      "category": "marketing",
      "description": "get me enterprise saas leads",
      "status": "queued",
      "priority": 2,
      "progress": 0,
      "result": "",
      "proof_ids": [],
      "approval_ids": [],
      "deal_room_ids": []
    }
  ],
  "agents": [],
  "companies": [],
  "simulation_plan": [
    {
      "task_id": "task_521be1cd49",
      "title": "enterprise saas leads",
      "category": "marketing",
      "order": 1,
      "confidence": 92,
      "rationale": "Launch narrative should reinforce investor and partner conversations."
    },
    {
      "task_id": "task_4948846ce8",
      "title": "lead pull",
      "category": "marketing",
      "order": 2,
      "confidence": 88,
      "rationale": "Launch narrative should reinforce investor and partner conversations."
    }
  ],
  "handshakes": [],
  "deal_rooms": [],
  "approvals": [
    {
      "id": "approval_9bcdd9c074",
      "task_id": null,
      "task_title": "",
      "title": "Catalog governance review: NexaMarket Workflow Automation Pack",
      "company_name": "Product catalog",
      "status": "pending",
      "reason": "Catalog governance update for next packaging phase.",
      "risk": "medium",
      "policy_name": "CPQ Catalog Governance",
      "created_at": "2026-07-17T19:33:52",
      "payload": {
        "entity_kind": "catalog_change",
        "catalog_change_id": "catalog_change_b089a47cc9"
      },
      "escalation_level": 0,
      "escalated": false,
      "assigned_role": "Revenue Ops",
      "updated_at": "2026-07-17T19:33:52",
      "due_at": "2026-07-19",
      "sla_status": "overdue"
    }
  ],
  "proofs": [],
  "activity": [
    {
      "id": "activity_e92730bbc3",
      "timestamp": "2026-07-17T19:33:52",
      "level": "warning",
      "message": "Catalog change queued for approval: Add product NexaMarket Workflow Automation Pack."
    },
    {
      "id": "activity_0943f499c4",
      "timestamp": "2026-07-12T01:28:46",
      "level": "info",
      "message": "Task added: lead pull."
    },
    {
      "id": "activity_ecf0fb0b81",
      "timestamp": "2026-07-12T01:22:17",
      "level": "success",
      "message": "Platform sync conflict resolved: Provider needs attention: E-Sign Provider Stub."
    },
    {
      "id": "activity_53abded5dd",
      "timestamp": "2026-07-09T20:45:01",
      "level": "success",
      "message": "Platform sync conflict resolved: No governed training dataset exists."
    },
    {
      "id": "activity_0928820d37",
      "timestamp": "2026-07-09T20:41:01",
      "level": "success",
      "message": "Event subscription created for all."
    },
    {
      "id": "activity_7fa531b5a6",
      "timestamp": "2026-07-09T20:40:15",
      "level": "success",
      "message": "Provider sync completed: Google Calendar \u2192 meeting."
    },
    {
      "id": "activity_8f3c0e67b6",
      "timestamp": "2026-07-09T20:40:12",
      "level": "success",
      "message": "Provider connection test completed for Google Calendar."
    },
    {
      "id": "activity_49872a831d",
      "timestamp": "2026-07-09T20:39:02",
      "level": "info",
      "message": "Forecast updated for deal."
    },
    {
      "id": "activity_34318e8620",
      "timestamp": "2026-07-09T20:39:00",
      "level": "info",
      "message": "Forecast updated for deal."
    },
    {
      "id": "activity_a775fd74f2",
      "timestamp": "2026-07-09T20:38:35",
      "level": "warning",
      "message": "No qualified match found for task \"enterprise saas leads\"."
    },
    {
      "id": "activity_03fb88f1be",
      "timestamp": "2026-07-09T20:37:15",
      "level": "info",
      "message": "Task added: enterprise saas leads."
    },
    {
      "id": "activity_source_control_seed",
      "timestamp": "2026-06-15T00:00:00Z",
      "level": "info",
      "message": "Source-control-safe seed loaded. Historical runtime data is intentionally excluded."
    }
  ],
  "metrics": {
    "emails_sent": 0,
    "dms_sent": 0,
    "meetings_booked": 0,
    "followups_sent": 0
  },
  "crm": {
    "leads": [],
    "accounts": [],
    "contacts": [],
    "deals": [
      {
        "id": "placeholder_deal_source_control_seed",
        "title": "Source-control seed placeholder",
        "stage": "placeholder",
        "amount": 0,
        "weighted_amount": 0.0,
        "probability": 75,
        "source": "source-control-safe-seed",
        "created_at": "2026-06-15T00:00:00Z",
        "updated_at": "2026-07-09T20:39:02",
        "notes": [
          "No customer, contact, credential, tenant, provider, or private identifier data.",
          "Manager forecast review: Reviewed forecast and next step discipline."
        ],
        "quote_ids": [],
        "contract_ids": [],
        "invoice_ids": [],
        "deal_room_ids": [],
        "proof_ids": [],
        "material_ids": [],
        "objections": [],
        "expected_close_date": "2026-08-08",
        "next_step": "Review the governed pipeline plan.",
        "canonical_id": "CAN-DEAL-DEAL_SOURCE_CONTROL_SEED",
        "document_ids": [],
        "meeting_ids": [],
        "seller_code": "NM-OWNER-PRIMARY",
        "post_termination_status": "active",
        "tail_end_date": null,
        "forecast_category": "commit",
        "stalled": false,
        "manager_note": "Reviewed forecast and next step discipline.",
        "close_confidence": 75,
        "last_manager_review_at": "2026-07-09T20:39:02"
      }
    ],
    "timeline": [
      {
        "id": "timeline_9abd5470a7",
        "timestamp": "2026-07-09T20:39:02",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "deal_id": "placeholder_deal_source_control_seed",
        "title": "Forecast reviewed",
        "note": "Bucket commit at 75% confidence.",
        "actor": "Manager"
      },
      {
        "id": "timeline_e012ca69de",
        "timestamp": "2026-07-09T20:39:00",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "deal_id": "placeholder_deal_source_control_seed",
        "title": "Forecast reviewed",
        "note": "Bucket commit at 75% confidence.",
        "actor": "Manager"
      }
    ],
    "summary": {
      "open_deals": 1,
      "pipeline_value": 0.0,
      "weighted_pipeline": 0.0,
      "commit_value": 0.0,
      "expected_close_count": 1,
      "stage_rollup": {
        "Lead": 0,
        "Qualified": 0,
        "Discovery": 0,
        "Proposal": 0,
        "Contract": 0,
        "Closed Won": 0,
        "Closed Lost": 0,
        "placeholder": 1
      },
      "at_risk_deals": []
    },
    "forecast": {
      "best_case_value": 0.0,
      "commit_value": 0.0,
      "upside_value": 0.0,
      "slipped_count": 0,
      "stalled_count": 0,
      "approval_overdue": 1,
      "at_risk_count": 1,
      "manager_queue": [
        {
          "deal_id": "placeholder_deal_source_control_seed",
          "company_name": null,
          "stage": "placeholder",
          "amount": 0,
          "priority": "warning",
          "reason": "Manager note: Reviewed forecast and next step discipline.",
          "expected_close_date": "2026-08-08"
        }
      ],
      "slipped_deals": [],
      "signals": [
        {
          "title": "Deal",
          "detail": "Manager note: Reviewed forecast and next step discipline.",
          "tone": "warning"
        }
      ]
    }
  },
  "approved_materials": [
    {
      "id": "mat_pitch_teaser_v32",
      "scope": "pitch_teaser",
      "title": "Investor Teaser",
      "type": "Deck",
      "version": "3.2",
      "status": "approved",
      "approved_channels": [
        "email",
        "meeting",
        "deal_room"
      ],
      "expires_on": "2026-08-23",
      "disclaimer": "Forward-looking statements require approval before pricing or financial commitments.",
      "locked_claims": [
        "No guaranteed ROI language",
        "No unapproved pricing promises"
      ],
      "latest": true,
      "latest_final": true,
      "training_required": false,
      "approval_required": false,
      "owner_role": "Revenue Ops",
      "compare_group": "pitchteaser:investor-teaser:deck",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-PITCH_TEASER_V32"
    },
    {
      "id": "mat_pitch_deck_v60",
      "scope": "pitch_deck",
      "title": "Corporate Pitch Deck",
      "type": "Deck",
      "version": "6.0",
      "status": "approved",
      "approved_channels": [
        "meeting",
        "deal_room"
      ],
      "expires_on": "2026-07-29",
      "disclaimer": "Only the latest board-approved deck may be shared externally.",
      "locked_claims": [
        "Use approved TAM slide only",
        "Do not edit pricing slide without deal-desk review"
      ],
      "latest": true,
      "latest_final": true,
      "training_required": false,
      "approval_required": false,
      "owner_role": "Revenue Ops",
      "compare_group": "pitchdeck:corporate-pitch-deck:deck",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-PITCH_DECK_V60"
    },
    {
      "id": "mat_financial_model_v14",
      "scope": "financial_model",
      "title": "Detailed Financial Model",
      "type": "Workbook",
      "version": "1.4",
      "status": "approval_only",
      "approved_channels": [
        "deal_room"
      ],
      "expires_on": "2026-07-24",
      "disclaimer": "Finance team approval required for any external financial model sharing.",
      "locked_claims": [
        "No scenario tabs may be exported",
        "Only approved assumptions can be shared"
      ],
      "latest": true,
      "latest_final": false,
      "training_required": false,
      "approval_required": true,
      "owner_role": "Revenue Ops",
      "compare_group": "financialmodel:detailed-financial-model:workbook",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-FINANCIAL_MODEL_V14"
    },
    {
      "id": "mat_security_packet_v21",
      "scope": "sensitive",
      "title": "Security Packet",
      "type": "Data Room",
      "version": "2.1",
      "status": "approved",
      "approved_channels": [
        "deal_room"
      ],
      "expires_on": "2026-09-07",
      "disclaimer": "Customer and internal security documents require deal-room delivery only.",
      "locked_claims": [
        "No credentials or production secrets",
        "Only sanitized exhibits"
      ],
      "latest": true,
      "latest_final": true,
      "training_required": false,
      "approval_required": false,
      "owner_role": "Revenue Ops",
      "compare_group": "sensitive:security-packet:data-room",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-SECURITY_PACKET_V21"
    },
    {
      "id": "mat_creative_brief_v11",
      "scope": "creative_brief",
      "title": "Creative Brief",
      "type": "Brief",
      "version": "1.1",
      "status": "approved",
      "approved_channels": [
        "meeting",
        "deal_room"
      ],
      "expires_on": "2026-10-07",
      "disclaimer": "Claims must align with current approved positioning.",
      "locked_claims": [
        "Use approved brand language",
        "Do not commit to production dates without approval"
      ],
      "latest": true,
      "latest_final": true,
      "training_required": false,
      "approval_required": false,
      "owner_role": "Revenue Ops",
      "compare_group": "creativebrief:creative-brief:brief",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-CREATIVE_BRIEF_V11"
    },
    {
      "id": "mat_audience_summary_v11",
      "scope": "audience_summary",
      "title": "Audience Summary",
      "type": "Summary",
      "version": "1.1",
      "status": "approved",
      "approved_channels": [
        "email",
        "meeting",
        "deal_room"
      ],
      "expires_on": "2026-08-13",
      "disclaimer": "Segment definitions should match the latest marketing operations export.",
      "locked_claims": [
        "No purchased-list claims",
        "Consent rules must be referenced in email plans"
      ],
      "latest": true,
      "latest_final": true,
      "training_required": false,
      "approval_required": false,
      "owner_role": "Revenue Ops",
      "compare_group": "audiencesummary:audience-summary:summary",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-AUDIENCE_SUMMARY_V11"
    },
    {
      "id": "mat_budget_guardrail_v10",
      "scope": "budget",
      "title": "Budget Guardrails",
      "type": "Policy",
      "version": "1.0",
      "status": "approval_only",
      "approved_channels": [
        "meeting",
        "deal_room"
      ],
      "expires_on": "2026-08-28",
      "disclaimer": "Budget and pricing changes require owner approval.",
      "locked_claims": [
        "No non-standard discounts without deal-desk approval"
      ],
      "latest": true,
      "latest_final": false,
      "training_required": false,
      "approval_required": true,
      "owner_role": "Revenue Ops",
      "compare_group": "budget:budget-guardrails:policy",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-BUDGET_GUARDRAIL_V10"
    },
    {
      "id": "mat_brief_v10",
      "scope": "brief",
      "title": "General Solution Brief",
      "type": "Brief",
      "version": "1.0",
      "status": "approved",
      "approved_channels": [
        "email",
        "meeting",
        "deal_room"
      ],
      "expires_on": "2026-09-22",
      "disclaimer": "General product brief only. Use governed commercial artifacts for pricing or legal terms.",
      "locked_claims": [
        "No pricing tables in brief",
        "No legal representations"
      ],
      "latest": true,
      "latest_final": true,
      "training_required": false,
      "approval_required": false,
      "owner_role": "Revenue Ops",
      "compare_group": "brief:general-solution-brief:brief",
      "created_at": "2026-07-09T19:05:10",
      "updated_at": "2026-07-09T19:05:10",
      "canonical_id": "CAN-MATE-BRIEF_V10"
    }
  ],
  "product_catalog": [
    {
      "id": "prod_enterprise_core",
      "sku": "NM-ENT-CORE",
      "name": "NexaMarket Enterprise Core",
      "family": "Subscription",
      "billing_period": "Annual",
      "list_price": 12000,
      "max_auto_discount_pct": 10,
      "active": true,
      "description": "Governed prospecting, deal rooms, approvals, and proof receipts.",
      "canonical_id": "CAN-PROD-ENTERPRISE_CORE",
      "catalog_version": "2026.1",
      "price_book_id": "pb_standard_2026",
      "unit_cost": 5040.0,
      "margin_floor_pct": 35,
      "requires_configuration": true,
      "bundle_eligible": true,
      "dependencies": [],
      "price_history": [],
      "last_catalog_review_at": "2026-07-09T19:05:10"
    },
    {
      "id": "prod_pipeline_plus",
      "sku": "NM-PIPE-PLUS",
      "name": "Pipeline Intelligence Plus",
      "family": "Add-On",
      "billing_period": "Annual",
      "list_price": 4800,
      "max_auto_discount_pct": 12,
      "active": true,
      "description": "Pipeline rollups, forecasting, and manager coaching screens.",
      "canonical_id": "CAN-PROD-PIPELINE_PLUS",
      "catalog_version": "2026.1",
      "price_book_id": "pb_standard_2026",
      "unit_cost": 1680.0,
      "margin_floor_pct": 35,
      "requires_configuration": true,
      "bundle_eligible": true,
      "dependencies": [
        "prod_enterprise_core"
      ],
      "price_history": [],
      "last_catalog_review_at": "2026-07-09T19:05:10"
    },
    {
      "id": "prod_partner_enablement",
      "sku": "NM-PARTNER-EN",
      "name": "Partner Enablement Pack",
      "family": "Services",
      "billing_period": "One-Time",
      "list_price": 3000,
      "max_auto_discount_pct": 0,
      "active": true,
      "description": "Approved materials, onboarding setup, and workflow configuration.",
      "canonical_id": "CAN-PROD-PARTNER_ENABLEMENT",
      "catalog_version": "2026.1",
      "price_book_id": "pb_standard_2026",
      "unit_cost": 1740.0,
      "margin_floor_pct": 20,
      "requires_configuration": false,
      "bundle_eligible": true,
      "dependencies": [],
      "price_history": [],
      "last_catalog_review_at": "2026-07-09T19:05:10"
    }
  ],
  "compliance": {
    "suppression_list": [],
    "privacy_requests": [
      {
        "id": "privacy_demo_export",
        "subject": "Demo audit export request",
        "status": "resolved",
        "requested_at": "2026-07-02T19:05:10",
        "resolved_at": "2026-07-04T19:05:10",
        "notes": "Sample privacy workflow record for the production control plane.",
        "canonical_id": "CAN-PRIV-DEMO_EXPORT",
        "request_type": "access_export",
        "contact_id": null,
        "contact_name": "Demo audit export request",
        "requested_by": "Internal",
        "sla_due_at": "2026-07-12",
        "resolution_notes": "",
        "data_minimized": false
      }
    ],
    "outbound_messages": [],
    "consent_logs": []
  },
  "quotes": [],
  "contracts": [],
  "invoices": [],
  "onboarding": [],
  "migration": {
    "imports": [],
    "duplicate_suggestions": [],
    "last_import_summary": {}
  },
  "integrations": {
    "health": [
      {
        "id": "conn_crm_core",
        "name": "Canonical CRM Core",
        "mode": "local",
        "status": "healthy",
        "last_event_at": "2026-07-12T01:22:17",
        "retry_queue": 0,
        "coverage": "Leads, accounts, contacts, deals, timeline",
        "events_processed": 5,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_approval_fabric",
        "name": "Approval Fabric",
        "mode": "local",
        "status": "healthy",
        "last_event_at": "2026-07-17T19:33:52",
        "retry_queue": 0,
        "coverage": "Quotes, contracts, materials, governed actions",
        "events_processed": 2,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_builder_sync",
        "name": "NexaBuilderAI Attribution Sync",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Attribution, seller code, payout handoff",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_outbound_hub",
        "name": "Outbound Connector Hub",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Email, SMS, WhatsApp, LinkedIn history",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_finance_sync",
        "name": "Finance Reconciliation Rail",
        "mode": "planned",
        "status": "planned",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Quote-to-invoice and payout reconciliation",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_identity_sync",
        "name": "Unified Identity Sync",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "SSO, MFA, role sync, access deactivation",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "One or more active users still need MFA verification.",
        "last_retried_at": null
      },
      {
        "id": "conn_event_gateway",
        "name": "API Gateway + Event Bus",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": "2026-07-17T19:33:52",
        "retry_queue": 12,
        "coverage": "Canonical IDs, object ownership, event reconciliation",
        "events_processed": 12,
        "alerts": 11,
        "last_error": "11 conflict(s) need review.",
        "last_retried_at": null
      },
      {
        "id": "conn_cpq_governance",
        "name": "CPQ + Catalog Governance",
        "mode": "local",
        "status": "healthy",
        "last_event_at": "2026-07-17T19:33:52",
        "retry_queue": 1,
        "coverage": "Product catalog, price books, bundle validation, margin guardrails",
        "events_processed": 1,
        "alerts": 1,
        "last_error": "Catalog changes or CPQ exceptions require review.",
        "last_retried_at": null
      },
      {
        "id": "conn_signature_authority",
        "name": "Signature Authority + Redline Control",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Contract tiers, signature matrix, clause library, redline approvals",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_provider_gateway",
        "name": "Provider Connector Gateway",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": "2026-07-09T20:40:15",
        "retry_queue": 0,
        "coverage": "Credential vault, provider sync jobs, webhook inbox, dead-letter review",
        "events_processed": 2,
        "alerts": 1,
        "last_error": "Provider sync items need attention.",
        "last_retried_at": null
      },
      {
        "id": "conn_procurement_ops",
        "name": "Procurement + Payment Terms Ops",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "PO readiness, vendor setup, security review, tax certificate, terms approval",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_revenue_schedule",
        "name": "Revenue Schedule + Tax Control",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tax profiles, payment terms, currency, deferred revenue recognition",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_customer_success_renewals",
        "name": "Customer Success + Renewals",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Health scoring, renewal plans, expansion candidates, risk review",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_enterprise_security_admin",
        "name": "Enterprise Security Admin",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 1,
        "coverage": "SSO provider metadata, SCIM user provisioning, MFA verification, access reviews",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "MFA gaps or access reviews require admin action.",
        "last_retried_at": null
      },
      {
        "id": "conn_credential_rotation",
        "name": "Credential Rotation Control",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Provider-secret rotation queue, expiry tracking, masked credential audit",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_event_delivery_replay",
        "name": "Event Delivery + Replay",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": "2026-07-17T19:33:52",
        "retry_queue": 0,
        "coverage": "Topic subscriptions, event delivery attempts, dead-letter replay jobs",
        "events_processed": 12,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_retention_backup",
        "name": "Retention, Holds + Backup Control",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Retention policies, legal holds, retention sweeps, backup snapshots, audit CSV",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "Create an initial backup snapshot.",
        "last_retried_at": null
      },
      {
        "id": "conn_release_control",
        "name": "Release Readiness Control",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Release plans, environment promotion, rollout gates, rollback checkpoints",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "Release blockers remain before production promotion.",
        "last_retried_at": null
      },
      {
        "id": "conn_quality_observability",
        "name": "Quality + Observability Monitor",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Data-quality scans, SLA monitors, incident queue, operational runbooks",
        "events_processed": 0,
        "alerts": 2,
        "last_error": "Quality, incident, or SLA attention required.",
        "last_retried_at": null
      },
      {
        "id": "conn_ops_export",
        "name": "Operations Export Ledger",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Release, quality, incident, SLA, deployment, and rollback export visibility",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_provider_certification",
        "name": "Provider Certification Gateway",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Provider go-live certification, credential posture, webhook readiness, sync evidence, and transaction-test records",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_esign_callback_gateway",
        "name": "E-Sign Callback Gateway",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Envelope creation, signer callback intake, completion evidence, and contract execution handoff",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_settlement_rail_control",
        "name": "Settlement Rail Control",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tax calculations, settlement batches, payout batches, fee estimates, and reconciliation evidence",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_event_bus_resilience",
        "name": "Event Bus Resilience Monitor",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Consumer lag checks, topic coverage, replay readiness, and synthetic delivery health",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_backup_vault",
        "name": "Immutable Backup Vault Control",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "WORM-style vault archive records, checksum verification, hold awareness, and recovery evidence",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_tenant_provisioning",
        "name": "Tenant Provisioning Gateway",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tenant boundary creation, domain verification, data-residency binding, environment provisioning, and health checks",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_trust_center",
        "name": "Trust Center and Security Review Control",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Trust artifacts, security questionnaires, DPA requests, evidence packets, and legal review queues",
        "events_processed": 5,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_ai_governance",
        "name": "AI Governance Control Plane",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Model registry, prompt-policy checks, synthetic evaluations, human review, and risk acceptance",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_enterprise_evidence_export",
        "name": "Enterprise Evidence Export",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tenant, trust, AI governance, and buyer/security evidence export coverage",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_customer_billing_ops",
        "name": "Customer Billing Operations",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Billing accounts, subscription plans, payment terms, invoice handoff, and SLA credit tracking",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_entitlement_control",
        "name": "Entitlement Control Plane",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tenant plan assignment, feature access, seat limits, renewal dates, and provisioning state",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_usage_metering",
        "name": "Usage Metering and Overage Monitor",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Customer usage events, monthly rollups, plan limits, overage alerts, and export evidence",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_support_success_ops",
        "name": "Support and Customer Success Operations",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Support tickets, SLA breaches, credits, success plans, QBR evidence, and renewal handoff",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_subscription_billing_gateway",
        "name": "Subscription Billing Provider Gateway",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Billing provider connections, external subscription refs, invoice sync jobs, and subscription invoice generation",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_usage_telemetry_pipeline",
        "name": "Usage Telemetry Pipeline",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Raw customer telemetry ingestion, entitlement limit checks, and metered-charge preparation",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_collections_dunning_ops",
        "name": "Collections and Dunning Operations",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Payment failures, retry evidence, dunning cases, service-risk escalation, and collections export",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_support_desk_bridge",
        "name": "Support Desk Bridge",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Support-ticket external refs, sync jobs, SLA signal write-back, and customer-success handoff",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_sla_credit_automation",
        "name": "SLA Credit Automation",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Pending SLA credit review, credit memo creation, invoice adjustment evidence, and finance approval status",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_partner_portal",
        "name": "Partner Portal Control Plane",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Partner onboarding, certification evidence, profile governance, and portal readiness",
        "events_processed": 2,
        "alerts": 1,
        "last_error": "Review partner/channel queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_marketplace_syndication",
        "name": "Marketplace Syndication Gateway",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Listing review, proof-pack evidence, publish status, and marketplace metadata sync",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_partner_deal_registration",
        "name": "Partner Deal Registration",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Referral intake, conflict review, protected accounts, and CRM lead/deal handoff",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_mdf_budget_control",
        "name": "MDF Budget Control",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Marketing-development-fund requests, approvals, reimbursement evidence, and budget exposure",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_partner_payout_reconciliation",
        "name": "Partner Payout Reconciliation",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Partner payout statement preparation, approval, simulated payment, and commission trace linkage",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_growth_audience_builder",
        "name": "Growth Audience Builder",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Audience segmentation, consent-safe channel readiness, and target-account coverage",
        "events_processed": 1,
        "alerts": 1,
        "last_error": "Review growth-ops queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_campaign_orchestration",
        "name": "Campaign Orchestration Gateway",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Governed campaign readiness, launch simulation, approved-material checks, and partner/MDF linkage",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_attribution_warehouse",
        "name": "Attribution Warehouse",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Campaign-touch events, pipeline influence, closed-won attribution, and ROI evidence",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "Review growth-ops queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_lead_scoring_router",
        "name": "Lead Scoring and Routing",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Lead scoring, sales-ready routing, owner assignment, and CRM write-back",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_experimentation_lab",
        "name": "Experimentation Lab",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "A/B test design, results intake, winner selection, and guardrail monitoring",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_revenue_intelligence",
        "name": "Revenue Intelligence Lake",
        "mode": "local",
        "status": "healthy",
        "last_event_at": "2026-07-12T01:35:50",
        "retry_queue": 0,
        "coverage": "Metric snapshots, pipeline health, bookings, ARR/MRR, usage, support, and growth attribution rollups",
        "events_processed": 1,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_anomaly_detection",
        "name": "Anomaly Detection and Risk Signals",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Pipeline coverage, SLA breaches, sync conflicts, failed-payment risk, growth ROI, and provider health signals",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_board_reporting",
        "name": "Board Reporting Workspace",
        "mode": "local",
        "status": "attention",
        "last_event_at": "2026-07-12T01:35:50",
        "retry_queue": 0,
        "coverage": "Executive scorecards, board packets, risk summaries, decisions, and evidence export preparation",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "Review revenue intelligence queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_playbook_orchestrator",
        "name": "Revenue Playbook Orchestrator",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Risk playbooks, owner assignment, remediation tasks, and alert closure evidence",
        "events_processed": 2,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_analytics_warehouse",
        "name": "Analytics Warehouse Gateway",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Warehouse/lakehouse connection metadata, ELT sync jobs, record counts, and refresh evidence",
        "events_processed": 1,
        "alerts": 1,
        "last_error": "Review analytics readiness queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_data_contract_monitor",
        "name": "Data Contract Monitor",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Required fields, freshness checks, contract validation runs, and violation resolution",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_metric_semantic_layer",
        "name": "Metric Semantic Layer",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Governed KPI definitions, owners, formulas, dimensions, and executive metric lineage",
        "events_processed": 4,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_forecast_lab",
        "name": "Forecast Lab",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Forecast models, backtest quality, prediction intervals, and model-governance evidence",
        "events_processed": 1,
        "alerts": 1,
        "last_error": "Review analytics readiness queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_bi_refresh_scheduler",
        "name": "BI Refresh Scheduler",
        "mode": "local",
        "status": "healthy",
        "last_event_at": "2026-07-12T01:35:50",
        "retry_queue": 0,
        "coverage": "Dashboard refreshes, stakeholder distribution, embedded evidence links, and board-reporting handoff",
        "events_processed": 1,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_modelops_feature_store",
        "name": "ModelOps Feature Store",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Governed feature sets, source lineage, data-contract dependencies, and feature freshness posture",
        "events_processed": 1,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_modelops_training_pipeline",
        "name": "ModelOps Training Pipeline",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Training datasets, evaluation runs, retraining jobs, and model-quality evidence",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "Review ModelOps readiness queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_modelops_drift_monitor",
        "name": "ModelOps Drift Monitor",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Forecast drift, data-quality drift, confidence drift, alert severity, and retraining triggers",
        "events_processed": 1,
        "alerts": 1,
        "last_error": "Review ModelOps readiness queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_modelops_deployment_gate",
        "name": "ModelOps Deployment Gate",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Model deployment approval, risk acceptance, champion/challenger promotion, and release evidence",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_modelops_lineage_graph",
        "name": "ModelOps Lineage Graph",
        "mode": "local",
        "status": "attention",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Lineage scans across warehouse syncs, data contracts, semantic metrics, datasets, forecast runs, and dashboards",
        "events_processed": 0,
        "alerts": 1,
        "last_error": "Review ModelOps readiness queue.",
        "last_retried_at": null
      },
      {
        "id": "conn_agentops_policy_engine",
        "name": "AgentOps Policy Engine",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Agent policies, allowed tools, data scopes, autonomy limits, and kill-switch posture",
        "events_processed": 2,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_agentops_prompt_registry",
        "name": "AgentOps Prompt Registry",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Prompt versions, safety evaluations, release approvals, and deployment evidence",
        "events_processed": 2,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_agentops_tool_sandbox",
        "name": "AgentOps Tool Sandbox",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tool catalog, tool authorizations, execution scopes, and human approval evidence",
        "events_processed": 7,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_agentops_runtime_observer",
        "name": "AgentOps Runtime Observer",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Workflow runs, action traces, blocked reasons, and human review posture",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_agentops_scheduler",
        "name": "AgentOps Automation Scheduler",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Automation schedules, cadence controls, environment gates, and guardrail incidents",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_observability_trace_collector",
        "name": "Runtime Trace Collector",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Workflow trace sessions, correlation IDs, sampled spans, and replay evidence",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_observability_telemetry_bus",
        "name": "Tool Telemetry Bus",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Tool-call metrics, runtime signals, severity posture, and escalation triggers",
        "events_processed": 6,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_observability_incident_router",
        "name": "Incident Router",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "On-call routes, escalation cases, owners, due dates, and resolution evidence",
        "events_processed": 3,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_observability_kill_switch",
        "name": "Production Kill-Switch Control",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Global and scoped kill switches for agents, outbound, providers, and finance actions",
        "events_processed": 4,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_observability_replay_lab",
        "name": "Runtime Replay Lab",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Replay jobs, mismatches, deterministic reruns, and evidence export links",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_observability_slo_monitor",
        "name": "Service-Level Monitor",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "SLO/SLA checks for latency, success rate, error rate, consumer lag, and review age",
        "events_processed": 5,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_runtime_worker_orchestrator",
        "name": "Runtime Worker Orchestrator",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Worker pools, leases, concurrency limits, and queue-to-pool routing",
        "events_processed": 4,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_runtime_job_queue",
        "name": "Runtime Job Queue",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Queued, leased, completed, failed, and dead-lettered runtime jobs",
        "events_processed": 5,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_runtime_tool_proxy_gateway",
        "name": "Tool Proxy Gateway",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Scoped tool proxy registration, policy enforcement, and invocation evidence",
        "events_processed": 4,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_runtime_sandbox_policy",
        "name": "Runtime Sandbox Policy Engine",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Network, PII, runtime, approval, and tool-scope restrictions for worker execution",
        "events_processed": 4,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_runtime_deployment_controller",
        "name": "Runtime Deployment Controller",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Runtime deployment manifests, canary rollout state, promotion evidence, and rollback plans",
        "events_processed": 2,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_runtime_capacity_autoscaler",
        "name": "Capacity + Autoscale Guard",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Capacity checks, queue-depth thresholds, load posture, and autoscale recommendations",
        "events_processed": 4,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_orchestration_workflow_engine",
        "name": "Durable Workflow Engine",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Workflow blueprints, runs, steps, cursor state, and completion evidence",
        "events_processed": 3,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_orchestration_agent_registry",
        "name": "Multi-Agent Registry",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Agent profiles, skills, tool scopes, availability, and ownership boundaries",
        "events_processed": 6,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_orchestration_state_lock",
        "name": "Cross-Agent State Lock Manager",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Object locks for deals, invoices, tenants, provider jobs, and runtime resources",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_orchestration_retry_compensation",
        "name": "Retry + Compensation Controller",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Retry policies, failed step handling, saga compensation, and rollback evidence",
        "events_processed": 2,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_orchestration_handoff_bus",
        "name": "Agent Handoff Bus",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Agent-to-agent handoff requests, acceptances, due dates, and context bundles",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_orchestration_runtime_dispatch",
        "name": "Runtime Dispatch Bridge",
        "mode": "local",
        "status": "healthy",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Workflow-step dispatch into RuntimeOps queues, traces, telemetry, and job receipts",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      },
      {
        "id": "conn_calendar_sync",
        "name": "Calendar Connector Hub",
        "mode": "simulated",
        "status": "simulated",
        "last_event_at": null,
        "retry_queue": 0,
        "coverage": "Meeting scheduling, meeting outcomes, demo logging",
        "events_processed": 0,
        "alerts": 0,
        "last_error": "",
        "last_retried_at": null
      }
    ],
    "event_bus": [
      {
        "id": "event_07edcc8a7a",
        "timestamp": "2026-07-17T19:33:52",
        "source": "cpq_catalog",
        "object_type": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "action": "queued",
        "summary": "Add product NexaMarket Workflow Automation Pack",
        "routed_to": [
          "conn_cpq_governance",
          "conn_approval_fabric",
          "conn_event_gateway",
          "conn_event_delivery_replay"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "catalog_change:catalog_change_b089a47cc9",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "all"
      },
      {
        "id": "event_c4a43a9170",
        "timestamp": "2026-07-17T19:33:52",
        "source": "approval_fabric",
        "object_type": "catalog_change",
        "object_id": "approval_9bcdd9c074",
        "action": "approval_queued",
        "summary": "Catalog governance review: NexaMarket Workflow Automation Pack queued for approval.",
        "routed_to": [
          "conn_approval_fabric",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "catalog_change:approval_9bcdd9c074",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "all"
      },
      {
        "id": "event_b0137ca6e2",
        "timestamp": "2026-07-12T01:35:50",
        "source": "bi_refresh_scheduler",
        "object_type": "analytics_dashboard_refresh",
        "object_id": "dashboard_refresh_ffc92770ea",
        "action": "published_simulated",
        "summary": "Dashboard refresh published_simulated: Executive Revenue BI Dashboard.",
        "routed_to": [
          "conn_bi_refresh_scheduler",
          "conn_board_reporting",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "analytics_dashboard_refresh:dashboard_refresh_ffc92770ea",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "analytics.dashboards"
      },
      {
        "id": "event_e81ba36608",
        "timestamp": "2026-07-12T01:35:50",
        "source": "revenue_intelligence",
        "object_type": "intelligence_metric_snapshot",
        "object_id": "snapshot_749adf2d44",
        "action": "created",
        "summary": "Revenue intelligence snapshot created for 2026-07.",
        "routed_to": [
          "conn_revenue_intelligence",
          "conn_board_reporting",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "intelligence_metric_snapshot:snapshot_749adf2d44",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "intelligence.metrics"
      },
      {
        "id": "event_80737020e1",
        "timestamp": "2026-07-12T01:22:17",
        "source": "platform_sync",
        "object_type": "sync_conflict",
        "object_id": "conflict_provider_provider_esign_stub",
        "action": "resolved",
        "summary": "Platform sync conflict resolved: Provider needs attention: E-Sign Provider Stub.",
        "routed_to": [
          "conn_event_gateway",
          "conn_crm_core",
          "conn_event_delivery_replay"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "sync_conflict:conflict_provider_provider_esign_stub",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "all"
      },
      {
        "id": "event_8dcd406944",
        "timestamp": "2026-07-09T20:45:01",
        "source": "platform_sync",
        "object_type": "sync_conflict",
        "object_id": "conflict_modelops_no_training_dataset",
        "action": "resolved",
        "summary": "Platform sync conflict resolved: No governed training dataset exists.",
        "routed_to": [
          "conn_event_gateway",
          "conn_crm_core",
          "conn_event_delivery_replay"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "sync_conflict:conflict_modelops_no_training_dataset",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "all"
      },
      {
        "id": "event_ab9f79566f",
        "timestamp": "2026-07-09T20:41:01",
        "source": "event_delivery",
        "object_type": "event_subscription",
        "object_id": "sub_dd6819138c",
        "action": "created",
        "summary": "Event subscription created for all.",
        "routed_to": [
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "event_subscription:sub_dd6819138c",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "all"
      },
      {
        "id": "event_153a5bac3f",
        "timestamp": "2026-07-09T20:40:15",
        "source": "provider_gateway",
        "object_type": "sync_job",
        "object_id": "sync_job_86d831e132",
        "action": "completed",
        "summary": "Google Calendar sync completed for meeting.",
        "routed_to": [
          "conn_provider_gateway",
          "conn_event_gateway",
          "conn_event_delivery_replay"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "sync_job:sync_job_86d831e132",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "provider.webhook"
      },
      {
        "id": "event_524d5bc869",
        "timestamp": "2026-07-09T20:40:12",
        "source": "provider_gateway",
        "object_type": "provider_connection",
        "object_id": "provider_calendar_google",
        "action": "test_passed",
        "summary": "Provider connection test passed: Google Calendar.",
        "routed_to": [
          "conn_provider_gateway",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "provider_connection:provider_calendar_google",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "provider.webhook"
      },
      {
        "id": "event_05e81d3652",
        "timestamp": "2026-07-09T20:39:02",
        "source": "forecast",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "action": "forecast_updated",
        "summary": "Forecast updated for deal.",
        "routed_to": [
          "conn_crm_core",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "NexaCRM",
        "canonical_object_key": "deal:placeholder_deal_source_control_seed",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "crm.deal"
      },
      {
        "id": "event_050aec77e2",
        "timestamp": "2026-07-09T20:39:00",
        "source": "forecast",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "action": "forecast_updated",
        "summary": "Forecast updated for deal.",
        "routed_to": [
          "conn_crm_core",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "NexaCRM",
        "canonical_object_key": "deal:placeholder_deal_source_control_seed",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "crm.deal"
      },
      {
        "id": "event_a30bf15457",
        "timestamp": "2026-07-09T20:38:35",
        "source": "match_engine",
        "object_type": "task",
        "object_id": "task_521be1cd49",
        "action": "no_match",
        "summary": "No qualified counterparty found for task \"enterprise saas leads\".",
        "routed_to": [
          "conn_crm_core",
          "conn_event_delivery_replay",
          "conn_event_gateway"
        ],
        "gateway_status": "pending",
        "contract_version": "revenue-sync.v1",
        "owner_system": "Shared Platform",
        "canonical_object_key": "task:task_521be1cd49",
        "sync_attempts": 0,
        "processed_at": null,
        "topic": "all"
      }
    ]
  },
  "audit_center": [
    {
      "timestamp": "2026-07-17T19:33:52",
      "kind": "approval",
      "title": "Catalog governance review: NexaMarket Workflow Automation Pack",
      "detail": "Catalog governance update for next packaging phase.",
      "status": "pending"
    },
    {
      "timestamp": "2026-07-17T19:33:52",
      "kind": "event",
      "title": "cpq_catalog: queued",
      "detail": "Add product NexaMarket Workflow Automation Pack",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-17T19:33:52",
      "kind": "event",
      "title": "approval_fabric: approval_queued",
      "detail": "Catalog governance review: NexaMarket Workflow Automation Pack queued for approval.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-12T01:35:50",
      "kind": "event",
      "title": "bi_refresh_scheduler: published_simulated",
      "detail": "Dashboard refresh published_simulated: Executive Revenue BI Dashboard.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-12T01:35:50",
      "kind": "event",
      "title": "revenue_intelligence: created",
      "detail": "Revenue intelligence snapshot created for 2026-07.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-12T01:22:17",
      "kind": "event",
      "title": "platform_sync: resolved",
      "detail": "Platform sync conflict resolved: Provider needs attention: E-Sign Provider Stub.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:45:01",
      "kind": "event",
      "title": "platform_sync: resolved",
      "detail": "Platform sync conflict resolved: No governed training dataset exists.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:41:01",
      "kind": "event",
      "title": "event_delivery: created",
      "detail": "Event subscription created for all.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:40:15",
      "kind": "event",
      "title": "provider_gateway: completed",
      "detail": "Google Calendar sync completed for meeting.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:40:12",
      "kind": "event",
      "title": "provider_gateway: test_passed",
      "detail": "Provider connection test passed: Google Calendar.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:39:02",
      "kind": "event",
      "title": "forecast: forecast_updated",
      "detail": "Forecast updated for deal.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:39:00",
      "kind": "event",
      "title": "forecast: forecast_updated",
      "detail": "Forecast updated for deal.",
      "status": "logged"
    },
    {
      "timestamp": "2026-07-09T20:38:35",
      "kind": "event",
      "title": "match_engine: no_match",
      "detail": "No qualified counterparty found for task \"enterprise saas leads\".",
      "status": "logged"
    }
  ],
  "production_ops": {
    "audit_events": [
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/run",
        "status_code": 200,
        "correlation_id": "corr_c325197a8dcd46c4",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_108b4d70c677",
        "created_at": "2026-07-09T20:35:42Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/run",
        "status_code": 200,
        "correlation_id": "corr_3be9f5add5da492b",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_bfd4e048d4ed",
        "created_at": "2026-07-09T20:35:48Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/tasks",
        "status_code": 201,
        "correlation_id": "corr_e8e1a60672b44b6d",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_251790180e2a",
        "created_at": "2026-07-09T20:37:15Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/run",
        "status_code": 200,
        "correlation_id": "corr_fbf07e7a13724fdc",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_9d09bd12d340",
        "created_at": "2026-07-09T20:38:35Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/deals/placeholder_deal_source_control_seed/forecast",
        "status_code": 200,
        "correlation_id": "corr_bc168c299db246e2",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_877ea5523d77",
        "created_at": "2026-07-09T20:39:00Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/deals/placeholder_deal_source_control_seed/forecast",
        "status_code": 200,
        "correlation_id": "corr_34922ff727bd4077",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_8bd54be31b5d",
        "created_at": "2026-07-09T20:39:02Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/providers/connections/provider_calendar_google/test",
        "status_code": 200,
        "correlation_id": "corr_f776fa6fe446477b",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_ee8d80231362",
        "created_at": "2026-07-09T20:40:12Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/providers/connections/provider_calendar_google/sync",
        "status_code": 201,
        "correlation_id": "corr_deb3952423384995",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_f942b702e285",
        "created_at": "2026-07-09T20:40:15Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/events/subscriptions",
        "status_code": 201,
        "correlation_id": "corr_83e6e41aebd14818",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_704adca67b0e",
        "created_at": "2026-07-09T20:41:01Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/sync/conflicts/conflict_modelops_no_training_dataset/resolve",
        "status_code": 200,
        "correlation_id": "corr_20161b6af0024cc4",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_66c9b7b9dca9",
        "created_at": "2026-07-09T20:45:01Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/run",
        "status_code": 200,
        "correlation_id": "corr_085aacb2e8f743e4",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_9e53f0290709",
        "created_at": "2026-07-11T01:49:32Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/sync/conflicts/conflict_provider_provider_esign_stub/resolve",
        "status_code": 200,
        "correlation_id": "corr_7aba571371a74a72",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_22368634f2b7",
        "created_at": "2026-07-12T01:22:17Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/run",
        "status_code": 200,
        "correlation_id": "corr_df8d95ece6aa405e",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_2c952ecf9091",
        "created_at": "2026-07-12T01:27:22Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/tasks",
        "status_code": 201,
        "correlation_id": "corr_cb0b4329723442dc",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_723d0dca47dc",
        "created_at": "2026-07-12T01:28:46Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/analytics/dashboard-refreshes",
        "status_code": 201,
        "correlation_id": "corr_b6aac42ecbb448da",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_33ef3e9aac1a",
        "created_at": "2026-07-12T01:35:50Z"
      },
      {
        "type": "mutation",
        "method": "POST",
        "path": "/api/cpq/catalog-changes",
        "status_code": 201,
        "correlation_id": "corr_07dee30fc72e4fa5",
        "idempotency_key": null,
        "replayed": false,
        "actor_id": "user_manager_demo",
        "actor_name": "Avery Stone",
        "actor_email": "avery.stone@nexabuilder.local",
        "actor_role": "manager",
        "tenant_id": "tenant_default",
        "mfa_verified": true,
        "principal_source": "state_session",
        "id": "audit_220c0ecf4932",
        "created_at": "2026-07-17T19:33:52Z"
      }
    ],
    "outbox_events": [
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/cpq/catalog-changes",
        "correlation_id": "corr_07dee30fc72e4fa5",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/cpq/catalog-changes",
          "status_code": 201,
          "idempotency_key": null
        },
        "id": "outbox_6008f77976e1",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-17T19:33:52Z",
        "updated_at": "2026-07-17T19:33:52Z",
        "next_attempt_at": "2026-07-17T19:33:52Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/analytics/dashboard-refreshes",
        "correlation_id": "corr_b6aac42ecbb448da",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/analytics/dashboard-refreshes",
          "status_code": 201,
          "idempotency_key": null
        },
        "id": "outbox_db4dd18596cf",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-12T01:35:50Z",
        "updated_at": "2026-07-12T01:35:50Z",
        "next_attempt_at": "2026-07-12T01:35:50Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/tasks",
        "correlation_id": "corr_cb0b4329723442dc",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/tasks",
          "status_code": 201,
          "idempotency_key": null
        },
        "id": "outbox_d8bf9854ced8",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-12T01:28:46Z",
        "updated_at": "2026-07-12T01:28:46Z",
        "next_attempt_at": "2026-07-12T01:28:46Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/run",
        "correlation_id": "corr_df8d95ece6aa405e",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/run",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_d9f08dea78c8",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-12T01:27:22Z",
        "updated_at": "2026-07-12T01:27:22Z",
        "next_attempt_at": "2026-07-12T01:27:22Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/sync/conflicts/conflict_provider_provider_esign_stub/resolve",
        "correlation_id": "corr_7aba571371a74a72",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/sync/conflicts/conflict_provider_provider_esign_stub/resolve",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_9d2c697007ae",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-12T01:22:17Z",
        "updated_at": "2026-07-12T01:22:17Z",
        "next_attempt_at": "2026-07-12T01:22:17Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/run",
        "correlation_id": "corr_085aacb2e8f743e4",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/run",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_2fbaad90829f",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-11T01:49:32Z",
        "updated_at": "2026-07-11T01:49:32Z",
        "next_attempt_at": "2026-07-11T01:49:32Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/sync/conflicts/conflict_modelops_no_training_dataset/resolve",
        "correlation_id": "corr_20161b6af0024cc4",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/sync/conflicts/conflict_modelops_no_training_dataset/resolve",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_399f99e9cfd4",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:45:01Z",
        "updated_at": "2026-07-09T20:45:01Z",
        "next_attempt_at": "2026-07-09T20:45:01Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/events/subscriptions",
        "correlation_id": "corr_83e6e41aebd14818",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/events/subscriptions",
          "status_code": 201,
          "idempotency_key": null
        },
        "id": "outbox_10c4b31275f1",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:41:01Z",
        "updated_at": "2026-07-09T20:41:01Z",
        "next_attempt_at": "2026-07-09T20:41:01Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/providers/connections/provider_calendar_google/sync",
        "correlation_id": "corr_deb3952423384995",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/providers/connections/provider_calendar_google/sync",
          "status_code": 201,
          "idempotency_key": null
        },
        "id": "outbox_dc817fdc367f",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:40:15Z",
        "updated_at": "2026-07-09T20:40:15Z",
        "next_attempt_at": "2026-07-09T20:40:15Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/providers/connections/provider_calendar_google/test",
        "correlation_id": "corr_f776fa6fe446477b",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/providers/connections/provider_calendar_google/test",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_5c778d2e7f3d",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:40:12Z",
        "updated_at": "2026-07-09T20:40:12Z",
        "next_attempt_at": "2026-07-09T20:40:12Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/deals/placeholder_deal_source_control_seed/forecast",
        "correlation_id": "corr_34922ff727bd4077",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/deals/placeholder_deal_source_control_seed/forecast",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_a686068d9846",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:39:02Z",
        "updated_at": "2026-07-09T20:39:02Z",
        "next_attempt_at": "2026-07-09T20:39:02Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/deals/placeholder_deal_source_control_seed/forecast",
        "correlation_id": "corr_bc168c299db246e2",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/deals/placeholder_deal_source_control_seed/forecast",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_3784350995e5",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:39:00Z",
        "updated_at": "2026-07-09T20:39:00Z",
        "next_attempt_at": "2026-07-09T20:39:00Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/run",
        "correlation_id": "corr_fbf07e7a13724fdc",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/run",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_28fb14f2c4bc",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:38:35Z",
        "updated_at": "2026-07-09T20:38:35Z",
        "next_attempt_at": "2026-07-09T20:38:35Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/tasks",
        "correlation_id": "corr_e8e1a60672b44b6d",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/tasks",
          "status_code": 201,
          "idempotency_key": null
        },
        "id": "outbox_fd10849392e9",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:37:15Z",
        "updated_at": "2026-07-09T20:37:15Z",
        "next_attempt_at": "2026-07-09T20:37:15Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/run",
        "correlation_id": "corr_3be9f5add5da492b",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/run",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_28d83fc5e87e",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:35:48Z",
        "updated_at": "2026-07-09T20:35:48Z",
        "next_attempt_at": "2026-07-09T20:35:48Z"
      },
      {
        "event_type": "platform.mutation.committed",
        "aggregate_type": "http_request",
        "aggregate_id": "/api/run",
        "correlation_id": "corr_c325197a8dcd46c4",
        "tenant_id": "tenant_default",
        "actor_id": "user_manager_demo",
        "payload": {
          "method": "POST",
          "path": "/api/run",
          "status_code": 200,
          "idempotency_key": null
        },
        "id": "outbox_53851ff5f1e6",
        "status": "pending",
        "attempts": 0,
        "created_at": "2026-07-09T20:35:42Z",
        "updated_at": "2026-07-09T20:35:42Z",
        "next_attempt_at": "2026-07-09T20:35:42Z"
      }
    ],
    "claim_freeze_active": true,
    "public_no1_claim_allowed": false,
    "blueprint_100_public_claim_allowed": false,
    "missing_verified_receipt_count": 56,
    "posture": "production_grade_control_plane",
    "controls": {
      "environment": "development",
      "application_version": "7.35.0",
      "storage_mode": "json_state_compatibility",
      "queue_mode": "in_process_compatibility",
      "object_storage_mode": "local_reference_only",
      "secret_manager_mode": "not_configured",
      "identity_mode": "simulated_local_identity",
      "api_auth_required": false,
      "api_key_configured": false,
      "demo_reset_enabled": true,
      "require_idempotency": false,
      "trusted_identity_headers": false,
      "outbox_required": false,
      "allowed_origins_configured": false,
      "csrf_protection_required": false,
      "csrf_token_configured": false,
      "webhook_signature_required": false,
      "webhook_secret_configured": false,
      "webhook_max_age_seconds": 300,
      "edge_rate_limited": false,
      "rate_limit_enabled": false,
      "rate_limit_per_minute": 120,
      "release_manifest_required": false,
      "tenant_isolation_required": false,
      "async_exports_required": false,
      "backup_plan_required": false,
      "repository_contracts_required": false,
      "data_quality_gates_required": false,
      "retention_scans_required": false,
      "secret_reference_enforcement_required": false,
      "policy_bundle_required": false,
      "route_governance_required": false,
      "access_governance_required": false,
      "break_glass_controls_required": false,
      "provider_contract_tests_required": false,
      "incident_response_required": false,
      "slo_evidence_required": false,
      "feature_flags_required": false,
      "deployment_change_control_required": false,
      "dlp_scans_required": false,
      "scheduler_required": false,
      "service_accounts_required": false,
      "object_artifacts_required": false,
      "webhook_replay_required": false,
      "synthetic_monitoring_required": false,
      "api_lifecycle_required": false,
      "compliance_evidence_required": false,
      "data_residency_required": false,
      "backup_drill_required": false,
      "supply_chain_required": false,
      "sbom_required": false,
      "cross_border_export_review_required": false,
      "consent_ledger_required": false,
      "billing_reconciliation_required": false,
      "resilience_drills_required": false,
      "kms_provider_mode": "not_configured",
      "kms_provider_configured": false,
      "kms_controls_required": false,
      "data_encryption_required": false,
      "encryption_key_rotation_days": 365,
      "vulnerability_scans_required": false,
      "dependency_scans_required": false,
      "configuration_baseline_required": false,
      "evidence_seals_required": false,
      "telemetry_pipeline_required": false,
      "otel_exporter_otlp_configured": false,
      "otel_sampling_ratio": 0.1,
      "log_shipping_required": false,
      "siem_export_configured": false,
      "alert_routing_required": false,
      "status_page_configured": false,
      "data_lineage_required": false,
      "capacity_tests_required": false,
      "p95_latency_target_ms": 750,
      "min_available_workers": 2,
      "zero_trust_sessions_required": false,
      "session_risk_required": false,
      "session_max_age_minutes": 480,
      "search_index_required": false,
      "search_index_backend_configured": false,
      "search_index_max_documents": 5000,
      "queue_autoscaling_required": false,
      "queue_max_backlog": 100,
      "migration_rollback_required": false,
      "database_cutover_required": false,
      "migration_shadow_reads_required": false,
      "migration_dual_write_required": false,
      "schema_drift_checks_required": false,
      "query_performance_required": false,
      "archive_lifecycle_required": false,
      "queue_sla_required": false,
      "query_p95_target_ms": 500,
      "queue_backlog_threshold": 100,
      "archive_retention_days": 365,
      "control_objectives_required": false,
      "threat_model_required": false,
      "access_review_cycles_required": false,
      "runbook_automation_required": false,
      "sla_controls_required": false,
      "privacy_subject_rights_required": false,
      "privacy_identity_verification_required": false,
      "privacy_request_sla_days": 30,
      "tenant_entitlements_required": false,
      "usage_metering_required": false,
      "quota_enforcement_required": false,
      "default_tenant_plan": "growth",
      "network_perimeter_required": false,
      "mtls_required": false,
      "service_mesh_required": false,
      "egress_allowlist_required": false,
      "egress_allowlist_configured": false,
      "waf_enabled": false,
      "maintenance_windows_required": false,
      "release_freeze_required": false,
      "customer_sla_credit_policy_configured": false,
      "vendor_risk_required": false,
      "third_party_register_configured": false,
      "privacy_requests_required": false,
      "revenue_recognition_required": false,
      "revenue_recognition_policy_configured": false,
      "model_risk_required": false,
      "model_risk_policy_configured": false,
      "trust_evidence_required": false,
      "trust_portal_configured": false,
      "identity_cutover_required": false,
      "scim_sync_required": false,
      "scim_base_url_configured": false,
      "tenant_activation_required": false,
      "evidence_vault_required": false,
      "evidence_vault_configured": false,
      "evidence_vault_retention_days": 2555,
      "provider_oauth_required": false,
      "oauth_client_registry_configured": false,
      "data_migration_waves_required": false,
      "provider_execution_required": false,
      "notification_delivery_required": false,
      "notification_provider_configured": false,
      "webhook_assurance_required": false,
      "external_audit_required": false,
      "external_audit_register_configured": false,
      "client_app_governance_required": false,
      "redirect_uri_allowlist_required": false,
      "oauth_pkce_required": false,
      "client_secret_rotation_days": 90,
      "data_minimization_required": false,
      "field_level_masking_required": false,
      "default_pii_retention_days": 365,
      "support_escalations_required": false,
      "support_ticketing_configured": false,
      "environment_promotion_required": false,
      "staging_url_configured": false,
      "production_url_configured": false,
      "custom_domain_required": false,
      "dns_provider_configured": false,
      "email_auth_required": false,
      "tls_certificate_provider_configured": false,
      "domain_verification_ttl_hours": 72,
      "warehouse_sync_required": false,
      "warehouse_configured": false,
      "cdc_pipeline_required": false,
      "data_contract_enforcement_required": false,
      "egress_gateway_required": false,
      "egress_gateway_configured": false,
      "secret_rotation_campaigns_required": false,
      "secret_rotation_sla_days": 90,
      "payment_risk_controls_required": false,
      "payment_risk_high_value_threshold_usd": 100000.0,
      "oncall_coverage_required": false,
      "oncall_min_coverage_hours": 24,
      "incident_postmortems_required": false,
      "postmortem_sla_days": 5,
      "data_backfill_required": false,
      "backfill_worker_configured": false,
      "backfill_max_diff_count": 0,
      "email_deliverability_required": false,
      "email_provider_configured": false,
      "email_bounce_threshold_pct": 2.0,
      "email_complaint_threshold_pct": 0.1,
      "contract_obligations_required": false,
      "contract_repository_configured": false,
      "contract_obligation_sla_days": 30,
      "customer_health_governance_required": false,
      "customer_success_system_configured": false,
      "customer_health_review_threshold": 70,
      "customer_health_block_threshold": 45,
      "knowledge_governance_required": false,
      "knowledge_base_configured": false,
      "knowledge_review_days": 90,
      "warehouse_max_cdc_lag_seconds": 300,
      "dr_failover_required": false,
      "secondary_region_configured": false,
      "secondary_region": "",
      "multi_region_object_store_required": false,
      "finops_required": false,
      "cloud_budget_monthly_usd": 0.0,
      "cost_anomaly_threshold_pct": 20.0,
      "cost_tagging_required": false,
      "policy_exceptions_required": false,
      "risk_acceptance_max_days": 30,
      "high_risk_exception_approval_required": true,
      "allowed_data_regions": "us,eu,ca,uk,au",
      "default_data_region": "us",
      "api_deprecation_notice_days": 180,
      "backup_rto_minutes": 240,
      "backup_rpo_minutes": 60,
      "api_token_rotation_days": 90,
      "object_artifact_retention_days": 365,
      "incident_pager_configured": false,
      "database_operations_required": false,
      "database_replica_configured": false,
      "database_migration_tool": "manual_sql_manifest",
      "database_pool_size": 10,
      "database_pitr_required": false,
      "database_replication_lag_threshold_seconds": 60,
      "database_maintenance_window": "not_configured",
      "directory_sync_required": false,
      "directory_deprovisioning_sla_hours": 24,
      "provider_sandbox_required": false,
      "document_custody_required": false,
      "document_custody_retention_days": 2555,
      "error_budget_required": false,
      "error_budget_availability_target_pct": 99.5,
      "error_budget_freeze_threshold_pct": 0.0,
      "error_budget_review_threshold_pct": 20.0,
      "customer_comms_required": false,
      "customer_notification_sla_minutes": 60,
      "service_catalog_required": false,
      "service_owner_review_days": 90,
      "integration_circuit_breakers_required": false,
      "circuit_breaker_failure_threshold": 5,
      "circuit_breaker_cooldown_seconds": 300,
      "privacy_impact_required": false,
      "privacy_impact_policy_configured": false,
      "accessibility_assurance_required": false,
      "accessibility_standard": "WCAG2.2AA",
      "frontend_tests_required": false,
      "cost_governance_required": false,
      "monthly_cloud_budget_usd": 0.0,
      "hypercare_required": false,
      "hypercare_duration_days": 14,
      "launch_readiness_required": false,
      "launch_approval_board_configured": false,
      "production_launch_date": "",
      "go_live_control_required": false,
      "launch_war_room_configured": false,
      "rollback_owner_configured": false,
      "runtime_parity_required": false,
      "post_launch_hypercare_required": false,
      "api_consumer_governance_required": false,
      "api_consumer_program_configured": false,
      "api_consumer_rotation_days": 90,
      "api_consumer_ip_allowlist_required": false,
      "sso_claim_mapping_required": false,
      "sso_group_mapping_configured": false,
      "sso_tenant_claim": "tenant_id",
      "abuse_detection_required": false,
      "abuse_export_threshold": 1000,
      "abuse_failed_auth_threshold": 10,
      "traffic_management_required": false,
      "traffic_controller_configured": false,
      "canary_max_error_rate_pct": 2.0,
      "rollback_execution_required": false,
      "rollback_time_target_minutes": 60,
      "infrastructure_policy_required": false,
      "iac_repository_configured": false,
      "cloud_account_configured": false,
      "terraform_workspace_configured": false,
      "kubernetes_namespace_configured": false,
      "infrastructure_policy_pack_configured": false,
      "release_smoke_tests_required": false,
      "smoke_test_runner_configured": false,
      "smoke_test_min_pass_rate": 100.0,
      "legal_hold_enforcement_required": false,
      "revenue_close_validation_required": false,
      "revenue_close_minimum_records": 1,
      "support_readiness_required": false,
      "data_integrity_required": false,
      "data_integrity_min_score": 95.0,
      "provider_sla_required": false,
      "provider_sla_uptime_target_pct": 99.5,
      "provider_sla_latency_target_ms": 1500,
      "provider_sla_error_rate_threshold_pct": 2.0,
      "tenant_lifecycle_required": false,
      "tenant_offboarding_required": false,
      "workflow_recovery_required": false,
      "workflow_recovery_target_minutes": 30,
      "release_acceptance_required": false,
      "release_acceptance_min_gate_score": 90.0,
      "audit_export_required": false,
      "audit_export_max_lag_seconds": 900,
      "retention_execution_required": false,
      "entitlement_reconciliation_required": false,
      "entitlement_overage_block_threshold_pct": 25.0,
      "contract_renewal_governance_required": false,
      "contract_renewal_notice_days": 90,
      "auto_renew_review_required": true,
      "runtime_guardrails_required": false,
      "runtime_guardrail_max_unapproved_actions": 0,
      "permission_matrix_required": false,
      "permission_matrix_strict": false,
      "export_watermarking_required": false,
      "export_watermark_secret_configured": false,
      "export_watermark_max_expiration_hours": 168,
      "erasure_verification_required": false,
      "incident_comms_approval_required": false,
      "workflow_sandbox_required": false,
      "repository_cutover_execution_required": false,
      "repository_cutover_min_pass_rate": 99.0,
      "repository_adapter_registry_configured": false,
      "route_modularization_required": false,
      "route_modularization_max_main_routes": 150,
      "identity_enforcement_required": false,
      "worker_runtime_binding_required": false,
      "worker_runtime_url_configured": false,
      "provider_adapter_binding_required": false,
      "provider_adapter_registry_configured": false,
      "production_binding_acceptance_required": false,
      "production_binding_min_gate_score": 90.0,
      "repository_adapter_verification_required": false,
      "repository_adapter_min_coverage_pct": 95.0,
      "auth_gateway_verification_required": false,
      "auth_gateway_url_configured": false,
      "auth_gateway_max_failed_tests": 0,
      "worker_supervision_required": false,
      "worker_heartbeat_max_age_seconds": 90,
      "worker_dlq_max_count": 0,
      "provider_live_cutover_required": false,
      "provider_live_cutover_min_ready_pct": 100.0,
      "data_plane_acceptance_required": false,
      "data_plane_acceptance_min_gate_score": 92.0,
      "repository_transaction_binding_required": false,
      "worker_lease_supervision_required": false,
      "worker_lease_max_heartbeat_age_seconds": 60,
      "provider_adapter_execution_required": false,
      "ui_surface_contracts_required": false,
      "ui_surface_max_full_state_fetches": 0,
      "cutover_readiness_evidence_required": false,
      "cutover_readiness_min_gate_score": 92.0,
      "dependency_topology_required": false,
      "dependency_topology_catalog_configured": false,
      "repository_rls_proof_required": false,
      "repository_rls_min_negative_tests": 2,
      "worker_failover_required": false,
      "worker_failover_target_seconds": 120,
      "provider_webhook_binding_required": false,
      "provider_webhook_binding_max_skew_seconds": 300,
      "production_launch_acceptance_required": false,
      "production_launch_acceptance_min_gate_score": 94.0,
      "repository_live_cutover_required": false,
      "repository_live_cutover_min_validation_pct": 99.0,
      "repository_live_cutover_max_mismatch_count": 0,
      "authorization_enforcement_required": false,
      "authorization_enforcement_min_coverage_pct": 100.0,
      "worker_job_runtime_required": false,
      "worker_job_completion_min_pct": 99.0,
      "worker_job_dlq_max_count": 0,
      "provider_webhook_cutover_required": false,
      "provider_webhook_signature_min_pass_pct": 99.0,
      "frontend_navigation_contracts_required": false,
      "frontend_navigation_max_full_state_fetches": 0,
      "runtime_cutover_acceptance_required": false,
      "runtime_cutover_acceptance_min_gate_score": 94.0,
      "postgres_repository_runtime_required": false,
      "repository_runtime_min_contract_pass_pct": 98.0,
      "authz_decision_runtime_required": false,
      "authz_decision_max_bypass_count": 0,
      "durable_worker_queue_required": false,
      "durable_worker_max_lag_seconds": 120,
      "provider_webhook_runtime_required": false,
      "provider_webhook_max_timestamp_skew_seconds": 300,
      "ui_api_regression_required": false,
      "launch_binding_acceptance_required": false,
      "launch_binding_min_gate_score": 94.0,
      "database_repository_binding_required": false,
      "database_repository_min_contract_pass_pct": 99.0,
      "auth_middleware_enforcement_required": false,
      "auth_middleware_max_bypass_routes": 0,
      "worker_daemon_operations_required": false,
      "worker_daemon_max_heartbeat_age_seconds": 90,
      "worker_daemon_max_dlq_count": 0,
      "provider_connector_operations_required": false,
      "provider_connector_min_contract_pass_pct": 99.0,
      "observability_trace_binding_required": false,
      "observability_min_trace_coverage_pct": 95.0,
      "infrastructure_execution_acceptance_required": false,
      "infrastructure_execution_acceptance_min_gate_score": 95.0,
      "repository_connection_pool_required": false,
      "repository_connection_pool_max_acquire_ms": 200,
      "repository_connection_pool_max_failed_health_checks": 0,
      "identity_token_runtime_required": false,
      "identity_token_max_failed_validations": 0,
      "identity_token_max_clock_skew_seconds": 300,
      "worker_orchestration_runtime_required": false,
      "worker_orchestration_max_lag_seconds": 120,
      "worker_orchestration_min_active_workers": 1,
      "provider_connector_health_required": false,
      "provider_connector_health_min_contract_pct": 99.0,
      "provider_connector_health_max_error_pct": 1.0,
      "evidence_pipeline_runtime_required": false,
      "evidence_pipeline_max_lag_seconds": 300,
      "evidence_pipeline_max_failed_deliveries": 0,
      "live_runtime_acceptance_required": false,
      "live_runtime_acceptance_min_gate_score": 95.0,
      "tenant_data_boundary_runtime_required": false,
      "tenant_data_boundary_min_coverage_pct": 100.0,
      "repository_snapshot_consistency_required": false,
      "repository_snapshot_consistency_min_pass_pct": 99.5,
      "repository_snapshot_max_replica_lag_ms": 500,
      "worker_backpressure_runtime_required": false,
      "worker_backpressure_max_queue_age_seconds": 120,
      "worker_backpressure_max_dlq_count": 0,
      "provider_failback_runtime_required": false,
      "provider_failback_max_seconds": 300,
      "provider_failback_max_error_pct": 1.0,
      "observability_slo_burn_required": false,
      "observability_slo_burn_max_1h": 2.0,
      "observability_slo_min_error_budget_remaining_pct": 10.0,
      "runtime_operations_acceptance_required": false,
      "runtime_operations_acceptance_min_gate_score": 96.0,
      "customer_launch_wave_required": false,
      "customer_launch_wave_max_open_blockers": 0,
      "cache_coherency_runtime_required": false,
      "cache_coherency_max_invalidation_lag_ms": 250,
      "cache_coherency_max_stale_reads": 0,
      "queue_replay_runtime_required": false,
      "queue_replay_max_duplicate_effects": 0,
      "queue_replay_max_lag_seconds": 300,
      "provider_credential_attestation_required": false,
      "provider_credential_rotation_max_age_days": 90,
      "support_access_runtime_required": false,
      "support_access_max_unapproved_sessions": 0,
      "support_access_max_session_minutes": 60,
      "launch_wave_acceptance_required": false,
      "launch_wave_acceptance_min_gate_score": 97.0,
      "tenant_migration_cutover_required": false,
      "edge_gateway_runtime_required": false,
      "billing_subscription_cutover_required": false,
      "provider_rate_limit_budget_required": false,
      "compliance_attestation_runtime_required": false,
      "hypercare_command_center_required": false,
      "go_live_acceptance_required": false,
      "go_live_acceptance_min_gate_score": 98.0,
      "no1_program_required": false,
      "no1_program_min_gate_score": 88.0,
      "no1_execution_required": false,
      "no1_execution_min_gate_score": 90.0,
      "no1_leadership_required": false,
      "no1_leadership_min_gate_score": 92.0,
      "no1_productization_required": false,
      "no1_productization_min_gate_score": 94.0,
      "no1_operating_system_required": false,
      "no1_operating_system_min_gate_score": 95.0,
      "no1_future_simulation_required": false,
      "no1_future_simulation_min_gate_score": 96.0,
      "no1_commercialization_required": false,
      "no1_commercialization_min_gate_score": 97.0,
      "no1_growth_scale_required": false,
      "no1_growth_scale_min_gate_score": 98.0,
      "no1_enterprise_scale_required": false,
      "no1_enterprise_scale_min_gate_score": 98.0,
      "no1_global_leadership_required": false,
      "no1_global_leadership_min_gate_score": 99.0,
      "no1_network_effects_required": false,
      "no1_network_effects_min_gate_score": 98.5,
      "no1_global_scale_required": false,
      "no1_global_scale_min_gate_score": 98.5,
      "no1_autonomous_market_mesh_required": false,
      "no1_autonomous_market_mesh_min_gate_score": 99.0,
      "no1_verified_market_network_required": false,
      "no1_verified_market_network_min_gate_score": 99.0,
      "no1_mortalytics_subscription_required": false,
      "no1_mortalytics_subscription_min_gate_score": 99.0,
      "no1_operational_proof_required": false,
      "no1_operational_proof_min_gate_score": 99.0,
      "no1_external_readiness_required": false,
      "no1_external_readiness_min_gate_score": 99.0,
      "no1_completion_certification_required": false,
      "no1_completion_certification_min_gate_score": 99.0,
      "no1_live_evidence_execution_required": false,
      "no1_live_evidence_execution_min_gate_score": 99.0,
      "no1_publishable_proof_required": false,
      "no1_publishable_proof_min_gate_score": 99.0,
      "no1_packet_publication_required": false,
      "no1_packet_publication_min_gate_score": 99.0,
      "no1_publication_export_required": false,
      "no1_publication_export_min_gate_score": 99.0,
      "no1_external_review_execution_required": false,
      "no1_external_review_execution_min_gate_score": 99.0,
      "no1_artifact_integrity_required": false,
      "no1_artifact_integrity_min_gate_score": 99.0,
      "no1_review_artifact_export_required": false,
      "no1_review_artifact_export_min_gate_score": 99.0,
      "no1_formal_delivery_required": false,
      "no1_formal_delivery_min_gate_score": 99.0,
      "no1_builderai_checkpoint_required": false,
      "no1_builderai_checkpoint_min_gate_score": 99.0,
      "no1_runtime_execution_required": false,
      "no1_runtime_execution_min_gate_score": 99.0,
      "no1_dependency_environment_required": false,
      "no1_dependency_environment_min_gate_score": 98.0,
      "no1_production_process_required": false,
      "no1_production_process_min_gate_score": 98.0,
      "no1_final_execution_required": false,
      "no1_final_execution_min_gate_score": 98.0,
      "no1_live_infrastructure_required": false,
      "no1_live_infrastructure_min_gate_score": 98.0,
      "no1_live_proof_closure_required": false,
      "no1_live_proof_closure_min_gate_score": 99.0,
      "metrics_enabled": true
    },
    "readiness": {
      "posture": "production_grade_control_plane",
      "runtime_status": "ready",
      "score": 96,
      "generated_at": "2026-07-27T15:37:40Z",
      "route_count": 2320,
      "settings": {
        "environment": "development",
        "application_version": "7.35.0",
        "storage_mode": "json_state_compatibility",
        "queue_mode": "in_process_compatibility",
        "object_storage_mode": "local_reference_only",
        "secret_manager_mode": "not_configured",
        "identity_mode": "simulated_local_identity",
        "api_auth_required": false,
        "api_key_configured": false,
        "demo_reset_enabled": true,
        "require_idempotency": false,
        "trusted_identity_headers": false,
        "outbox_required": false,
        "allowed_origins_configured": false,
        "csrf_protection_required": false,
        "csrf_token_configured": false,
        "webhook_signature_required": false,
        "webhook_secret_configured": false,
        "webhook_max_age_seconds": 300,
        "edge_rate_limited": false,
        "rate_limit_enabled": false,
        "rate_limit_per_minute": 120,
        "release_manifest_required": false,
        "tenant_isolation_required": false,
        "async_exports_required": false,
        "backup_plan_required": false,
        "repository_contracts_required": false,
        "data_quality_gates_required": false,
        "retention_scans_required": false,
        "secret_reference_enforcement_required": false,
        "policy_bundle_required": false,
        "route_governance_required": false,
        "access_governance_required": false,
        "break_glass_controls_required": false,
        "provider_contract_tests_required": false,
        "incident_response_required": false,
        "slo_evidence_required": false,
        "feature_flags_required": false,
        "deployment_change_control_required": false,
        "dlp_scans_required": false,
        "scheduler_required": false,
        "service_accounts_required": false,
        "object_artifacts_required": false,
        "webhook_replay_required": false,
        "synthetic_monitoring_required": false,
        "api_lifecycle_required": false,
        "compliance_evidence_required": false,
        "data_residency_required": false,
        "backup_drill_required": false,
        "supply_chain_required": false,
        "sbom_required": false,
        "cross_border_export_review_required": false,
        "consent_ledger_required": false,
        "billing_reconciliation_required": false,
        "resilience_drills_required": false,
        "kms_provider_mode": "not_configured",
        "kms_provider_configured": false,
        "kms_controls_required": false,
        "data_encryption_required": false,
        "encryption_key_rotation_days": 365,
        "vulnerability_scans_required": false,
        "dependency_scans_required": false,
        "configuration_baseline_required": false,
        "evidence_seals_required": false,
        "telemetry_pipeline_required": false,
        "otel_exporter_otlp_configured": false,
        "otel_sampling_ratio": 0.1,
        "log_shipping_required": false,
        "siem_export_configured": false,
        "alert_routing_required": false,
        "status_page_configured": false,
        "data_lineage_required": false,
        "capacity_tests_required": false,
        "p95_latency_target_ms": 750,
        "min_available_workers": 2,
        "zero_trust_sessions_required": false,
        "session_risk_required": false,
        "session_max_age_minutes": 480,
        "search_index_required": false,
        "search_index_backend_configured": false,
        "search_index_max_documents": 5000,
        "queue_autoscaling_required": false,
        "queue_max_backlog": 100,
        "migration_rollback_required": false,
        "database_cutover_required": false,
        "migration_shadow_reads_required": false,
        "migration_dual_write_required": false,
        "schema_drift_checks_required": false,
        "query_performance_required": false,
        "archive_lifecycle_required": false,
        "queue_sla_required": false,
        "query_p95_target_ms": 500,
        "queue_backlog_threshold": 100,
        "archive_retention_days": 365,
        "control_objectives_required": false,
        "threat_model_required": false,
        "access_review_cycles_required": false,
        "runbook_automation_required": false,
        "sla_controls_required": false,
        "privacy_subject_rights_required": false,
        "privacy_identity_verification_required": false,
        "privacy_request_sla_days": 30,
        "tenant_entitlements_required": false,
        "usage_metering_required": false,
        "quota_enforcement_required": false,
        "default_tenant_plan": "growth",
        "network_perimeter_required": false,
        "mtls_required": false,
        "service_mesh_required": false,
        "egress_allowlist_required": false,
        "egress_allowlist_configured": false,
        "waf_enabled": false,
        "maintenance_windows_required": false,
        "release_freeze_required": false,
        "customer_sla_credit_policy_configured": false,
        "vendor_risk_required": false,
        "third_party_register_configured": false,
        "privacy_requests_required": false,
        "revenue_recognition_required": false,
        "revenue_recognition_policy_configured": false,
        "model_risk_required": false,
        "model_risk_policy_configured": false,
        "trust_evidence_required": false,
        "trust_portal_configured": false,
        "identity_cutover_required": false,
        "scim_sync_required": false,
        "scim_base_url_configured": false,
        "tenant_activation_required": false,
        "evidence_vault_required": false,
        "evidence_vault_configured": false,
        "evidence_vault_retention_days": 2555,
        "provider_oauth_required": false,
        "oauth_client_registry_configured": false,
        "data_migration_waves_required": false,
        "provider_execution_required": false,
        "notification_delivery_required": false,
        "notification_provider_configured": false,
        "webhook_assurance_required": false,
        "external_audit_required": false,
        "external_audit_register_configured": false,
        "client_app_governance_required": false,
        "redirect_uri_allowlist_required": false,
        "oauth_pkce_required": false,
        "client_secret_rotation_days": 90,
        "data_minimization_required": false,
        "field_level_masking_required": false,
        "default_pii_retention_days": 365,
        "support_escalations_required": false,
        "support_ticketing_configured": false,
        "environment_promotion_required": false,
        "staging_url_configured": false,
        "production_url_configured": false,
        "custom_domain_required": false,
        "dns_provider_configured": false,
        "email_auth_required": false,
        "tls_certificate_provider_configured": false,
        "domain_verification_ttl_hours": 72,
        "warehouse_sync_required": false,
        "warehouse_configured": false,
        "cdc_pipeline_required": false,
        "data_contract_enforcement_required": false,
        "egress_gateway_required": false,
        "egress_gateway_configured": false,
        "secret_rotation_campaigns_required": false,
        "secret_rotation_sla_days": 90,
        "payment_risk_controls_required": false,
        "payment_risk_high_value_threshold_usd": 100000.0,
        "oncall_coverage_required": false,
        "oncall_min_coverage_hours": 24,
        "incident_postmortems_required": false,
        "postmortem_sla_days": 5,
        "data_backfill_required": false,
        "backfill_worker_configured": false,
        "backfill_max_diff_count": 0,
        "email_deliverability_required": false,
        "email_provider_configured": false,
        "email_bounce_threshold_pct": 2.0,
        "email_complaint_threshold_pct": 0.1,
        "contract_obligations_required": false,
        "contract_repository_configured": false,
        "contract_obligation_sla_days": 30,
        "customer_health_governance_required": false,
        "customer_success_system_configured": false,
        "customer_health_review_threshold": 70,
        "customer_health_block_threshold": 45,
        "knowledge_governance_required": false,
        "knowledge_base_configured": false,
        "knowledge_review_days": 90,
        "warehouse_max_cdc_lag_seconds": 300,
        "dr_failover_required": false,
        "secondary_region_configured": false,
        "secondary_region": "",
        "multi_region_object_store_required": false,
        "finops_required": false,
        "cloud_budget_monthly_usd": 0.0,
        "cost_anomaly_threshold_pct": 20.0,
        "cost_tagging_required": false,
        "policy_exceptions_required": false,
        "risk_acceptance_max_days": 30,
        "high_risk_exception_approval_required": true,
        "allowed_data_regions": "us,eu,ca,uk,au",
        "default_data_region": "us",
        "api_deprecation_notice_days": 180,
        "backup_rto_minutes": 240,
        "backup_rpo_minutes": 60,
        "api_token_rotation_days": 90,
        "object_artifact_retention_days": 365,
        "incident_pager_configured": false,
        "database_operations_required": false,
        "database_replica_configured": false,
        "database_migration_tool": "manual_sql_manifest",
        "database_pool_size": 10,
        "database_pitr_required": false,
        "database_replication_lag_threshold_seconds": 60,
        "database_maintenance_window": "not_configured",
        "directory_sync_required": false,
        "directory_deprovisioning_sla_hours": 24,
        "provider_sandbox_required": false,
        "document_custody_required": false,
        "document_custody_retention_days": 2555,
        "error_budget_required": false,
        "error_budget_availability_target_pct": 99.5,
        "error_budget_freeze_threshold_pct": 0.0,
        "error_budget_review_threshold_pct": 20.0,
        "customer_comms_required": false,
        "customer_notification_sla_minutes": 60,
        "service_catalog_required": false,
        "service_owner_review_days": 90,
        "integration_circuit_breakers_required": false,
        "circuit_breaker_failure_threshold": 5,
        "circuit_breaker_cooldown_seconds": 300,
        "privacy_impact_required": false,
        "privacy_impact_policy_configured": false,
        "accessibility_assurance_required": false,
        "accessibility_standard": "WCAG2.2AA",
        "frontend_tests_required": false,
        "cost_governance_required": false,
        "monthly_cloud_budget_usd": 0.0,
        "hypercare_required": false,
        "hypercare_duration_days": 14,
        "launch_readiness_required": false,
        "launch_approval_board_configured": false,
        "production_launch_date": "",
        "go_live_control_required": false,
        "launch_war_room_configured": false,
        "rollback_owner_configured": false,
        "runtime_parity_required": false,
        "post_launch_hypercare_required": false,
        "api_consumer_governance_required": false,
        "api_consumer_program_configured": false,
        "api_consumer_rotation_days": 90,
        "api_consumer_ip_allowlist_required": false,
        "sso_claim_mapping_required": false,
        "sso_group_mapping_configured": false,
        "sso_tenant_claim": "tenant_id",
        "abuse_detection_required": false,
        "abuse_export_threshold": 1000,
        "abuse_failed_auth_threshold": 10,
        "traffic_management_required": false,
        "traffic_controller_configured": false,
        "canary_max_error_rate_pct": 2.0,
        "rollback_execution_required": false,
        "rollback_time_target_minutes": 60,
        "infrastructure_policy_required": false,
        "iac_repository_configured": false,
        "cloud_account_configured": false,
        "terraform_workspace_configured": false,
        "kubernetes_namespace_configured": false,
        "infrastructure_policy_pack_configured": false,
        "release_smoke_tests_required": false,
        "smoke_test_runner_configured": false,
        "smoke_test_min_pass_rate": 100.0,
        "legal_hold_enforcement_required": false,
        "revenue_close_validation_required": false,
        "revenue_close_minimum_records": 1,
        "support_readiness_required": false,
        "data_integrity_required": false,
        "data_integrity_min_score": 95.0,
        "provider_sla_required": false,
        "provider_sla_uptime_target_pct": 99.5,
        "provider_sla_latency_target_ms": 1500,
        "provider_sla_error_rate_threshold_pct": 2.0,
        "tenant_lifecycle_required": false,
        "tenant_offboarding_required": false,
        "workflow_recovery_required": false,
        "workflow_recovery_target_minutes": 30,
        "release_acceptance_required": false,
        "release_acceptance_min_gate_score": 90.0,
        "audit_export_required": false,
        "audit_export_max_lag_seconds": 900,
        "retention_execution_required": false,
        "entitlement_reconciliation_required": false,
        "entitlement_overage_block_threshold_pct": 25.0,
        "contract_renewal_governance_required": false,
        "contract_renewal_notice_days": 90,
        "auto_renew_review_required": true,
        "runtime_guardrails_required": false,
        "runtime_guardrail_max_unapproved_actions": 0,
        "permission_matrix_required": false,
        "permission_matrix_strict": false,
        "export_watermarking_required": false,
        "export_watermark_secret_configured": false,
        "export_watermark_max_expiration_hours": 168,
        "erasure_verification_required": false,
        "incident_comms_approval_required": false,
        "workflow_sandbox_required": false,
        "repository_cutover_execution_required": false,
        "repository_cutover_min_pass_rate": 99.0,
        "repository_adapter_registry_configured": false,
        "route_modularization_required": false,
        "route_modularization_max_main_routes": 150,
        "identity_enforcement_required": false,
        "worker_runtime_binding_required": false,
        "worker_runtime_url_configured": false,
        "provider_adapter_binding_required": false,
        "provider_adapter_registry_configured": false,
        "production_binding_acceptance_required": false,
        "production_binding_min_gate_score": 90.0,
        "repository_adapter_verification_required": false,
        "repository_adapter_min_coverage_pct": 95.0,
        "auth_gateway_verification_required": false,
        "auth_gateway_url_configured": false,
        "auth_gateway_max_failed_tests": 0,
        "worker_supervision_required": false,
        "worker_heartbeat_max_age_seconds": 90,
        "worker_dlq_max_count": 0,
        "provider_live_cutover_required": false,
        "provider_live_cutover_min_ready_pct": 100.0,
        "data_plane_acceptance_required": false,
        "data_plane_acceptance_min_gate_score": 92.0,
        "repository_transaction_binding_required": false,
        "worker_lease_supervision_required": false,
        "worker_lease_max_heartbeat_age_seconds": 60,
        "provider_adapter_execution_required": false,
        "ui_surface_contracts_required": false,
        "ui_surface_max_full_state_fetches": 0,
        "cutover_readiness_evidence_required": false,
        "cutover_readiness_min_gate_score": 92.0,
        "dependency_topology_required": false,
        "dependency_topology_catalog_configured": false,
        "repository_rls_proof_required": false,
        "repository_rls_min_negative_tests": 2,
        "worker_failover_required": false,
        "worker_failover_target_seconds": 120,
        "provider_webhook_binding_required": false,
        "provider_webhook_binding_max_skew_seconds": 300,
        "production_launch_acceptance_required": false,
        "production_launch_acceptance_min_gate_score": 94.0,
        "repository_live_cutover_required": false,
        "repository_live_cutover_min_validation_pct": 99.0,
        "repository_live_cutover_max_mismatch_count": 0,
        "authorization_enforcement_required": false,
        "authorization_enforcement_min_coverage_pct": 100.0,
        "worker_job_runtime_required": false,
        "worker_job_completion_min_pct": 99.0,
        "worker_job_dlq_max_count": 0,
        "provider_webhook_cutover_required": false,
        "provider_webhook_signature_min_pass_pct": 99.0,
        "frontend_navigation_contracts_required": false,
        "frontend_navigation_max_full_state_fetches": 0,
        "runtime_cutover_acceptance_required": false,
        "runtime_cutover_acceptance_min_gate_score": 94.0,
        "postgres_repository_runtime_required": false,
        "repository_runtime_min_contract_pass_pct": 98.0,
        "authz_decision_runtime_required": false,
        "authz_decision_max_bypass_count": 0,
        "durable_worker_queue_required": false,
        "durable_worker_max_lag_seconds": 120,
        "provider_webhook_runtime_required": false,
        "provider_webhook_max_timestamp_skew_seconds": 300,
        "ui_api_regression_required": false,
        "launch_binding_acceptance_required": false,
        "launch_binding_min_gate_score": 94.0,
        "database_repository_binding_required": false,
        "database_repository_min_contract_pass_pct": 99.0,
        "auth_middleware_enforcement_required": false,
        "auth_middleware_max_bypass_routes": 0,
        "worker_daemon_operations_required": false,
        "worker_daemon_max_heartbeat_age_seconds": 90,
        "worker_daemon_max_dlq_count": 0,
        "provider_connector_operations_required": false,
        "provider_connector_min_contract_pass_pct": 99.0,
        "observability_trace_binding_required": false,
        "observability_min_trace_coverage_pct": 95.0,
        "infrastructure_execution_acceptance_required": false,
        "infrastructure_execution_acceptance_min_gate_score": 95.0,
        "repository_connection_pool_required": false,
        "repository_connection_pool_max_acquire_ms": 200,
        "repository_connection_pool_max_failed_health_checks": 0,
        "identity_token_runtime_required": false,
        "identity_token_max_failed_validations": 0,
        "identity_token_max_clock_skew_seconds": 300,
        "worker_orchestration_runtime_required": false,
        "worker_orchestration_max_lag_seconds": 120,
        "worker_orchestration_min_active_workers": 1,
        "provider_connector_health_required": false,
        "provider_connector_health_min_contract_pct": 99.0,
        "provider_connector_health_max_error_pct": 1.0,
        "evidence_pipeline_runtime_required": false,
        "evidence_pipeline_max_lag_seconds": 300,
        "evidence_pipeline_max_failed_deliveries": 0,
        "live_runtime_acceptance_required": false,
        "live_runtime_acceptance_min_gate_score": 95.0,
        "tenant_data_boundary_runtime_required": false,
        "tenant_data_boundary_min_coverage_pct": 100.0,
        "repository_snapshot_consistency_required": false,
        "repository_snapshot_consistency_min_pass_pct": 99.5,
        "repository_snapshot_max_replica_lag_ms": 500,
        "worker_backpressure_runtime_required": false,
        "worker_backpressure_max_queue_age_seconds": 120,
        "worker_backpressure_max_dlq_count": 0,
        "provider_failback_runtime_required": false,
        "provider_failback_max_seconds": 300,
        "provider_failback_max_error_pct": 1.0,
        "observability_slo_burn_required": false,
        "observability_slo_burn_max_1h": 2.0,
        "observability_slo_min_error_budget_remaining_pct": 10.0,
        "runtime_operations_acceptance_required": false,
        "runtime_operations_acceptance_min_gate_score": 96.0,
        "customer_launch_wave_required": false,
        "customer_launch_wave_max_open_blockers": 0,
        "cache_coherency_runtime_required": false,
        "cache_coherency_max_invalidation_lag_ms": 250,
        "cache_coherency_max_stale_reads": 0,
        "queue_replay_runtime_required": false,
        "queue_replay_max_duplicate_effects": 0,
        "queue_replay_max_lag_seconds": 300,
        "provider_credential_attestation_required": false,
        "provider_credential_rotation_max_age_days": 90,
        "support_access_runtime_required": false,
        "support_access_max_unapproved_sessions": 0,
        "support_access_max_session_minutes": 60,
        "launch_wave_acceptance_required": false,
        "launch_wave_acceptance_min_gate_score": 97.0,
        "tenant_migration_cutover_required": false,
        "edge_gateway_runtime_required": false,
        "billing_subscription_cutover_required": false,
        "provider_rate_limit_budget_required": false,
        "compliance_attestation_runtime_required": false,
        "hypercare_command_center_required": false,
        "go_live_acceptance_required": false,
        "go_live_acceptance_min_gate_score": 98.0,
        "no1_program_required": false,
        "no1_program_min_gate_score": 88.0,
        "no1_execution_required": false,
        "no1_execution_min_gate_score": 90.0,
        "no1_leadership_required": false,
        "no1_leadership_min_gate_score": 92.0,
        "no1_productization_required": false,
        "no1_productization_min_gate_score": 94.0,
        "no1_operating_system_required": false,
        "no1_operating_system_min_gate_score": 95.0,
        "no1_future_simulation_required": false,
        "no1_future_simulation_min_gate_score": 96.0,
        "no1_commercialization_required": false,
        "no1_commercialization_min_gate_score": 97.0,
        "no1_growth_scale_required": false,
        "no1_growth_scale_min_gate_score": 98.0,
        "no1_enterprise_scale_required": false,
        "no1_enterprise_scale_min_gate_score": 98.0,
        "no1_global_leadership_required": false,
        "no1_global_leadership_min_gate_score": 99.0,
        "no1_network_effects_required": false,
        "no1_network_effects_min_gate_score": 98.5,
        "no1_global_scale_required": false,
        "no1_global_scale_min_gate_score": 98.5,
        "no1_autonomous_market_mesh_required": false,
        "no1_autonomous_market_mesh_min_gate_score": 99.0,
        "no1_verified_market_network_required": false,
        "no1_verified_market_network_min_gate_score": 99.0,
        "no1_mortalytics_subscription_required": false,
        "no1_mortalytics_subscription_min_gate_score": 99.0,
        "no1_operational_proof_required": false,
        "no1_operational_proof_min_gate_score": 99.0,
        "no1_external_readiness_required": false,
        "no1_external_readiness_min_gate_score": 99.0,
        "no1_completion_certification_required": false,
        "no1_completion_certification_min_gate_score": 99.0,
        "no1_live_evidence_execution_required": false,
        "no1_live_evidence_execution_min_gate_score": 99.0,
        "no1_publishable_proof_required": false,
        "no1_publishable_proof_min_gate_score": 99.0,
        "no1_packet_publication_required": false,
        "no1_packet_publication_min_gate_score": 99.0,
        "no1_publication_export_required": false,
        "no1_publication_export_min_gate_score": 99.0,
        "no1_external_review_execution_required": false,
        "no1_external_review_execution_min_gate_score": 99.0,
        "no1_artifact_integrity_required": false,
        "no1_artifact_integrity_min_gate_score": 99.0,
        "no1_review_artifact_export_required": false,
        "no1_review_artifact_export_min_gate_score": 99.0,
        "no1_formal_delivery_required": false,
        "no1_formal_delivery_min_gate_score": 99.0,
        "no1_builderai_checkpoint_required": false,
        "no1_builderai_checkpoint_min_gate_score": 99.0,
        "no1_runtime_execution_required": false,
        "no1_runtime_execution_min_gate_score": 99.0,
        "no1_dependency_environment_required": false,
        "no1_dependency_environment_min_gate_score": 98.0,
        "no1_production_process_required": false,
        "no1_production_process_min_gate_score": 98.0,
        "no1_final_execution_required": false,
        "no1_final_execution_min_gate_score": 98.0,
        "no1_live_infrastructure_required": false,
        "no1_live_infrastructure_min_gate_score": 98.0,
        "no1_live_proof_closure_required": false,
        "no1_live_proof_closure_min_gate_score": 99.0,
        "metrics_enabled": true
      },
      "checks": [
        {
          "key": "runtime_environment",
          "label": "Explicit runtime environment",
          "status": "pass",
          "severity": "critical",
          "detail": "NEXAMARKET_ENV=development",
          "remediation": "Use one of development, test, staging, production, prod, or production-beta."
        },
        {
          "key": "secret_key",
          "label": "Non-default high-entropy secret",
          "status": "pass",
          "severity": "critical",
          "detail": "Application secret is configured.",
          "remediation": "Set NEXAMARKET_SECRET to a unique 32+ character secret from a managed secret store."
        },
        {
          "key": "api_auth_gate",
          "label": "Fail-closed API auth gate",
          "status": "warn",
          "severity": "critical",
          "detail": "API routes are open for local development.",
          "remediation": "Use the production-beta Cognito route policy or configure OIDC/API key auth for legacy machine APIs."
        },
        {
          "key": "database",
          "label": "Durable SQL persistence",
          "status": "warn",
          "severity": "critical",
          "detail": "Using atomic JSON state compatibility mode.",
          "remediation": "Set DATABASE_URL and run production migrations before live customer traffic."
        },
        {
          "key": "queue_backend",
          "label": "External queue/cache backend",
          "status": "warn",
          "severity": "high",
          "detail": "Runtime jobs use local compatibility state only.",
          "remediation": "Set REDIS_URL or connect an equivalent queue backend for workers, locks, and retries."
        },
        {
          "key": "object_storage",
          "label": "External object/document storage",
          "status": "warn",
          "severity": "high",
          "detail": "Documents remain references/local metadata only.",
          "remediation": "Set OBJECT_STORE_URL or equivalent document storage for contract packages and exports."
        },
        {
          "key": "secret_manager",
          "label": "Managed secret store",
          "status": "warn",
          "severity": "critical",
          "detail": "Provider credentials use local reference metadata only.",
          "remediation": "Set SECRET_MANAGER_URL or NEXAMARKET_SECRET_MANAGER_URL and store provider/OIDC/webhook secrets outside application state."
        },
        {
          "key": "identity_provider",
          "label": "OIDC identity provider",
          "status": "warn",
          "severity": "critical",
          "detail": "Local simulated identity is active.",
          "remediation": "Use production-beta Cognito hosted UI or set OIDC_ISSUER and OIDC_CLIENT_ID and map roles/tenants before production launch."
        },
        {
          "key": "allowed_origins",
          "label": "Explicit browser origin allow-list",
          "status": "warn",
          "severity": "high",
          "detail": "No browser origin allow-list is configured.",
          "remediation": "Set NEXAMARKET_ALLOWED_ORIGINS to the exact production dashboard origin(s)."
        },
        {
          "key": "csrf_protection",
          "label": "Browser CSRF protection",
          "status": "pass",
          "severity": "critical",
          "detail": "CSRF enforcement is optional outside production.",
          "remediation": "Use session-bound CSRF for production-beta or set NEXAMARKET_CSRF_PROTECTION_REQUIRED=true and NEXAMARKET_CSRF_TOKEN for legacy browser/API mutations."
        },
        {
          "key": "signed_webhooks",
          "label": "Signed provider webhook ingress",
          "status": "pass",
          "severity": "critical",
          "detail": "Unsigned provider webhooks are only allowed outside production.",
          "remediation": "Set NEXAMARKET_WEBHOOK_SIGNATURE_REQUIRED=true and NEXAMARKET_WEBHOOK_SECRET before exposing provider webhook ingress."
        },
        {
          "key": "migration_manifest",
          "label": "Database migration manifest",
          "status": "pass",
          "severity": "critical",
          "detail": "158 migration file(s) registered.",
          "remediation": "Keep migrations/MANIFEST.json and SQL files in sync and run them before production deployment."
        },
        {
          "key": "trusted_identity_boundary",
          "label": "Trusted identity header boundary",
          "status": "warn",
          "severity": "critical",
          "detail": "No external identity boundary is active.",
          "remediation": "Terminate OIDC/SAML at the edge or enable NEXAMARKET_TRUSTED_IDENTITY_HEADERS only behind a trusted proxy."
        },
        {
          "key": "outbox_delivery",
          "label": "Transactional outbox delivery path",
          "status": "pass",
          "severity": "high",
          "detail": "Outbox compatibility ledger is local only.",
          "remediation": "Configure Redis/workers or an equivalent durable dispatcher for outbox_events."
        },
        {
          "key": "rate_limit",
          "label": "API rate limiting",
          "status": "warn",
          "severity": "high",
          "detail": "Rate limiting is disabled.",
          "remediation": "Set NEXAMARKET_RATE_LIMIT_ENABLED=true, configure Redis-backed limits, or set NEXAMARKET_EDGE_RATE_LIMITED=true in production."
        },
        {
          "key": "release_manifest",
          "label": "Release evidence manifest",
          "status": "pass",
          "severity": "high",
          "detail": "RELEASE_MANIFEST.json is present.",
          "remediation": "Run scripts/generate_release_manifest.py during CI and attach the manifest to the deploy artifact."
        },
        {
          "key": "tenant_isolation",
          "label": "Tenant-scoped resource access",
          "status": "pass",
          "severity": "critical",
          "detail": "Tenant scoping is optional only outside production.",
          "remediation": "Set NEXAMARKET_TENANT_ISOLATION_REQUIRED=true and enforce tenant_id predicates in production repositories."
        },
        {
          "key": "async_exports",
          "label": "Asynchronous export job path",
          "status": "pass",
          "severity": "high",
          "detail": "Legacy direct exports are allowed only in compatibility mode.",
          "remediation": "Set NEXAMARKET_ASYNC_EXPORTS_REQUIRED=true and route large/sensitive exports through export_jobs."
        },
        {
          "key": "backup_recovery_plan",
          "label": "Backup and recovery evidence plan",
          "status": "pass",
          "severity": "high",
          "detail": "Recovery plan is documented but external backup infrastructure is not declared.",
          "remediation": "Set NEXAMARKET_BACKUP_PLAN_REQUIRED=true, DATABASE_URL, and OBJECT_STORE_URL; schedule restore drills before production."
        },
        {
          "key": "repository_contracts",
          "label": "Repository contract boundary",
          "status": "pass",
          "severity": "critical",
          "detail": "Repository contracts are informational outside production.",
          "remediation": "Set DATABASE_URL and NEXAMARKET_REPOSITORY_CONTRACTS_REQUIRED=true, then route core domains through tenant-aware repositories."
        },
        {
          "key": "data_quality_gates",
          "label": "Production data-quality gates",
          "status": "pass",
          "severity": "high",
          "detail": "Data-quality scans are optional only in compatibility mode.",
          "remediation": "Set NEXAMARKET_DATA_QUALITY_GATES_REQUIRED=true and run /api/data-quality/runs before release cutover."
        },
        {
          "key": "privacy_retention_scans",
          "label": "Privacy retention scan cadence",
          "status": "pass",
          "severity": "high",
          "detail": "Retention scans are optional only in compatibility mode.",
          "remediation": "Set NEXAMARKET_RETENTION_SCANS_REQUIRED=true and schedule retention scan workers for production."
        },
        {
          "key": "secret_reference_enforcement",
          "label": "Secret-reference-only provider credentials",
          "status": "pass",
          "severity": "critical",
          "detail": "Secret-reference enforcement is optional only in local compatibility mode.",
          "remediation": "Set NEXAMARKET_SECRET_REFERENCE_ENFORCEMENT_REQUIRED=true and configure SECRET_MANAGER_URL before live provider integrations."
        },
        {
          "key": "policy_bundle",
          "label": "Policy-as-code bundle enforcement",
          "status": "pass",
          "severity": "critical",
          "detail": "Policy bundle is informational outside production.",
          "remediation": "Set NEXAMARKET_POLICY_BUNDLE_REQUIRED=true and promote a signed policy bundle before production launch."
        },
        {
          "key": "route_governance",
          "label": "Route-control governance inventory",
          "status": "pass",
          "severity": "high",
          "detail": "Route governance is informational outside production.",
          "remediation": "Set NEXAMARKET_ROUTE_GOVERNANCE_REQUIRED=true and review /api/system/route-governance before release."
        },
        {
          "key": "access_governance",
          "label": "Privileged access governance",
          "status": "pass",
          "severity": "critical",
          "detail": "Privileged access governance is optional only in compatibility mode.",
          "remediation": "Set NEXAMARKET_ACCESS_GOVERNANCE_REQUIRED=true and wire privileged access receipts to identity/SIEM."
        },
        {
          "key": "break_glass_controls",
          "label": "Break-glass session controls",
          "status": "pass",
          "severity": "critical",
          "detail": "Break-glass controls are optional only in compatibility mode.",
          "remediation": "Set NEXAMARKET_BREAK_GLASS_CONTROLS_REQUIRED=true and require short-lived MFA-backed emergency sessions."
        },
        {
          "key": "provider_contract_tests",
          "label": "Provider contract-test promotion gates",
          "status": "pass",
          "severity": "high",
          "detail": "Provider contract tests are optional only in compatibility mode.",
          "remediation": "Set NEXAMARKET_PROVIDER_CONTRACT_TESTS_REQUIRED=true and run provider contract tests before enabling live adapters."
        },
        {
          "key": "incident_response",
          "label": "Incident response runbook evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Incident response is documented but external routing is not configured.",
          "remediation": "Set NEXAMARKET_INCIDENT_RESPONSE_REQUIRED=true and NEXAMARKET_INCIDENT_PAGER_URL before production launch."
        },
        {
          "key": "slo_evidence",
          "label": "SLO snapshot evidence cadence",
          "status": "pass",
          "severity": "medium",
          "detail": "SLO snapshots are optional only in compatibility mode.",
          "remediation": "Set NEXAMARKET_SLO_EVIDENCE_REQUIRED=true and schedule /api/system/slo/snapshots capture."
        },
        {
          "key": "feature_flags",
          "label": "Audited feature flags and kill switches",
          "status": "pass",
          "severity": "high",
          "detail": "Feature flags are informational only outside production.",
          "remediation": "Set NEXAMARKET_FEATURE_FLAGS_REQUIRED=true and govern high-risk feature rollout through /api/feature-flags."
        },
        {
          "key": "deployment_change_control",
          "label": "Deployment change-control evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Deployment change-control is optional only outside production.",
          "remediation": "Set NEXAMARKET_DEPLOYMENT_CHANGE_CONTROL_REQUIRED=true and require approved deployment-change records before promotion."
        },
        {
          "key": "dlp_scans",
          "label": "PII/DLP scan evidence",
          "status": "pass",
          "severity": "high",
          "detail": "DLP scans are optional only outside production.",
          "remediation": "Set NEXAMARKET_DLP_SCANS_REQUIRED=true and schedule /api/privacy/dlp-scans before releases and exports."
        },
        {
          "key": "scheduler_controls",
          "label": "Scheduled operations evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Scheduler controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_SCHEDULER_REQUIRED=true and wire scheduled DLP, retention, SLO, outbox, recovery, and data-quality jobs to workers."
        },
        {
          "key": "service_accounts",
          "label": "Service-account and API credential governance",
          "status": "pass",
          "severity": "critical",
          "detail": "Service-account controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_SERVICE_ACCOUNTS_REQUIRED=true, configure SECRET_MANAGER_URL, and require API/OIDC authentication for machine principals."
        },
        {
          "key": "object_artifacts",
          "label": "Object storage artifact lifecycle evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Object artifact controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_OBJECT_ARTIFACTS_REQUIRED=true and OBJECT_STORE_URL, then route exports/contracts/audit bundles to object storage manifests."
        },
        {
          "key": "webhook_replay",
          "label": "Signed webhook replay and dead-letter controls",
          "status": "pass",
          "severity": "high",
          "detail": "Webhook replay controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_WEBHOOK_REPLAY_REQUIRED=true, keep signed webhook verification enabled, and connect replay jobs to durable queue/outbox workers."
        },
        {
          "key": "synthetic_monitoring",
          "label": "Synthetic canary and runtime assurance evidence",
          "status": "pass",
          "severity": "medium",
          "detail": "Synthetic monitoring is optional only outside production.",
          "remediation": "Set NEXAMARKET_SYNTHETIC_MONITORING_REQUIRED=true, scrape /metrics privately, and schedule /api/synthetic-monitor/runs from monitoring infrastructure."
        },
        {
          "key": "api_lifecycle",
          "label": "API lifecycle and compatibility governance",
          "status": "pass",
          "severity": "high",
          "detail": "API lifecycle checks are optional only outside production.",
          "remediation": "Set NEXAMARKET_API_LIFECYCLE_REQUIRED=true and run /api/api-lifecycle/checks before promotion."
        },
        {
          "key": "data_residency",
          "label": "Tenant data residency and transfer controls",
          "status": "pass",
          "severity": "high",
          "detail": "Data residency controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DATA_RESIDENCY_REQUIRED=true, define NEXAMARKET_ALLOWED_DATA_REGIONS, and schedule residency assessments."
        },
        {
          "key": "consent_ledger",
          "label": "Consent preference and suppression ledger",
          "status": "pass",
          "severity": "high",
          "detail": "Consent ledger controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_CONSENT_LEDGER_REQUIRED=true and route opt-in/suppression/privacy preference changes through /api/privacy/consent-events."
        },
        {
          "key": "billing_reconciliation",
          "label": "Billing, payment, and settlement reconciliation",
          "status": "pass",
          "severity": "high",
          "detail": "Billing reconciliation is optional only outside production.",
          "remediation": "Set NEXAMARKET_BILLING_RECONCILIATION_REQUIRED=true and schedule /api/finance/reconciliation-runs with provider payment evidence."
        },
        {
          "key": "resilience_drills",
          "label": "Operational resilience game-day drills",
          "status": "pass",
          "severity": "medium",
          "detail": "Resilience drills are optional only outside production.",
          "remediation": "Set NEXAMARKET_RESILIENCE_DRILLS_REQUIRED=true and record recurring /api/resilience-drills/runs evidence."
        },
        {
          "key": "backup_drills",
          "label": "Backup drill and restore rehearsal evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Backup drills are optional only outside production.",
          "remediation": "Set NEXAMARKET_BACKUP_DRILL_REQUIRED=true, configure DATABASE_URL/OBJECT_STORE_URL, and run /api/recovery/backup-drills on a cadence."
        },
        {
          "key": "compliance_evidence",
          "label": "Compliance evidence pack generation",
          "status": "pass",
          "severity": "medium",
          "detail": "Compliance evidence packs are optional only outside production.",
          "remediation": "Set NEXAMARKET_COMPLIANCE_EVIDENCE_REQUIRED=true and generate evidence packs for release/security reviews."
        },
        {
          "key": "supply_chain",
          "label": "SBOM and supply-chain release evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Supply-chain controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_SUPPLY_CHAIN_REQUIRED=true and NEXAMARKET_SBOM_REQUIRED=true, then run supply-chain scans in CI."
        },
        {
          "key": "kms_controls",
          "label": "Managed KMS and encryption-key governance",
          "status": "pass",
          "severity": "critical",
          "detail": "Managed KMS provider is not configured.",
          "remediation": "Set NEXAMARKET_KMS_CONTROLS_REQUIRED=true, NEXAMARKET_DATA_ENCRYPTION_REQUIRED=true, and KMS_PROVIDER_URL/NEXAMARKET_KMS_PROVIDER_URL before production traffic."
        },
        {
          "key": "vulnerability_scans",
          "label": "Vulnerability and dependency scan evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Vulnerability scans are optional only outside production.",
          "remediation": "Set NEXAMARKET_VULNERABILITY_SCANS_REQUIRED=true and NEXAMARKET_DEPENDENCY_SCANS_REQUIRED=true, then record /api/security/vulnerability-scans evidence in CI/CD."
        },
        {
          "key": "configuration_baseline",
          "label": "Runtime configuration baseline and drift gate",
          "status": "pass",
          "severity": "high",
          "detail": "Configuration baselines are optional only outside production.",
          "remediation": "Set NEXAMARKET_CONFIGURATION_BASELINE_REQUIRED=true, create a production baseline, and evaluate drift before deployment promotion."
        },
        {
          "key": "evidence_seals",
          "label": "Tamper-evident release and audit evidence seals",
          "status": "pass",
          "severity": "high",
          "detail": "Evidence sealing is optional only outside production.",
          "remediation": "Set NEXAMARKET_EVIDENCE_SEALS_REQUIRED=true and use a managed non-default NEXAMARKET_SECRET so HMAC evidence seals are meaningful."
        },
        {
          "key": "telemetry_pipeline",
          "label": "Telemetry export and SIEM/log shipping readiness",
          "status": "pass",
          "severity": "high",
          "detail": "OTLP telemetry exporter is not configured.",
          "remediation": "Set NEXAMARKET_TELEMETRY_PIPELINE_REQUIRED=true, OTEL_EXPORTER_OTLP_ENDPOINT/NEXAMARKET_OTEL_EXPORTER_OTLP_ENDPOINT, and SIEM_EXPORT_URL when log shipping is required."
        },
        {
          "key": "alert_routing",
          "label": "Pager/status alert routing",
          "status": "pass",
          "severity": "high",
          "detail": "Pager routing is not configured.",
          "remediation": "Set NEXAMARKET_ALERT_ROUTING_REQUIRED=true and NEXAMARKET_INCIDENT_PAGER_URL before production launch."
        },
        {
          "key": "data_lineage",
          "label": "Revenue object lineage scan evidence",
          "status": "pass",
          "severity": "medium",
          "detail": "Data lineage scans are optional only outside production.",
          "remediation": "Set NEXAMARKET_DATA_LINEAGE_REQUIRED=true and run /api/data-lineage/runs before release promotion."
        },
        {
          "key": "capacity_tests",
          "label": "Capacity and saturation evidence",
          "status": "pass",
          "severity": "medium",
          "detail": "Capacity tests are optional only outside production.",
          "remediation": "Set NEXAMARKET_CAPACITY_TESTS_REQUIRED=true and record /api/capacity/assessments for staging and production release gates."
        },
        {
          "key": "database_cutover",
          "label": "Database cutover rehearsal evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Database cutover rehearsal is optional only outside production.",
          "remediation": "Set DATABASE_URL, NEXAMARKET_DATABASE_CUTOVER_REQUIRED=true, NEXAMARKET_MIGRATION_SHADOW_READS_REQUIRED=true, and NEXAMARKET_MIGRATION_DUAL_WRITE_REQUIRED=true; then run /api/database/cutover-rehearsals before production traffic."
        },
        {
          "key": "schema_drift_checks",
          "label": "Schema drift and migration manifest gate",
          "status": "pass",
          "severity": "high",
          "detail": "Schema drift checks are optional only outside production.",
          "remediation": "Set NEXAMARKET_SCHEMA_DRIFT_CHECKS_REQUIRED=true and run /api/database/schema-drift-checks for every release promotion."
        },
        {
          "key": "query_performance",
          "label": "Tenant-scoped query performance evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Query performance assessment is optional only outside production.",
          "remediation": "Set NEXAMARKET_QUERY_PERFORMANCE_REQUIRED=true and record /api/database/query-assessments after migration and load-test runs."
        },
        {
          "key": "archive_lifecycle",
          "label": "Archive lifecycle and legal-hold-aware cleanup",
          "status": "pass",
          "severity": "medium",
          "detail": "Archive lifecycle control is optional only outside production.",
          "remediation": "Set NEXAMARKET_ARCHIVE_LIFECYCLE_REQUIRED=true and run /api/archive/runs on a scheduled cadence with object storage configured."
        },
        {
          "key": "queue_sla",
          "label": "Runtime queue backlog and dead-letter SLA gate",
          "status": "pass",
          "severity": "high",
          "detail": "Queue SLA scans are optional only outside production.",
          "remediation": "Set NEXAMARKET_QUEUE_SLA_REQUIRED=true, configure REDIS_URL, and run /api/runtime/queue-sla-scans before production cutover."
        },
        {
          "key": "control_objectives",
          "label": "Compliance control-objective mapping and assessment evidence",
          "status": "pass",
          "severity": "medium",
          "detail": "Control-objective assessments are optional only outside production.",
          "remediation": "Set NEXAMARKET_CONTROL_OBJECTIVES_REQUIRED=true and record /api/compliance/control-assessments before production promotion."
        },
        {
          "key": "threat_model",
          "label": "Threat model and abuse-case review evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Threat-model evidence is optional only outside production.",
          "remediation": "Set NEXAMARKET_THREAT_MODEL_REQUIRED=true and record /api/security/threat-model-runs for high-risk release/provider/workflow changes."
        },
        {
          "key": "access_review_cycles",
          "label": "Periodic privileged access review cycles",
          "status": "pass",
          "severity": "high",
          "detail": "Access review cycles are optional only outside production.",
          "remediation": "Set NEXAMARKET_ACCESS_REVIEW_CYCLES_REQUIRED=true and run /api/security/access-review-cycles for privileged users and service accounts."
        },
        {
          "key": "runbook_automation",
          "label": "Executable incident and operations runbooks",
          "status": "pass",
          "severity": "medium",
          "detail": "Runbook automation evidence is optional only outside production.",
          "remediation": "Set NEXAMARKET_RUNBOOK_AUTOMATION_REQUIRED=true and record /api/runbooks/executions for provider, queue, security, workflow, and export runbooks."
        },
        {
          "key": "sla_controls",
          "label": "Customer SLA and credit governance",
          "status": "pass",
          "severity": "medium",
          "detail": "SLA controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_SLA_CONTROLS_REQUIRED=true and record /api/customer/sla-assessments for customer-facing availability commitments."
        },
        {
          "key": "identity_cutover",
          "label": "Identity-provider cutover and SCIM readiness",
          "status": "pass",
          "severity": "critical",
          "detail": "Identity cutover controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_IDENTITY_CUTOVER_REQUIRED=true, configure OIDC/trusted identity headers, and configure SCIM_BASE_URL when SCIM sync is required."
        },
        {
          "key": "tenant_activation",
          "label": "Tenant activation and customer go-live readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Tenant activation is optional only outside production.",
          "remediation": "Set NEXAMARKET_TENANT_ACTIVATION_REQUIRED=true and record /api/tenants/activation-runs before customer go-live."
        },
        {
          "key": "evidence_vault",
          "label": "Immutable evidence vault",
          "status": "pass",
          "severity": "high",
          "detail": "Evidence-vault external storage is not configured.",
          "remediation": "Set NEXAMARKET_EVIDENCE_VAULT_REQUIRED=true and EVIDENCE_VAULT_URL/NEXAMARKET_EVIDENCE_VAULT_URL for immutable evidence storage."
        },
        {
          "key": "provider_oauth",
          "label": "Provider OAuth client and refresh-token health",
          "status": "pass",
          "severity": "high",
          "detail": "Provider OAuth controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_PROVIDER_OAUTH_REQUIRED=true, OAUTH_CLIENT_REGISTRY_URL, and SECRET_MANAGER_URL before live provider OAuth integrations."
        },
        {
          "key": "data_migration_waves",
          "label": "Production data-migration wave governance",
          "status": "pass",
          "severity": "critical",
          "detail": "Data-migration wave controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DATA_MIGRATION_WAVES_REQUIRED=true, configure DATABASE_URL, and record /api/data-migration/waves before production cutover."
        },
        {
          "key": "provider_execution",
          "label": "Live provider action execution controls",
          "status": "pass",
          "severity": "critical",
          "detail": "Provider execution controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_PROVIDER_EXECUTION_REQUIRED=true, configure SECRET_MANAGER_URL and Redis/outbox delivery, then record /api/providers/action-runs before live provider execution."
        },
        {
          "key": "notification_delivery",
          "label": "Customer/operator notification delivery governance",
          "status": "pass",
          "severity": "high",
          "detail": "Notification delivery controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_NOTIFICATION_DELIVERY_REQUIRED=true, NEXAMARKET_NOTIFICATION_PROVIDER_URL, and NEXAMARKET_CONSENT_LEDGER_REQUIRED=true before customer-facing email/SMS notifications."
        },
        {
          "key": "webhook_assurance",
          "label": "Signed webhook assurance and replay-window checks",
          "status": "pass",
          "severity": "critical",
          "detail": "Webhook assurance controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_WEBHOOK_ASSURANCE_REQUIRED=true, NEXAMARKET_WEBHOOK_SIGNATURE_REQUIRED=true, and configure provider webhook secrets before live ingress."
        },
        {
          "key": "external_audit",
          "label": "External audit engagement and attestation readiness",
          "status": "pass",
          "severity": "medium",
          "detail": "External audit controls are optional unless explicitly required.",
          "remediation": "Set NEXAMARKET_EXTERNAL_AUDIT_REQUIRED=true, NEXAMARKET_EXTERNAL_AUDIT_REGISTER_URL, and evidence-vault settings before sharing audit evidence externally."
        },
        {
          "key": "client_applications",
          "label": "Client-application and OAuth app governance",
          "status": "pass",
          "severity": "high",
          "detail": "Client-application governance is optional only outside production.",
          "remediation": "Set NEXAMARKET_CLIENT_APP_GOVERNANCE_REQUIRED=true, OAUTH_CLIENT_REGISTRY_URL, and SECRET_MANAGER_URL; register browser/server clients before production."
        },
        {
          "key": "data_minimization",
          "label": "Data minimization and field-level masking",
          "status": "pass",
          "severity": "high",
          "detail": "Data minimization controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DATA_MINIMIZATION_REQUIRED=true, require field-level masking, and run /api/privacy/data-minimization-assessments."
        },
        {
          "key": "support_escalations",
          "label": "Customer support escalation and SLA routing",
          "status": "pass",
          "severity": "medium",
          "detail": "Support escalation evidence is optional only outside production.",
          "remediation": "Set NEXAMARKET_SUPPORT_ESCALATIONS_REQUIRED=true and SUPPORT_TICKETING_URL before live customer support operations."
        },
        {
          "key": "environment_promotion",
          "label": "Staging-to-production environment promotion evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Environment promotion controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_ENVIRONMENT_PROMOTION_REQUIRED=true, STAGING_URL, and PRODUCTION_URL; record /api/deployment/environment-promotions before go-live."
        },
        {
          "key": "service_catalog",
          "label": "Service ownership and dependency catalog",
          "status": "pass",
          "severity": "high",
          "detail": "Service catalog governance is optional only outside production.",
          "remediation": "Set NEXAMARKET_SERVICE_CATALOG_REQUIRED=true and register production services through /api/ops/service-catalog/entries."
        },
        {
          "key": "integration_circuit_breakers",
          "label": "Provider integration circuit breakers",
          "status": "pass",
          "severity": "high",
          "detail": "Circuit breaker controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_INTEGRATION_CIRCUIT_BREAKERS_REQUIRED=true and configure REDIS_URL for distributed breaker state."
        },
        {
          "key": "privacy_impact",
          "label": "Privacy impact and DPIA assessments",
          "status": "pass",
          "severity": "high",
          "detail": "Privacy impact controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_PRIVACY_IMPACT_REQUIRED=true and NEXAMARKET_PRIVACY_IMPACT_POLICY_URL, then record /api/privacy/impact-assessments."
        },
        {
          "key": "accessibility_assurance",
          "label": "Accessibility assurance and WCAG release evidence",
          "status": "pass",
          "severity": "medium",
          "detail": "Accessibility controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_ACCESSIBILITY_ASSURANCE_REQUIRED=true and run /api/ux/accessibility-scans for launch-critical UI paths."
        },
        {
          "key": "cost_governance",
          "label": "Cloud cost and FinOps governance",
          "status": "pass",
          "severity": "medium",
          "detail": "Cost governance is optional only outside production.",
          "remediation": "Set NEXAMARKET_COST_GOVERNANCE_REQUIRED=true and NEXAMARKET_MONTHLY_CLOUD_BUDGET_USD before production launch."
        },
        {
          "key": "hypercare",
          "label": "Post-launch hypercare controls",
          "status": "pass",
          "severity": "medium",
          "detail": "Hypercare controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_HYPERCARE_REQUIRED=true, configure SUPPORT_TICKETING_URL, and open /api/ops/hypercare-runs for launches."
        },
        {
          "key": "privacy_subject_rights",
          "label": "Data-subject rights and erasure workflow evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Privacy subject-rights workflow is optional only outside production.",
          "remediation": "Set NEXAMARKET_PRIVACY_SUBJECT_RIGHTS_REQUIRED=true and route access/deletion/suppression requests through /api/privacy/subject-requests."
        },
        {
          "key": "tenant_entitlements",
          "label": "Tenant entitlement, usage-metering, and quota controls",
          "status": "pass",
          "severity": "high",
          "detail": "Tenant entitlement controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_TENANT_ENTITLEMENTS_REQUIRED=true, NEXAMARKET_USAGE_METERING_REQUIRED=true, and NEXAMARKET_QUOTA_ENFORCEMENT_REQUIRED=true; then record /api/usage-metering/events and /api/tenants/entitlement-assessments."
        },
        {
          "key": "network_perimeter",
          "label": "Network perimeter, WAF/API gateway, mTLS, and egress controls",
          "status": "pass",
          "severity": "critical",
          "detail": "Network perimeter checks are optional only outside production.",
          "remediation": "Set NEXAMARKET_NETWORK_PERIMETER_REQUIRED=true, NEXAMARKET_WAF_ENABLED=true, configure egress allow-list evidence, and enable service-mesh/mTLS where required."
        },
        {
          "key": "maintenance_windows",
          "label": "Maintenance windows and release-freeze governance",
          "status": "pass",
          "severity": "medium",
          "detail": "Maintenance windows are optional only outside production.",
          "remediation": "Set NEXAMARKET_MAINTENANCE_WINDOWS_REQUIRED=true, configure status-page/customer notification evidence, and record /api/deployment/maintenance-windows before production changes."
        },
        {
          "key": "zero_trust_sessions",
          "label": "Zero-trust session and MFA-risk evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Session governance is optional only outside production.",
          "remediation": "Set NEXAMARKET_ZERO_TRUST_SESSIONS_REQUIRED=true and NEXAMARKET_SESSION_RISK_REQUIRED=true, then wire OIDC/trusted headers and MFA claims."
        },
        {
          "key": "search_index",
          "label": "Tenant-aware search-index readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Search-index governance is optional only outside production.",
          "remediation": "Set NEXAMARKET_SEARCH_INDEX_REQUIRED=true and configure SEARCH_INDEX_URL/NEXAMARKET_SEARCH_INDEX_URL or DATABASE_URL before indexing customer data."
        },
        {
          "key": "queue_autoscaling",
          "label": "Queue autoscaling and backlog controls",
          "status": "pass",
          "severity": "high",
          "detail": "Queue autoscaling evidence is optional only outside production.",
          "remediation": "Set NEXAMARKET_QUEUE_AUTOSCALING_REQUIRED=true and REDIS_URL, then record /api/queue-autoscaling/assessments during load tests and incidents."
        },
        {
          "key": "migration_rollback",
          "label": "Migration rollback rehearsal evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Migration rollback rehearsals are optional only outside production.",
          "remediation": "Set NEXAMARKET_MIGRATION_ROLLBACK_REQUIRED=true, configure DATABASE_URL, keep migration manifests current, and run /api/migration-rollbacks/rehearsals before release promotion."
        },
        {
          "key": "vendor_risk",
          "label": "Third-party vendor risk and provider due-diligence gate",
          "status": "pass",
          "severity": "high",
          "detail": "Vendor-risk due-diligence controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_VENDOR_RISK_REQUIRED=true and NEXAMARKET_THIRD_PARTY_REGISTER_URL, then run /api/security/vendor-risk-assessments for live providers."
        },
        {
          "key": "privacy_requests",
          "label": "DSAR/privacy request fulfillment controls",
          "status": "pass",
          "severity": "high",
          "detail": "Privacy request controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_PRIVACY_REQUESTS_REQUIRED=true and route data subject access/deletion/export requests through /api/privacy/governed-requests."
        },
        {
          "key": "revenue_recognition",
          "label": "Revenue-recognition and finance-close controls",
          "status": "pass",
          "severity": "high",
          "detail": "Revenue-recognition controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_REVENUE_RECOGNITION_REQUIRED=true and NEXAMARKET_REVENUE_RECOGNITION_POLICY_URL, then run /api/finance/revenue-recognition-runs before finance close."
        },
        {
          "key": "model_risk",
          "label": "AI/model/agent risk assessment controls",
          "status": "pass",
          "severity": "high",
          "detail": "Model-risk controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_MODEL_RISK_REQUIRED=true and NEXAMARKET_MODEL_RISK_POLICY_URL, then run /api/ai/model-risk-assessments before enabling AI/agent releases."
        },
        {
          "key": "trust_evidence",
          "label": "Customer trust evidence sharing controls",
          "status": "pass",
          "severity": "medium",
          "detail": "Trust evidence sharing controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_TRUST_EVIDENCE_REQUIRED=true, NEXAMARKET_TRUST_PORTAL_URL, and OBJECT_STORE_URL, then record /api/trust/evidence-shares for customer assurance packages."
        },
        {
          "key": "database_operations",
          "label": "Database operations and PITR readiness",
          "status": "pass",
          "severity": "critical",
          "detail": "Database operations controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DATABASE_OPERATIONS_REQUIRED=true, DATABASE_URL, DATABASE_REPLICA_URL where applicable, and verify PITR before production cutover."
        },
        {
          "key": "directory_sync",
          "label": "Directory sync and deprovisioning readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Directory sync controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DIRECTORY_SYNC_REQUIRED=true and configure SCIM_BASE_URL or IdP group claims before production tenant activation."
        },
        {
          "key": "provider_sandbox",
          "label": "Provider sandbox validation readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Provider sandbox validation is optional only outside production.",
          "remediation": "Set NEXAMARKET_PROVIDER_SANDBOX_REQUIRED=true, OAUTH_CLIENT_REGISTRY_URL, and SECRET_MANAGER_URL; record sandbox validations before live provider activation."
        },
        {
          "key": "document_custody",
          "label": "Document custody and legal artifact storage",
          "status": "pass",
          "severity": "high",
          "detail": "Document custody controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DOCUMENT_CUSTODY_REQUIRED=true and OBJECT_STORE_URL; store executed contracts as checksummed external artifacts."
        },
        {
          "key": "error_budget",
          "label": "Error budget release guard",
          "status": "pass",
          "severity": "high",
          "detail": "Error budget controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_ERROR_BUDGET_REQUIRED=true and NEXAMARKET_SLO_EVIDENCE_REQUIRED=true; generate error-budget reports before release promotion."
        },
        {
          "key": "customer_comms",
          "label": "Customer communications and status notification readiness",
          "status": "pass",
          "severity": "medium",
          "detail": "Customer communications controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_CUSTOMER_COMMS_REQUIRED=true and configure STATUS_PAGE_URL or incident/customer-notification routing."
        },
        {
          "key": "domain_verification",
          "label": "Tenant custom domain and email-auth readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Domain verification controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_CUSTOM_DOMAIN_REQUIRED=true, NEXAMARKET_DNS_PROVIDER_URL, and TLS/email-auth provider evidence before enabling branded tenant domains."
        },
        {
          "key": "warehouse_sync",
          "label": "Warehouse sync, CDC, and data-contract readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Warehouse sync controls are optional only outside production.",
          "remediation": "Set WAREHOUSE_URL, NEXAMARKET_WAREHOUSE_SYNC_REQUIRED=true, CDC/data-contract gates, and schedule tenant-scoped sync evidence."
        },
        {
          "key": "dr_failover",
          "label": "Regional disaster-recovery failover readiness",
          "status": "pass",
          "severity": "critical",
          "detail": "DR failover controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_DR_FAILOVER_REQUIRED=true, NEXAMARKET_SECONDARY_REGION, and backup/restore evidence before enterprise customer launch."
        },
        {
          "key": "finops",
          "label": "Cloud budget, tagging, and cost-anomaly controls",
          "status": "pass",
          "severity": "medium",
          "detail": "FinOps controls are optional only outside production.",
          "remediation": "Set NEXAMARKET_FINOPS_REQUIRED=true, NEXAMARKET_CLOUD_BUDGET_MONTHLY_USD, and cost-tagging evidence for production operations."
        },
        {
          "key": "policy_exceptions",
          "label": "Risk acceptance and policy-exception governance",
          "status": "pass",
          "severity": "high",
          "detail": "Policy exceptions are compatibility/informational only outside production.",
          "remediation": "Set NEXAMARKET_POLICY_EXCEPTIONS_REQUIRED=true and require approvals, expiry, and compensating controls for risk acceptances."
        },
        {
          "key": "launch_readiness",
          "label": "Final launch-readiness gate",
          "status": "pass",
          "severity": "critical",
          "detail": "Launch readiness gate is optional outside production.",
          "remediation": "Set NEXAMARKET_LAUNCH_READINESS_REQUIRED=true and record /api/launch/readiness-runs before cutover."
        },
        {
          "key": "go_live_control",
          "label": "Go-live command center and rollback owner",
          "status": "pass",
          "severity": "critical",
          "detail": "War room or rollback owner is not configured.",
          "remediation": "Set NEXAMARKET_GO_LIVE_CONTROL_REQUIRED=true, NEXAMARKET_LAUNCH_WAR_ROOM_URL, and NEXAMARKET_ROLLBACK_OWNER."
        },
        {
          "key": "runtime_parity",
          "label": "Staging-to-production runtime parity",
          "status": "pass",
          "severity": "high",
          "detail": "Runtime parity is optional outside production.",
          "remediation": "Set NEXAMARKET_RUNTIME_PARITY_REQUIRED=true and record /api/runtime/parity-checks before production traffic."
        },
        {
          "key": "post_launch_hypercare",
          "label": "Post-launch hypercare reviews",
          "status": "pass",
          "severity": "high",
          "detail": "Hypercare reviews are optional outside production.",
          "remediation": "Set NEXAMARKET_POST_LAUNCH_HYPERCARE_REQUIRED=true and record /api/launch/hypercare-reviews during stabilization."
        },
        {
          "key": "api_consumer_governance",
          "label": "External API consumer governance",
          "status": "pass",
          "severity": "high",
          "detail": "API consumer governance is optional outside production.",
          "remediation": "Set NEXAMARKET_API_CONSUMER_GOVERNANCE_REQUIRED=true and register /api/security/api-consumers before external API access."
        },
        {
          "key": "sso_claim_mapping",
          "label": "SSO claim and role mapping validation",
          "status": "pass",
          "severity": "critical",
          "detail": "SSO claim mapping is optional only outside production.",
          "remediation": "Set NEXAMARKET_SSO_CLAIM_MAPPING_REQUIRED=true, configure OIDC/trusted identity, and run /api/security/sso-claim-checks."
        },
        {
          "key": "abuse_detection",
          "label": "Abuse and anomalous behavior detection",
          "status": "pass",
          "severity": "high",
          "detail": "Abuse detection is optional outside production.",
          "remediation": "Set NEXAMARKET_ABUSE_DETECTION_REQUIRED=true and connect alert or log routing before API launch."
        },
        {
          "key": "traffic_management",
          "label": "Canary, blue/green, and production traffic control",
          "status": "pass",
          "severity": "critical",
          "detail": "Traffic controller is not configured.",
          "remediation": "Set NEXAMARKET_TRAFFIC_MANAGEMENT_REQUIRED=true and NEXAMARKET_TRAFFIC_CONTROLLER_URL before shifting customer traffic."
        },
        {
          "key": "rollback_execution",
          "label": "Rollback execution and post-rollback validation",
          "status": "pass",
          "severity": "critical",
          "detail": "Rollback owner/execution gate is optional only outside production.",
          "remediation": "Set NEXAMARKET_ROLLBACK_EXECUTION_REQUIRED=true, NEXAMARKET_ROLLBACK_OWNER, and record /api/deployment/rollback-runs."
        },
        {
          "key": "data_contract_enforcement",
          "label": "Production data-contract enforcement",
          "status": "pass",
          "severity": "critical",
          "detail": "Data-contract enforcement is optional outside production.",
          "remediation": "Set NEXAMARKET_DATA_CONTRACT_ENFORCEMENT_REQUIRED=true, configure DATABASE_URL, and run /api/data-contracts/runs before release."
        },
        {
          "key": "egress_gateway",
          "label": "Controlled provider egress gateway",
          "status": "pass",
          "severity": "high",
          "detail": "Egress gateway is not configured.",
          "remediation": "Set NEXAMARKET_EGRESS_GATEWAY_REQUIRED=true and NEXAMARKET_EGRESS_GATEWAY_URL before live provider/warehouse egress."
        },
        {
          "key": "secret_rotation_campaigns",
          "label": "Managed secret rotation campaigns",
          "status": "pass",
          "severity": "high",
          "detail": "Secret rotation campaigns are optional outside production.",
          "remediation": "Set NEXAMARKET_SECRET_ROTATION_CAMPAIGNS_REQUIRED=true, configure SECRET_MANAGER_URL, and run /api/security/secret-rotation-campaigns."
        },
        {
          "key": "payment_risk_controls",
          "label": "Payment and payout risk controls",
          "status": "pass",
          "severity": "high",
          "detail": "Payment-risk controls are optional outside production.",
          "remediation": "Set NEXAMARKET_PAYMENT_RISK_CONTROLS_REQUIRED=true and run /api/finance/payment-risk-assessments for payment, settlement, refund, and payout paths."
        },
        {
          "key": "oncall_coverage",
          "label": "On-call coverage and escalation policy",
          "status": "pass",
          "severity": "high",
          "detail": "On-call coverage is optional outside production.",
          "remediation": "Set NEXAMARKET_ONCALL_COVERAGE_REQUIRED=true, configure NEXAMARKET_INCIDENT_PAGER_URL, and run /api/ops/oncall-coverage-checks."
        },
        {
          "key": "incident_postmortems",
          "label": "Incident postmortem and action-item governance",
          "status": "pass",
          "severity": "medium",
          "detail": "Incident postmortems are optional outside production.",
          "remediation": "Set NEXAMARKET_INCIDENT_POSTMORTEMS_REQUIRED=true and record /api/incidents/postmortems for high-severity incidents."
        },
        {
          "key": "data_backfill",
          "label": "Production data backfill remediation",
          "status": "pass",
          "severity": "critical",
          "detail": "Data backfill remediation is optional outside production.",
          "remediation": "Set NEXAMARKET_DATA_BACKFILL_REQUIRED=true, configure DATABASE_URL, and run /api/data-backfill/runs before cutover."
        },
        {
          "key": "email_deliverability",
          "label": "Outbound email deliverability and suppression controls",
          "status": "pass",
          "severity": "high",
          "detail": "Email provider is not configured.",
          "remediation": "Set NEXAMARKET_EMAIL_DELIVERABILITY_REQUIRED=true, configure NEXAMARKET_EMAIL_PROVIDER_URL, and run /api/customer/email-deliverability-assessments."
        },
        {
          "key": "contract_obligations",
          "label": "Post-signature contract obligation tracking",
          "status": "pass",
          "severity": "high",
          "detail": "Contract repository is not configured.",
          "remediation": "Set NEXAMARKET_CONTRACT_OBLIGATIONS_REQUIRED=true, configure NEXAMARKET_CONTRACT_REPOSITORY_URL, and create /api/contracts/obligations records."
        },
        {
          "key": "customer_health_governance",
          "label": "Customer health and renewal-risk governance",
          "status": "pass",
          "severity": "medium",
          "detail": "Customer success system is not configured.",
          "remediation": "Set NEXAMARKET_CUSTOMER_HEALTH_GOVERNANCE_REQUIRED=true, configure NEXAMARKET_CUSTOMER_SUCCESS_SYSTEM_URL, and run /api/customer/health-assessments."
        },
        {
          "key": "knowledge_governance",
          "label": "Runbook and knowledge-base governance",
          "status": "pass",
          "severity": "medium",
          "detail": "Knowledge base is not configured.",
          "remediation": "Set NEXAMARKET_KNOWLEDGE_GOVERNANCE_REQUIRED=true, configure NEXAMARKET_KNOWLEDGE_BASE_URL, and review /api/knowledge/reviews before launch."
        },
        {
          "key": "infrastructure_policy",
          "label": "Infrastructure-as-code and cloud policy evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Infrastructure policy evidence is incomplete.",
          "remediation": "Configure NEXAMARKET_IAC_REPOSITORY_URL, NEXAMARKET_CLOUD_ACCOUNT_ID, and NEXAMARKET_INFRASTRUCTURE_POLICY_PACK_REF before production launch."
        },
        {
          "key": "release_smoke_tests",
          "label": "Launch-critical release smoke tests",
          "status": "pass",
          "severity": "high",
          "detail": "Smoke-test runner is not configured.",
          "remediation": "Configure NEXAMARKET_SMOKE_TEST_RUNNER_URL and record /api/release/smoke-tests before promotion."
        },
        {
          "key": "legal_hold_enforcement",
          "label": "Legal-hold-safe retention enforcement",
          "status": "pass",
          "severity": "critical",
          "detail": "Evidence vault is not configured for legal-hold enforcement.",
          "remediation": "Configure NEXAMARKET_EVIDENCE_VAULT_URL before enabling retention/archive execution."
        },
        {
          "key": "revenue_close_validation",
          "label": "Revenue closeout validation gate",
          "status": "pass",
          "severity": "high",
          "detail": "Revenue closeout validation is optional outside production.",
          "remediation": "Run /api/revenue/close-validations before production closeout automation."
        },
        {
          "key": "support_readiness",
          "label": "Customer support and status-page launch readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Support ticketing or status-page configuration is missing.",
          "remediation": "Configure support/status-page URLs and run /api/customer/support-readiness-runs before go-live."
        },
        {
          "key": "data_integrity",
          "label": "Data integrity and reference-assurance scans",
          "status": "pass",
          "severity": "critical",
          "detail": "Data-integrity scans are optional outside production.",
          "remediation": "Set NEXAMARKET_DATA_INTEGRITY_REQUIRED=true and run /api/data-integrity/runs before promotion."
        },
        {
          "key": "provider_sla",
          "label": "Provider SLA, latency, retry, and dead-letter assurance",
          "status": "pass",
          "severity": "high",
          "detail": "Provider SLA evidence is optional outside production.",
          "remediation": "Set NEXAMARKET_PROVIDER_SLA_REQUIRED=true and run /api/providers/sla-assessments for every live provider family."
        },
        {
          "key": "tenant_lifecycle",
          "label": "Tenant activation, suspension, offboarding, and deletion governance",
          "status": "pass",
          "severity": "critical",
          "detail": "Tenant lifecycle governance is optional outside production.",
          "remediation": "Set NEXAMARKET_TENANT_LIFECYCLE_REQUIRED=true and record /api/tenants/lifecycle-runs before tenant go-live or offboarding."
        },
        {
          "key": "workflow_recovery",
          "label": "Workflow recovery drills for locks, retries, handoffs, and compensation",
          "status": "pass",
          "severity": "high",
          "detail": "Workflow recovery drills are optional outside production.",
          "remediation": "Set NEXAMARKET_WORKFLOW_RECOVERY_REQUIRED=true and run /api/workflows/recovery-drills before autonomous workflow launch."
        },
        {
          "key": "release_acceptance",
          "label": "Aggregated release-acceptance evidence pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Release acceptance packs are optional outside production.",
          "remediation": "Set NEXAMARKET_RELEASE_ACCEPTANCE_REQUIRED=true and create /api/release/acceptance-packs after all launch gates complete."
        },
        {
          "key": "audit_export",
          "label": "Append-only audit export delivery",
          "status": "pass",
          "severity": "critical",
          "detail": "Audit export sink is not configured.",
          "remediation": "Configure SIEM_EXPORT_URL or NEXAMARKET_EVIDENCE_VAULT_URL and create /api/audit/export-batches evidence."
        },
        {
          "key": "retention_execution",
          "label": "Legal-hold-safe retention execution",
          "status": "pass",
          "severity": "critical",
          "detail": "Evidence vault is not configured for retention execution.",
          "remediation": "Configure NEXAMARKET_EVIDENCE_VAULT_URL and record /api/privacy/retention-execution-runs before destructive jobs."
        },
        {
          "key": "entitlement_reconciliation",
          "label": "Tenant entitlement and usage reconciliation",
          "status": "pass",
          "severity": "high",
          "detail": "Entitlement reconciliation is optional outside production.",
          "remediation": "Set NEXAMARKET_ENTITLEMENT_RECONCILIATION_REQUIRED=true and run /api/tenants/entitlement-reconciliations."
        },
        {
          "key": "contract_renewal_governance",
          "label": "Contract renewal and auto-renew governance",
          "status": "pass",
          "severity": "high",
          "detail": "Contract repository URL is not configured for renewal governance.",
          "remediation": "Configure NEXAMARKET_CONTRACT_REPOSITORY_URL and run /api/contracts/renewal-reviews before renewal automation."
        },
        {
          "key": "runtime_guardrails",
          "label": "Runtime and agent tool-action guardrails",
          "status": "pass",
          "severity": "critical",
          "detail": "Runtime guardrails are optional outside production.",
          "remediation": "Set NEXAMARKET_RUNTIME_GUARDRAILS_REQUIRED=true and run /api/runtime/guardrail-checks before enabling autonomous actions."
        },
        {
          "key": "permission_matrix",
          "label": "Route-level least-privilege permission matrix",
          "status": "pass",
          "severity": "critical",
          "detail": "Permission matrix enforcement is optional outside production.",
          "remediation": "Set NEXAMARKET_PERMISSION_MATRIX_REQUIRED=true and run /api/security/permission-matrix-runs before promotion."
        },
        {
          "key": "export_watermarking",
          "label": "Sensitive export watermark and expiration controls",
          "status": "pass",
          "severity": "high",
          "detail": "Export watermark secret is not configured.",
          "remediation": "Set NEXAMARKET_EXPORT_WATERMARKING_REQUIRED=true and NEXAMARKET_EXPORT_WATERMARK_SECRET, then run /api/audit/export-watermark-checks."
        },
        {
          "key": "erasure_verification",
          "label": "Privacy erasure residual-record verification",
          "status": "pass",
          "severity": "critical",
          "detail": "Erasure verification is optional outside production.",
          "remediation": "Set NEXAMARKET_ERASURE_VERIFICATION_REQUIRED=true and capture /api/privacy/erasure-verifications after every erasure fulfillment."
        },
        {
          "key": "incident_comms_approval",
          "label": "Customer-impact incident communications approvals",
          "status": "pass",
          "severity": "high",
          "detail": "Incident communications approval is optional outside production.",
          "remediation": "Set NEXAMARKET_INCIDENT_COMMS_APPROVAL_REQUIRED=true and use /api/incidents/comms-approvals for customer-impacting notices."
        },
        {
          "key": "workflow_sandbox",
          "label": "Workflow sandbox replay before promotion",
          "status": "pass",
          "severity": "high",
          "detail": "Workflow sandbox replay is optional outside production.",
          "remediation": "Set NEXAMARKET_WORKFLOW_SANDBOX_REQUIRED=true and run /api/workflows/sandbox-runs before promoting workflow templates."
        },
        {
          "key": "repository_cutover_execution",
          "label": "Postgres repository cutover execution",
          "status": "pass",
          "severity": "critical",
          "detail": "Database or repository adapter registry is not configured for cutover execution.",
          "remediation": "Configure DATABASE_URL and NEXAMARKET_REPOSITORY_ADAPTER_REGISTRY_URL, then run /api/ops/repository-cutover-runs."
        },
        {
          "key": "route_modularization",
          "label": "Route modularization and blueprint ownership",
          "status": "pass",
          "severity": "high",
          "detail": "Route modularization is optional outside production.",
          "remediation": "Set NEXAMARKET_ROUTE_MODULARIZATION_REQUIRED=true and run /api/ops/route-modularization-runs before production refactor milestones."
        },
        {
          "key": "identity_enforcement",
          "label": "Identity enforcement and negative authorization tests",
          "status": "pass",
          "severity": "critical",
          "detail": "OIDC/SAML or trusted identity headers are not configured.",
          "remediation": "Configure OIDC/SAML or trusted identity headers and run /api/security/identity-enforcement-runs."
        },
        {
          "key": "worker_runtime_binding",
          "label": "Durable worker runtime binding",
          "status": "pass",
          "severity": "critical",
          "detail": "Worker runtime binding is not configured.",
          "remediation": "Configure REDIS_URL or NEXAMARKET_WORKER_RUNTIME_URL and run /api/ops/worker-runtime-bindings."
        },
        {
          "key": "provider_adapter_binding",
          "label": "Live provider adapter binding",
          "status": "pass",
          "severity": "high",
          "detail": "Provider adapter registry is not configured.",
          "remediation": "Configure NEXAMARKET_PROVIDER_ADAPTER_REGISTRY_URL and run /api/providers/adapter-bindings for launch providers."
        },
        {
          "key": "production_binding_acceptance",
          "label": "Production infrastructure-binding acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Production binding acceptance is optional outside production.",
          "remediation": "Set NEXAMARKET_PRODUCTION_BINDING_ACCEPTANCE_REQUIRED=true and create /api/release/production-binding-acceptance-packs after infrastructure gates pass."
        },
        {
          "key": "repository_transaction_binding",
          "label": "Repository transaction-bound audit/outbox binding",
          "status": "pass",
          "severity": "critical",
          "detail": "Database is not configured for repository transaction binding.",
          "remediation": "Configure DATABASE_URL and run /api/ops/repository-transaction-runs for each launch repository boundary."
        },
        {
          "key": "worker_lease_supervision",
          "label": "Durable worker lease supervision",
          "status": "pass",
          "severity": "critical",
          "detail": "Worker lease runtime is not configured.",
          "remediation": "Configure REDIS_URL or NEXAMARKET_WORKER_RUNTIME_URL and run /api/ops/worker-lease-cycles."
        },
        {
          "key": "provider_adapter_execution",
          "label": "Provider adapter execution gate",
          "status": "pass",
          "severity": "high",
          "detail": "Provider adapter registry is not configured for execution gates.",
          "remediation": "Configure NEXAMARKET_PROVIDER_ADAPTER_REGISTRY_URL and run /api/providers/adapter-executions before live provider actions."
        },
        {
          "key": "ui_surface_contracts",
          "label": "Role-based UI surface contract governance",
          "status": "pass",
          "severity": "high",
          "detail": "UI surface contracts are optional outside production.",
          "remediation": "Set NEXAMARKET_UI_SURFACE_CONTRACTS_REQUIRED=true and record /api/ops/ui-surface-contracts for each launch surface."
        },
        {
          "key": "cutover_readiness",
          "label": "Final production cutover readiness evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Cutover readiness evidence is optional outside production.",
          "remediation": "Set NEXAMARKET_CUTOVER_READINESS_EVIDENCE_REQUIRED=true and create /api/release/cutover-readiness-packs after v6.24 gates pass."
        },
        {
          "key": "repository_adapter_verification",
          "label": "Repository adapter verification",
          "status": "pass",
          "severity": "critical",
          "detail": "Database URL or repository adapter registry is missing.",
          "remediation": "Configure DATABASE_URL and NEXAMARKET_REPOSITORY_ADAPTER_REGISTRY_URL, then run /api/ops/repository-adapter-verifications."
        },
        {
          "key": "auth_gateway_verification",
          "label": "Auth gateway verification",
          "status": "pass",
          "severity": "critical",
          "detail": "Auth gateway, OIDC, or trusted identity header boundary is missing.",
          "remediation": "Configure NEXAMARKET_AUTH_GATEWAY_URL or OIDC/trusted headers and run /api/security/auth-gateway-verifications."
        },
        {
          "key": "worker_supervision",
          "label": "Worker supervision and queue health",
          "status": "pass",
          "severity": "critical",
          "detail": "Redis or external worker runtime is not configured.",
          "remediation": "Configure REDIS_URL or NEXAMARKET_WORKER_RUNTIME_URL and run /api/ops/worker-supervision-checks."
        },
        {
          "key": "provider_live_cutover",
          "label": "Provider live cutover readiness",
          "status": "pass",
          "severity": "high",
          "detail": "Provider adapter registry is missing for live cutover.",
          "remediation": "Configure NEXAMARKET_PROVIDER_ADAPTER_REGISTRY_URL and run /api/providers/live-cutover-runs."
        },
        {
          "key": "data_plane_acceptance",
          "label": "Data-plane acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Data-plane acceptance is optional outside production.",
          "remediation": "Set NEXAMARKET_DATA_PLANE_ACCEPTANCE_REQUIRED=true and create /api/release/data-plane-acceptance-packs after v6.24 gates pass."
        },
        {
          "key": "postgres_repository_runtime",
          "label": "Postgres repository runtime binding",
          "status": "pass",
          "severity": "critical",
          "detail": "Database URL or repository adapter registry is missing for repository runtime.",
          "remediation": "Configure DATABASE_URL and NEXAMARKET_REPOSITORY_ADAPTER_REGISTRY_URL, then run /api/ops/postgres-repository-runtime-checks."
        },
        {
          "key": "authz_decision_runtime",
          "label": "Runtime authorization decision enforcement",
          "status": "pass",
          "severity": "critical",
          "detail": "Auth gateway, OIDC, or trusted identity boundary is missing for runtime authz proof.",
          "remediation": "Configure auth gateway/OIDC/trusted headers and run /api/security/authz-decision-checks."
        },
        {
          "key": "durable_worker_queue",
          "label": "Durable worker queue runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Redis or worker runtime URL is missing for durable queue binding.",
          "remediation": "Configure REDIS_URL or NEXAMARKET_WORKER_RUNTIME_URL and run /api/ops/durable-worker-queue-runs."
        },
        {
          "key": "provider_webhook_runtime",
          "label": "Signed provider webhook runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Webhook signing secret or managed secret store is missing.",
          "remediation": "Configure webhook secret references and run /api/providers/webhook-runtime-checks for launch providers."
        },
        {
          "key": "ui_api_regression",
          "label": "Role-based UI/API regression gate",
          "status": "pass",
          "severity": "high",
          "detail": "UI/API regression evidence is optional outside production.",
          "remediation": "Set NEXAMARKET_UI_API_REGRESSION_REQUIRED=true and run /api/ops/ui-api-regression-runs for launch surfaces."
        },
        {
          "key": "launch_binding_acceptance",
          "label": "Production launch binding acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Launch binding acceptance is optional outside production.",
          "remediation": "Create /api/release/launch-binding-packs after repository, authz, worker, webhook, UI, and cutover gates pass."
        },
        {
          "key": "dependency_topology",
          "label": "Service dependency topology and blast-radius evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Dependency topology evidence is optional outside production.",
          "remediation": "Set NEXAMARKET_DEPENDENCY_TOPOLOGY_REQUIRED=true and run /api/ops/dependency-topology-checks."
        },
        {
          "key": "repository_rls_proof",
          "label": "Repository tenant SQL/RLS proof",
          "status": "pass",
          "severity": "critical",
          "detail": "Database URL or repository adapter registry is missing for RLS proof.",
          "remediation": "Configure DATABASE_URL and NEXAMARKET_REPOSITORY_ADAPTER_REGISTRY_URL, then run /api/ops/repository-rls-proofs."
        },
        {
          "key": "worker_failover",
          "label": "Worker failover and job recovery rehearsal",
          "status": "pass",
          "severity": "critical",
          "detail": "Redis or worker runtime is not configured for failover rehearsal.",
          "remediation": "Configure REDIS_URL or NEXAMARKET_WORKER_RUNTIME_URL, then run /api/ops/worker-failover-rehearsals."
        },
        {
          "key": "provider_webhook_binding",
          "label": "Provider webhook ingress binding",
          "status": "pass",
          "severity": "critical",
          "detail": "Signed provider webhook ingress is not fully configured.",
          "remediation": "Set NEXAMARKET_PROVIDER_WEBHOOK_BINDING_REQUIRED=true, configure signed webhook secrets/refs, and run /api/providers/webhook-bindings."
        },
        {
          "key": "production_launch_acceptance",
          "label": "Final production launch acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Production launch acceptance is optional outside production.",
          "remediation": "Set NEXAMARKET_PRODUCTION_LAUNCH_ACCEPTANCE_REQUIRED=true and create /api/release/production-launch-acceptance-packs after v6.25 gates pass."
        },
        {
          "key": "repository_live_cutover",
          "label": "Repository live cutover execution",
          "status": "pass",
          "severity": "critical",
          "detail": "Database URL or repository adapter registry is missing for live repository cutover.",
          "remediation": "Configure DATABASE_URL and NEXAMARKET_REPOSITORY_ADAPTER_REGISTRY_URL, then run /api/ops/repository-live-cutovers."
        },
        {
          "key": "authorization_enforcement",
          "label": "Authorization enforcement runtime proof",
          "status": "pass",
          "severity": "critical",
          "detail": "Trusted identity/OIDC is missing for authorization enforcement.",
          "remediation": "Configure identity boundary and run /api/security/authorization-enforcement-checks."
        },
        {
          "key": "worker_job_runtime",
          "label": "Worker job runtime execution",
          "status": "pass",
          "severity": "critical",
          "detail": "Redis or worker runtime URL is missing for worker job runtime.",
          "remediation": "Configure REDIS_URL or worker runtime URL and run /api/ops/worker-job-batches."
        },
        {
          "key": "provider_webhook_cutover",
          "label": "Provider webhook live cutover",
          "status": "pass",
          "severity": "critical",
          "detail": "Webhook signing secret or secret manager is missing for provider webhook cutover.",
          "remediation": "Configure webhook secret refs and run /api/providers/webhook-cutovers."
        },
        {
          "key": "frontend_navigation_contracts",
          "label": "Frontend navigation contract evidence",
          "status": "pass",
          "severity": "high",
          "detail": "Frontend navigation contract evidence is optional outside production.",
          "remediation": "Run /api/ops/frontend-navigation-contracts for launch roles and ensure no full-state fetch dependency."
        },
        {
          "key": "runtime_cutover_acceptance",
          "label": "Runtime launch cutover acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Runtime cutover acceptance is optional outside production.",
          "remediation": "Create /api/release/runtime-cutover-acceptance-packs after live repository, authz, worker, webhook, and frontend gates pass."
        },
        {
          "key": "repository_connection_pool",
          "label": "Repository connection-pool runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Repository connection pool lacks DATABASE_URL backing.",
          "remediation": "Configure DATABASE_URL and run /api/ops/repository-connection-pool-checks with RLS session-context proof."
        },
        {
          "key": "identity_token_runtime",
          "label": "Identity token validation runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "OIDC/trusted identity is missing for token runtime validation.",
          "remediation": "Configure OIDC_ISSUER/OIDC_CLIENT_ID or trusted identity headers and run /api/security/identity-token-runtime-checks."
        },
        {
          "key": "worker_orchestration_runtime",
          "label": "Worker orchestration runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Redis or worker runtime URL is missing for worker orchestration.",
          "remediation": "Configure REDIS_URL or worker runtime URL and run /api/ops/worker-orchestration-runs."
        },
        {
          "key": "provider_connector_health",
          "label": "Provider connector health runtime",
          "status": "pass",
          "severity": "high",
          "detail": "Provider connector health lacks adapter registry/secret-manager backing.",
          "remediation": "Configure provider adapter registry, managed credential refs, and run /api/providers/connector-health-checks."
        },
        {
          "key": "evidence_pipeline_runtime",
          "label": "Evidence pipeline runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Evidence pipeline lacks object storage or immutable sink configuration.",
          "remediation": "Configure object storage plus SIEM/evidence-vault sink and run /api/audit/evidence-pipeline-runs."
        },
        {
          "key": "live_runtime_acceptance",
          "label": "Live runtime acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Live runtime acceptance is optional outside production.",
          "remediation": "Create /api/release/live-runtime-acceptance-packs after repository pool, token runtime, worker orchestration, provider health, evidence pipeline, infrastructure, data-plane, and launch gates pass."
        },
        {
          "key": "tenant_data_boundary_runtime",
          "label": "Tenant data-boundary runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Tenant data-boundary runtime lacks database or trusted identity context evidence.",
          "remediation": "Configure tenant-scoped repositories and run /api/security/tenant-data-boundary-checks."
        },
        {
          "key": "repository_snapshot_consistency",
          "label": "Repository snapshot consistency",
          "status": "pass",
          "severity": "critical",
          "detail": "Repository snapshot consistency lacks DATABASE_URL backing.",
          "remediation": "Configure Postgres repositories and run /api/ops/repository-snapshot-consistency-checks."
        },
        {
          "key": "worker_backpressure_runtime",
          "label": "Worker backpressure runtime",
          "status": "pass",
          "severity": "high",
          "detail": "Worker backpressure runtime lacks queue backend configuration.",
          "remediation": "Configure REDIS_URL or worker runtime URL and run /api/ops/worker-backpressure-runs."
        },
        {
          "key": "provider_failback_runtime",
          "label": "Provider failback runtime",
          "status": "pass",
          "severity": "high",
          "detail": "Provider failback lacks adapter registry or managed secret configuration.",
          "remediation": "Configure provider adapters and run /api/providers/failback-runs."
        },
        {
          "key": "observability_slo_burn_runtime",
          "label": "Observability SLO burn runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "SLO burn runtime lacks telemetry/SIEM backing.",
          "remediation": "Configure OTEL/SIEM and run /api/observability/slo-burn-checks."
        },
        {
          "key": "runtime_operations_acceptance",
          "label": "Runtime operations acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Runtime operations acceptance is optional outside production.",
          "remediation": "Create /api/release/runtime-operations-acceptance-packs after tenant boundary, repository consistency, worker backpressure, provider failback, SLO burn, and live-runtime gates pass."
        },
        {
          "key": "customer_launch_wave",
          "label": "Customer launch-wave governance",
          "status": "pass",
          "severity": "critical",
          "detail": "Customer launch-wave gating is optional outside production.",
          "remediation": "Run /api/launch/customer-waves with acceptance, rollback, tenant-boundary, support, and comms evidence."
        },
        {
          "key": "cache_coherency_runtime",
          "label": "Cache coherency runtime proof",
          "status": "pass",
          "severity": "critical",
          "detail": "Cache coherency proof is optional outside production.",
          "remediation": "Run /api/ops/cache-coherency-checks and verify tenant key namespaces, invalidation, read-after-write, and metrics."
        },
        {
          "key": "queue_replay_runtime",
          "label": "Queue replay runtime proof",
          "status": "pass",
          "severity": "critical",
          "detail": "Queue replay proof is optional outside production.",
          "remediation": "Run /api/ops/queue-replay-runs and verify idempotency, ordering, poison-message isolation, and audit/outbox correlation."
        },
        {
          "key": "provider_credential_attestation",
          "label": "Provider credential attestation",
          "status": "pass",
          "severity": "critical",
          "detail": "Provider credential attestation requires SECRET_MANAGER_URL.",
          "remediation": "Run /api/providers/credential-attestations and verify secret references, OAuth refresh, rotation, webhook secrets, egress, and audit evidence."
        },
        {
          "key": "support_access_runtime",
          "label": "Support access runtime controls",
          "status": "pass",
          "severity": "critical",
          "detail": "Support access runtime controls are optional outside production.",
          "remediation": "Run /api/security/support-access-runtime-checks and verify reason, MFA, timebox, redaction, audit, revocation, and post-access review evidence."
        },
        {
          "key": "launch_wave_acceptance",
          "label": "Launch-wave acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Launch-wave acceptance is optional outside production.",
          "remediation": "Create /api/release/launch-wave-acceptance-packs after customer wave, cache, queue replay, provider credential, support access, runtime operations, and release acceptance gates pass."
        },
        {
          "key": "tenant_migration_cutover",
          "label": "Tenant migration cutover execution",
          "status": "pass",
          "severity": "critical",
          "detail": "Tenant migration cutover requires DATABASE_URL.",
          "remediation": "Run /api/ops/tenant-migration-cutovers with RLS, dual-write, diff, privacy, and rollback evidence."
        },
        {
          "key": "edge_gateway_runtime",
          "label": "Edge gateway runtime binding",
          "status": "pass",
          "severity": "critical",
          "detail": "Edge gateway runtime lacks allowed origins or edge rate-limit evidence.",
          "remediation": "Run /api/security/edge-gateway-checks."
        },
        {
          "key": "billing_subscription_cutover",
          "label": "Billing subscription cutover",
          "status": "pass",
          "severity": "critical",
          "detail": "Billing cutover requires managed secret/provider credential references.",
          "remediation": "Run /api/finance/billing-subscription-cutovers."
        },
        {
          "key": "provider_rate_limit_budget",
          "label": "Provider rate-limit budget runtime",
          "status": "pass",
          "severity": "high",
          "detail": "Provider rate-limit budget lacks adapter registry or runtime queue/cache backing.",
          "remediation": "Run /api/providers/rate-limit-budgets."
        },
        {
          "key": "compliance_attestation_runtime",
          "label": "Compliance attestation runtime",
          "status": "pass",
          "severity": "critical",
          "detail": "Compliance attestation is optional outside production.",
          "remediation": "Run /api/compliance/attestations."
        },
        {
          "key": "hypercare_command_center",
          "label": "Hypercare command center",
          "status": "pass",
          "severity": "critical",
          "detail": "Hypercare command center is optional outside production.",
          "remediation": "Run /api/ops/hypercare-command-runs."
        },
        {
          "key": "go_live_acceptance",
          "label": "Go-live acceptance pack",
          "status": "pass",
          "severity": "critical",
          "detail": "Go-live acceptance is optional outside production.",
          "remediation": "Create /api/release/go-live-acceptance-packs."
        },
        {
          "key": "no1_market_program",
          "label": "No. 1 market/revenue program blueprint gates",
          "status": "pass",
          "severity": "critical",
          "detail": "No. 1 program gates are optional outside production.",
          "remediation": "Create /api/release/no1-program-acceptance-packs after scope lock, cockpit, graph, discovery, proof, campaign simulation, safe outreach, provider live gate, workflow commander, revenue boardroom, AI evidence, and NexaTrust evidence pass."
        },
        {
          "key": "no1_execution_readiness",
          "label": "No. 1 execution-readiness evidence gates",
          "status": "pass",
          "severity": "critical",
          "detail": "No. 1 execution-readiness gates are optional outside production.",
          "remediation": "Create /api/release/no1-execution-acceptance-packs after sprint backlog, UI prototype, acceptance tests, provider certification, AI policies/evals, pilot scorecard, and demo script pass."
        },
        {
          "key": "no1_leadership_proof",
          "label": "No. 1 leadership-proof evidence gates",
          "status": "pass",
          "severity": "critical",
          "detail": "No. 1 leadership-proof gates are optional outside production.",
          "remediation": "Create /api/release/no1-leadership-acceptance-packs after benchmark, pilot, data-rights, CRM handoff, UX polish, claim guard, and customer/investor proof evidence pass."
        },
        {
          "key": "no1_productization_runtime",
          "label": "No. 1 productization runtime gates",
          "status": "pass",
          "severity": "critical",
          "detail": "No. 1 productization gates are optional outside production.",
          "remediation": "Create /api/release/no1-productization-acceptance-packs after signal ingestion, target queue, proof workflow, campaign lab, safe outreach, CRM promotion, trust portal, and boardroom evidence pass."
        },
        {
          "key": "no1_operating_system_runtime",
          "label": "No. 1 market operating-system gates",
          "status": "pass",
          "severity": "critical",
          "detail": "No. 1 operating-system gates are optional outside production.",
          "remediation": "Create /api/release/no1-operating-system-acceptance-packs after cockpit, market intelligence, agent ledger, revenue motion, provider ecosystem, customer proof, and trust attestation evidence pass."
        },
        {
          "key": "no1_future_simulation_runtime",
          "label": "No. 1 future simulation and market-digital-twin gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Future-simulation gates are optional outside production.",
          "remediation": "Create /api/release/no1-future-simulation-acceptance-packs after market twin, benchmark, agent simulation, consent intelligence, proof-to-revenue, demo narrative, and launch scorecard evidence pass."
        },
        {
          "key": "no1_commercialization_runtime",
          "label": "No. 1 commercialization and market-launch gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Commercialization gates are optional outside production.",
          "remediation": "Create /api/release/no1-commercialization-acceptance-packs after pilot cohort, GTM, pricing, partner marketplace, public trust, customer reference, and analytics-loop evidence pass."
        },
        {
          "key": "no1_growth_scale_runtime",
          "label": "No. 1 growth-scale and enterprise value gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Growth-scale gates are optional outside production.",
          "remediation": "Create /api/release/no1-growth-scale-acceptance-packs after enterprise expansion, onboarding, value realization, win/loss, marketplace distribution, benchmark publication, and lifecycle-retention evidence pass."
        },
        {
          "key": "no1_enterprise_scale_runtime",
          "label": "No. 1 enterprise-scale and expansion gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Enterprise-scale gates are optional outside production.",
          "remediation": "Create /api/release/no1-enterprise-scale-acceptance-packs after procurement, questionnaire, data-rights, implementation, expansion, partner-channel, and leadership-certification evidence pass."
        },
        {
          "key": "no1_global_leadership_runtime",
          "label": "No. 1 global leadership and autonomous governance gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Global-leadership gates are optional outside production.",
          "remediation": "Create /api/release/no1-global-leadership-acceptance-packs after regulatory, customer advisory, trust marketplace, benchmark observatory, ecosystem quality, autonomous governance, AI drift, and command-room evidence pass."
        },
        {
          "key": "no1_network_effects_runtime",
          "label": "No. 1 network-effects, trust-score, partner co-sell, and moat gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Network-effect gates are optional outside production.",
          "remediation": "Create /api/release/no1-network-effects-acceptance-packs after ecosystem map, federated proof, partner co-sell, trust score, community loop, moat, and leadership-index evidence pass."
        },
        {
          "key": "no1_global_scale_runtime",
          "label": "No. 1 global scale, localization, sovereign data, and regional support gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Global-scale gates are optional outside production.",
          "remediation": "Create /api/release/no1-global-scale-acceptance-packs after regional launch, localization, billing/tax, follow-the-sun support, sovereign data, and global partner-channel evidence pass."
        },
        {
          "key": "no1_autonomous_market_mesh_runtime",
          "label": "No. 1 autonomous-market-mesh, proof-ledger, privacy benchmark, risk-command and flywheel gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Autonomous-market-mesh gates are optional outside production.",
          "remediation": "Create /api/release/no1-autonomous-market-mesh-acceptance-packs after mesh topology, agent decision rights, proof ledger, privacy benchmark, incentive alignment, risk command, and flywheel evidence pass."
        },
        {
          "key": "no1_verified_market_network_runtime",
          "label": "No. 1 verified market-network, consent-token, proof-exchange and agent-certification gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Verified-market-network gates are optional outside production.",
          "remediation": "Create /api/release/no1-verified-market-network-acceptance-packs after verified network, consent token ledger, agent certification, proof exchange, benchmark consortium, customer value, and policy-pack evidence pass."
        },
        {
          "key": "no1_blueprint_completion_runtime",
          "label": "No. 1 blueprint-completion gates for cockpit, market graph, providers, rights, AI, pilots, and trust publication",
          "status": "pass",
          "severity": "critical",
          "detail": "Blueprint-completion gates are optional outside production.",
          "remediation": "Create /api/release/no1-blueprint-completion-acceptance-packs after cockpit UX, market graph, provider certification, market-data rights, AI evaluation, pilot proof, and trust publication evidence pass."
        },
        {
          "key": "no1_finish_line_runtime",
          "label": "No. 1 finish-line runtime for multi-surface UX, install kits, rights-aware ingestion, eval scorecards, customer proof, and trust binders",
          "status": "pass",
          "severity": "critical",
          "detail": "Finish-line gates are optional outside production.",
          "remediation": "Create /api/release/no1-finish-line-acceptance-packs after the surface suite, provider install kits, rights-aware ingestion, eval scorecards, customer reference packets, and trust-publication binders pass."
        },
        {
          "key": "no1_completion_workbench_runtime",
          "label": "No. 1 completion-workbench gates for buyer surfaces, provider installs, rights registry, AI eval runner, pilot proof, trust exports, and demo assets",
          "status": "pass",
          "severity": "critical",
          "detail": "Completion-workbench gates are optional outside production.",
          "remediation": "Create /api/release/no1-completion-workbench-acceptance-packs after experience surfaces, provider installs, rights registry, AI eval runner, pilot/reference studio, trust export portal, and demo assets pass."
        },
        {
          "key": "no1_launch_proof_runtime",
          "label": "No. 1 launch-proof execution gates for live providers, rights contracts, AI eval publication, customer proof releases, and trust packet exports",
          "status": "pass",
          "severity": "critical",
          "detail": "Launch-proof gates are optional outside production.",
          "remediation": "Create /api/release/no1-launch-proof-acceptance-packs after provider live receipts, rights-contract execution, AI eval publication, customer-proof release, and trust-packet exports pass."
        },
        {
          "key": "no1_mortalytics_subscription_runtime",
          "label": "Mortalytics subscription-sales proof, claims, objection, experimentation, retrieval, and refresh-loop gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Mortalytics subscription gates are optional outside production.",
          "remediation": "Create /api/release/no1-mortalytics-subscription-acceptance-packs after proof packs, approved claims, objection responses, offer/message experiments, persona battlecards, partner kits, retrieval service, and proof refresh loop pass without CRM or BuilderAI boundary drift."
        },
        {
          "key": "no1_operational_proof_runtime",
          "label": "Operational-proof, ecosystem-handoff, provider-secret, rights-registry, AI eval, customer-proof, and trust-bundle gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Operational-proof gates are optional outside production.",
          "remediation": "Create /api/release/no1-operational-proof-acceptance-packs after premium cockpit polish, provider secret vault binding, provider install receipts, rights registry execution, ecosystem handoff contracts, AI eval batch runner, customer reference publication, and trust bundle distribution pass with launch-proof and Mortalytics dependencies accepted."
        },
        {
          "key": "no1_external_readiness_runtime",
          "label": "External-readiness, publishable proof, rights packets, AI scorecards, customer references, trust review, and blueprint-scoreboard gates",
          "status": "pass",
          "severity": "critical",
          "detail": "External-readiness gates are optional outside production.",
          "remediation": "Create /api/release/no1-external-readiness-acceptance-packs after provider-live evidence, rights contracts, AI eval publication bundles, customer reference packets, trust review packets, and blueprint progress scorecards pass with blueprint, launch-proof, Mortalytics, and operational-proof dependencies accepted."
        },
        {
          "key": "no1_completion_certification_runtime",
          "label": "Completion-certification, weighted completion report, provider activation, rights execution, AI benchmark, customer proof approval, and trust-publication signoff gates",
          "status": "pass",
          "severity": "critical",
          "detail": "Completion-certification gates are optional outside production.",
          "remediation": "Create /api/release/no1-completion-certification-acceptance-packs after provider activation, rights execution, AI benchmark, customer proof approval, trust-publication signoff, and weighted completion report evidence pass with blueprint, launch-proof, Mortalytics, operational-proof, and external-readiness dependencies accepted."
        },
        {
          "key": "no1_live_evidence_execution_runtime",
          "label": "Live-evidence execution, provider activation runs, rights-aware ingestion runs, AI benchmark publications, pilot metrics, procurement trust exports, and honest-100 scoreboard",
          "status": "pass",
          "severity": "critical",
          "detail": "Live-evidence execution gates are optional outside production.",
          "remediation": "Create /api/release/no1-live-evidence-execution-acceptance-packs after provider activation runs, rights-aware ingestion runs, AI benchmark publications, pilot-wave metrics, procurement trust exports, and the honest-100 scoreboard pass with Mortalytics, operational-proof, external-readiness, and completion-certification dependencies accepted."
        },
        {
          "key": "no1_publishable_proof_runtime",
          "label": "Publishable-proof bundles, rights receipt packets, AI benchmark packets, customer-reference review, procurement trust packets, and completion report packets",
          "status": "pass",
          "severity": "critical",
          "detail": "Publishable-proof gates are optional outside production.",
          "remediation": "Create /api/release/no1-publishable-proof-acceptance-packs after provider activation bundles, rights receipt bundles, AI benchmark packets, customer-reference review, procurement trust packets, and completion-report packets pass with Mortalytics, operational-proof, external-readiness, completion-certification, and live-evidence dependencies accepted."
        },
        {
          "key": "no1_packet_publication_runtime",
          "label": "Packet-publication enterprise/provider/customer/procurement review bundles and executive gap-burndown packets",
          "status": "pass",
          "severity": "critical",
          "detail": "Packet-publication gates are optional outside production.",
          "remediation": "Create /api/release/no1-packet-publication-acceptance-packs after provider enterprise packets, rights/license packets, AI benchmark publication packets, customer case packets, procurement trust review packets, and executive gap-burndown reports pass with Mortalytics, external-readiness, completion-certification, live-evidence, and publishable-proof dependencies accepted."
        },
        {
          "key": "no1_publication_export_runtime",
          "label": "Publication-export bundles for provider activation, rights receipts, AI benchmarks, customer references, procurement trust, and completion reporting",
          "status": "pass",
          "severity": "critical",
          "detail": "Publication-export gates are optional outside production.",
          "remediation": "Create /api/release/no1-publication-export-acceptance-packs after provider activation export bundles, rights receipt export bundles, AI benchmark export bundles, customer reference export bundles, procurement trust bundles, and completion report export bundles pass with Mortalytics, operational-proof, external-readiness, completion-certification, live-evidence, publishable-proof, and packet-publication dependencies accepted."
        },
        {
          "key": "no1_external_review_execution_runtime",
          "label": "External-review execution sessions for provider, rights, AI, customer, procurement, and completion evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "External-review execution gates are optional outside production.",
          "remediation": "Create /api/release/no1-external-review-execution-acceptance-packs after reviewer sessions, signed approvals, delivery receipts, and upstream publication/export dependencies pass."
        },
        {
          "key": "no1_artifact_integrity_runtime",
          "label": "Package artifact integrity and size-audit evidence",
          "status": "pass",
          "severity": "critical",
          "detail": "Artifact integrity gates are optional outside production.",
          "remediation": "Create /api/release/no1-artifact-integrity-acceptance-packs after size, source, manifest, route, and receipt-export evidence pass."
        },
        {
          "key": "no1_review_artifact_export_runtime",
          "label": "Signed review-artifact exports, procurement Q&A bundles, route/dependency certificates, weighted completion exports, and infrastructure binding readiness",
          "status": "pass",
          "severity": "critical",
          "detail": "Review-artifact export gates are optional outside production.",
          "remediation": "Create /api/release/no1-review-artifact-export-acceptance-packs after signed receipts, procurement Q&A, customer proof, route/dependency, weighted report, and infrastructure binding evidence pass."
        },
        {
          "key": "no1_formal_delivery_runtime",
          "label": "Formal delivery artifacts, signed receipts, procurement Q&A delivery, completion report delivery, route dependency reports, and production binding delivery",
          "status": "pass",
          "severity": "critical",
          "detail": "Formal delivery gates are optional outside production.",
          "remediation": "Create /api/release/no1-formal-delivery-acceptance-packs after formal delivery evidence passes."
        },
        {
          "key": "no1_builderai_checkpoint_runtime",
          "label": "BuilderAI source-checkpoint bridge, runtime-proof bundle, Trust Center sync, Mortalytics Phase 14 boundary, ecosystem feedback contracts, and collision scans",
          "status": "pass",
          "severity": "critical",
          "detail": "BuilderAI checkpoint bridge gates are optional outside production.",
          "remediation": "Create /api/release/no1-builderai-checkpoint-acceptance-packs after checkpoint bridge evidence passes."
        },
        {
          "key": "no1_dependency_environment_runtime",
          "label": "No. 1 dependency environment execution, route-client smoke, Gunicorn gap, signed artifacts, and weighted report exports",
          "status": "pass",
          "severity": "critical",
          "detail": "Dependency-environment gates are optional outside production.",
          "remediation": "Create /api/release/no1-dependency-environment-acceptance-packs after startup, route-client, mutation, Gunicorn gap, signed artifact, and weighted report evidence passes."
        },
        {
          "key": "no1_production_process_runtime",
          "label": "No. 1 production process execution, WSGI/Gunicorn harness, route matrix, artifacts, completion reports, and live infrastructure receipts",
          "status": "pass",
          "severity": "critical",
          "detail": "Production-process gates are optional outside production.",
          "remediation": "Create /api/release/no1-production-process-acceptance-packs after WSGI, Gunicorn harness, route matrix, artifact, report, and infrastructure receipt evidence passes."
        },
        {
          "key": "no1_live_infrastructure_runtime",
          "label": "No. 1 live infrastructure receipts for Postgres/RLS, Redis workers, object/WORM storage, identity, providers, observability, SIEM, and incident routing",
          "status": "pass",
          "severity": "critical",
          "detail": "Live-infrastructure gates are optional outside production.",
          "remediation": "Create /api/release/no1-live-infrastructure-acceptance-packs after Postgres/RLS, Redis worker, object/WORM, identity, provider, observability/SIEM, and incident-routing receipts pass."
        },
        {
          "key": "no1_live_proof_closure_runtime",
          "label": "No. 1 live-proof closure receipts for provider, data-rights, AI, customer, legal/privacy, cockpit, and honest scorecard proof",
          "status": "pass",
          "severity": "critical",
          "detail": "Live-proof closure gates are optional outside production.",
          "remediation": "Create /api/release/no1-live-proof-closure-acceptance-packs after all live-proof closure receipts pass."
        },
        {
          "key": "no1_final_execution_runtime",
          "label": "No. 1 final execution artifacts, expanded route matrix, signed delivery exports, template completion reports, live infrastructure receipts, and external review packet indexes",
          "status": "pass",
          "severity": "critical",
          "detail": "Final-execution gates are optional outside production.",
          "remediation": "Create /api/release/no1-final-execution-acceptance-packs after Gunicorn handoff, expanded route matrix, signed delivery exports, template reports, infrastructure receipts, and external packet indexes pass."
        },
        {
          "key": "no1_runtime_execution_runtime",
          "label": "Dependency startup, Flask route-client execution, Gunicorn readiness, signed delivery artifacts, completion reports, and retrieval trace exports",
          "status": "pass",
          "severity": "critical",
          "detail": "Runtime execution gates are optional outside production.",
          "remediation": "Create /api/release/no1-runtime-execution-acceptance-packs after startup, route-client, Gunicorn, artifact, report, and retrieval trace evidence passes."
        },
        {
          "key": "metrics_endpoint",
          "label": "Prometheus-compatible metrics endpoint",
          "status": "pass",
          "severity": "medium",
          "detail": "/metrics is enabled.",
          "remediation": "Set NEXAMARKET_METRICS_ENABLED=true and scrape /metrics from the private monitoring network."
        },
        {
          "key": "audit_log",
          "label": "Append-only audit sink",
          "status": "pass",
          "severity": "critical",
          "detail": "/app/app/data/audit_events.local.jsonl",
          "remediation": "Ship this audit stream to immutable storage/SIEM in production."
        },
        {
          "key": "demo_reset",
          "label": "Demo reset endpoint control",
          "status": "pass",
          "severity": "critical",
          "detail": "Demo reset enabled.",
          "remediation": "Set NEXAMARKET_ENABLE_DEMO_RESET=false for production."
        }
      ],
      "blockers": [],
      "warnings": [
        {
          "key": "api_auth_gate",
          "label": "Fail-closed API auth gate",
          "status": "warn",
          "severity": "critical",
          "detail": "API routes are open for local development.",
          "remediation": "Use the production-beta Cognito route policy or configure OIDC/API key auth for legacy machine APIs."
        },
        {
          "key": "database",
          "label": "Durable SQL persistence",
          "status": "warn",
          "severity": "critical",
          "detail": "Using atomic JSON state compatibility mode.",
          "remediation": "Set DATABASE_URL and run production migrations before live customer traffic."
        },
        {
          "key": "queue_backend",
          "label": "External queue/cache backend",
          "status": "warn",
          "severity": "high",
          "detail": "Runtime jobs use local compatibility state only.",
          "remediation": "Set REDIS_URL or connect an equivalent queue backend for workers, locks, and retries."
        },
        {
          "key": "object_storage",
          "label": "External object/document storage",
          "status": "warn",
          "severity": "high",
          "detail": "Documents remain references/local metadata only.",
          "remediation": "Set OBJECT_STORE_URL or equivalent document storage for contract packages and exports."
        },
        {
          "key": "secret_manager",
          "label": "Managed secret store",
          "status": "warn",
          "severity": "critical",
          "detail": "Provider credentials use local reference metadata only.",
          "remediation": "Set SECRET_MANAGER_URL or NEXAMARKET_SECRET_MANAGER_URL and store provider/OIDC/webhook secrets outside application state."
        },
        {
          "key": "identity_provider",
          "label": "OIDC identity provider",
          "status": "warn",
          "severity": "critical",
          "detail": "Local simulated identity is active.",
          "remediation": "Use production-beta Cognito hosted UI or set OIDC_ISSUER and OIDC_CLIENT_ID and map roles/tenants before production launch."
        },
        {
          "key": "allowed_origins",
          "label": "Explicit browser origin allow-list",
          "status": "warn",
          "severity": "high",
          "detail": "No browser origin allow-list is configured.",
          "remediation": "Set NEXAMARKET_ALLOWED_ORIGINS to the exact production dashboard origin(s)."
        },
        {
          "key": "trusted_identity_boundary",
          "label": "Trusted identity header boundary",
          "status": "warn",
          "severity": "critical",
          "detail": "No external identity boundary is active.",
          "remediation": "Terminate OIDC/SAML at the edge or enable NEXAMARKET_TRUSTED_IDENTITY_HEADERS only behind a trusted proxy."
        },
        {
          "key": "rate_limit",
          "label": "API rate limiting",
          "status": "warn",
          "severity": "high",
          "detail": "Rate limiting is disabled.",
          "remediation": "Set NEXAMARKET_RATE_LIMIT_ENABLED=true, configure Redis-backed limits, or set NEXAMARKET_EDGE_RATE_LIMITED=true in production."
        }
      ],
      "next_required_actions": []
    },
    "idempotency_ledger": [],
    "webhook_receipts": [],
    "security_events": [],
    "outbox_summary": {
      "total": 16,
      "pending": 16,
      "leased": 0,
      "failed": 0,
      "delivered": 0,
      "dead_lettered": 0,
      "by_status": {
        "pending": 16
      }
    },
    "deployment_evidence": [],
    "rate_limit_counters": [],
    "export_jobs": [],
    "recovery_points": [],
    "restore_validations": [],
    "rate_limit_policy": {
      "enabled": false,
      "edge_rate_limited": false,
      "limit_per_minute": 120,
      "mode": "disabled",
      "scope": "actor_id + tenant_id + method + path + minute_bucket",
      "production_note": "Use shared Redis or edge/API-gateway limits before multiple web workers receive live traffic."
    },
    "export_jobs_summary": {
      "total": 0,
      "by_status": {},
      "completed": 0,
      "failed": 0
    },
    "recovery_plan": {
      "version": "2026-04-20.4",
      "mode": "database_and_object_store_ready",
      "rto_minutes": 60,
      "rpo_minutes": 15,
      "required_controls": [
        "Scheduled database backups with point-in-time recovery enabled.",
        "Object storage versioning for contract packets, exports, and audit evidence.",
        "Quarterly restore drills with signed evidence packets.",
        "Immutable audit stream replicated outside the primary application account.",
        "Runbook approvals before destructive restore or tenant-level replay."
      ],
      "configured": {
        "database_url": false,
        "object_store_url": false,
        "audit_log_file": "/app/app/data/audit_events.local.jsonl"
      }
    },
    "recovery_summary": {
      "total": 0,
      "latest_digest": null
    },
    "migration_manifest": {
      "schema_version": "7.35.0",
      "application_version": "7.35.0",
      "dialect": "postgresql",
      "migrations_dir": "/app/migrations",
      "ready": true,
      "migrations": [
        {
          "file": "0001_core_control_plane.sql",
          "sha256": "7ddeb956afee697e4a0b5d62ea53f7251df73d3d91fe76f421ef27ab5c2f5e72",
          "exists": true
        },
        {
          "file": "0002_operational_runtime_controls.sql",
          "sha256": "04c4ba5136c2da7f5b5ff0d6fdbbf3c253b71c79c8c0b1948d2bca5370899e0d",
          "exists": true
        },
        {
          "file": "0003_browser_ingress_security.sql",
          "sha256": "3079a04c70d4294b00bdfe24ca2a60e9c5dd58ffdf5e79f50cc8c4291ec21536",
          "exists": true
        },
        {
          "file": "0004_tenant_export_recovery_controls.sql",
          "sha256": "5ecbda9d8097e33d77ff6a5459040e73c90ca27c60c2fedec227aad2b38cbf16",
          "exists": true
        },
        {
          "file": "0005_repository_quality_retention_controls.sql",
          "sha256": "8c574e6a0faf44bfdd11333d8f7417e135d3fcd4ad9650e41c71f7f4cb64aa8c",
          "exists": true
        },
        {
          "file": "0006_policy_route_governance_controls.sql",
          "sha256": "51409920e9a532658eecfe7640140a44eb0358e95e6ba7dd3e426ca7f5b2ea7e",
          "exists": true
        },
        {
          "file": "0007_access_contract_incident_controls.sql",
          "sha256": "398766e7f390b2eb9bb75031d4ca6eb0639cffe1ab1bcfdafb1cbc1f3203ef0a",
          "exists": true
        },
        {
          "file": "0008_feature_dlp_deployment_scheduler_controls.sql",
          "sha256": "5c905ce56877e586ff5b5470a894c77e1b6dcf5d379704aac56f98737839858b",
          "exists": true
        },
        {
          "file": "0009_service_artifact_webhook_synthetic_controls.sql",
          "sha256": "404491c27f66d7c50ff40b733fa21d55f851b322ffe50449f40c5ff5afb72b5c",
          "exists": true
        },
        {
          "file": "0010_api_compliance_residency_resilience_supply_chain_controls.sql",
          "sha256": "fe587bdae6e607531253c9cafe4b6a27ba5fcc5e0706214275763f2c8793f4a3",
          "exists": true
        },
        {
          "file": "0011_consent_billing_resilience_controls.sql",
          "sha256": "f843ad4652ddb9fa31f3195624823127c9248e41019e6c56d3797e2ffe0b4e80",
          "exists": true
        },
        {
          "file": "0012_kms_vulnerability_configuration_evidence_controls.sql",
          "sha256": "394f068938ea7832252fa3669d462172c58d27b326180180d690995cc56d5826",
          "exists": true
        },
        {
          "file": "0013_telemetry_alert_lineage_capacity_controls.sql",
          "sha256": "07a1044272c357346161208ead37683d0ed4826011564a19f4cf6cdf2472cc9e",
          "exists": true
        },
        {
          "file": "0014_database_cutover_query_archive_queue_controls.sql",
          "sha256": "ccc776abbbd712f908ae95f59b7ed84bea0e106d12351d3d9eb5528a673e8393",
          "exists": true
        },
        {
          "file": "0015_security_assurance_runbook_sla_controls.sql",
          "sha256": "e713359e66d3a85517cf73dad9a3d434bf9c580c9b24298b7d79a116773f0aef",
          "exists": true
        },
        {
          "file": "0016_zero_trust_search_queue_migration_controls.sql",
          "sha256": "3257b5b7f5db9b369da65b0e0689e66fe57c83e9842a898c24329a7b9fd273c8",
          "exists": true
        },
        {
          "file": "0017_privacy_entitlement_network_release_controls.sql",
          "sha256": "af2875ce2c141db7d6fd3fd622863846e1ced39d591a9e63b5665d4d7871baeb",
          "exists": true
        },
        {
          "file": "0018_identity_tenant_evidence_oauth_controls.sql",
          "sha256": "35a0b7e408aaffa365431dde8143721224eb357d0b2c193fa25814a899a11c17",
          "exists": true
        },
        {
          "file": "0019_client_privacy_support_environment_controls.sql",
          "sha256": "50a1c68ff0af96e7bdcc282092d7de6843a87d630147d40e88af646b5ce71f8f",
          "exists": true
        },
        {
          "file": "0020_database_directory_provider_custody_error_comms_controls.sql",
          "sha256": "085e51e1f1e81ab190d8e4dcf407fcd1b154c211684ffa7bf81740a03a47c57d",
          "exists": true
        },
        {
          "file": "0021_migration_provider_notification_audit_controls.sql",
          "sha256": "fe3157d9f1abe1308123d2e4977f573449cd38c68e9aab786de2c86d058d5376",
          "exists": true
        },
        {
          "file": "0022_operational_governance_launch_controls.sql",
          "sha256": "da8884be21f11fb406f47cada2e0af7fdcd8b913babc5c49f7ba1c0987f3a86b",
          "exists": true
        },
        {
          "file": "0023_domain_warehouse_dr_finops_exception_controls.sql",
          "sha256": "671d28f2c84175ab91b9cd6d36dc6bc6b09ae2c3fee8445afc18798782a77cc3",
          "exists": true
        },
        {
          "file": "0024_launch_cutover_runtime_parity_controls.sql",
          "sha256": "5c861bd690306f9ec4865551ab755a7784b46703e278b8f5e889774fa20a3290",
          "exists": true
        },
        {
          "file": "0025_api_sso_abuse_traffic_rollback_controls.sql",
          "sha256": "82d07556478f85228b83ab3abf6af7a157817ab74c04afc4ac33911112c6c28f",
          "exists": true
        },
        {
          "file": "0026_data_contract_egress_secret_payment_oncall_postmortem_controls.sql",
          "sha256": "733427ad898abf62a1b9e034fd5d2aac7af804aea1d6b2fdcae0281bb7d71cb4",
          "exists": true
        },
        {
          "file": "0027_backfill_deliverability_contract_health_knowledge_controls.sql",
          "sha256": "078d779c428d9a62281ea03b57dc4c257e13cbb6e867a013ba139a86268d633d",
          "exists": true
        },
        {
          "file": "0028_infrastructure_smoke_hold_revenue_support_controls.sql",
          "sha256": "5f196255edbc14ce0c5fdcc5abc78965c660166cef4c94ce85be3498571e7c9c",
          "exists": true
        },
        {
          "file": "0029_integrity_provider_tenant_workflow_acceptance_controls.sql",
          "sha256": "eeb8f8e669c36a88532f4ec2cab8418c96d8965c77244899be6fdb10b2961c6e",
          "exists": true
        },
        {
          "file": "0030_audit_retention_entitlement_renewal_runtime_controls.sql",
          "sha256": "9feefe215f28bc279ee7d532cb45af4cc9dc4d8d0ad135d6142d7fc2dfc55ee7",
          "exists": true
        },
        {
          "file": "0031_permission_export_erasure_incident_workflow_controls.sql",
          "sha256": "7ff9c1f254499e2c78a88964b27cefc7eeb8e1c8d4a983090051efdb6a1ac976",
          "exists": true
        },
        {
          "file": "0032_production_binding_repository_worker_provider_controls.sql",
          "sha256": "bd4630aa9196dba00f1e7fb77d9636a6cd6662c2ce47496a8f5a0971ec9267ca",
          "exists": true
        },
        {
          "file": "0033_repository_auth_worker_provider_dataplane_controls.sql",
          "sha256": "7e79418c5886d65c5e3cacc3c4721c5a14af2b0f42c91bcf9414b120eed63943",
          "exists": true
        },
        {
          "file": "0034_transaction_worker_adapter_ui_cutover_controls.sql",
          "sha256": "7d0e26974d28975956f45173c834978f8cdd2641a989c63c1382c67ca680a873",
          "exists": true
        },
        {
          "file": "0035_launch_binding_repository_auth_worker_webhook_ui_controls.sql",
          "sha256": "ec16dec273f032a2b5328e54ec1acb44e11d3c5e456e32d76842201afcf44c80",
          "exists": true
        },
        {
          "file": "0036_dependency_rls_worker_webhook_launch_controls.sql",
          "sha256": "bbb5087733e8b880a1500500429d684737c66b4d3eadaca3ae7e636b3617b343",
          "exists": true
        },
        {
          "file": "0037_runtime_launch_cutover_execution_controls.sql",
          "sha256": "bea4aeefde074cfc04f6190be3e54d40cc7c6e6f7d47fbaa671e8fb05f785db4",
          "exists": true
        },
        {
          "file": "0038_infrastructure_execution_runtime_binding_controls.sql",
          "sha256": "30aca6a3f6c0c98fbfffff905cc36c555304c3340363bb0104eee50b86c72f6f",
          "exists": true
        },
        {
          "file": "0039_live_runtime_connection_identity_worker_provider_evidence_controls.sql",
          "sha256": "b88252a749cc4c90ee3bed78d8e9a7519be6739c14dbaa20d076acda235939d6",
          "exists": true
        },
        {
          "file": "0040_runtime_operations_tenant_repository_worker_provider_slo_controls.sql",
          "sha256": "c7b83f7a123e69fa9ebeff004a67346986dba02def31d8549c2902f87ce1c192",
          "exists": true
        },
        {
          "file": "0041_customer_launch_cache_queue_provider_support_controls.sql",
          "sha256": "815f4d3f2c7dbcfed4a3e1c6ea6c5561c2257a7e25c5f76846ae5c1ab9f89cee",
          "exists": true
        },
        {
          "file": "0042_go_live_tenant_edge_billing_compliance_hypercare_controls.sql",
          "sha256": "ba395ba2cc27aca3edcd2dfb6ccb13891f1770f59b4d02071a49fa38211ed975",
          "exists": true
        },
        {
          "file": "0043_no1_market_program_blueprint_controls.sql",
          "sha256": "2e58f1e76c7f2f04b0574c6c16bf8807ae53af92fae1b3ac02c6672a4cdfeb46",
          "exists": true
        },
        {
          "file": "0044_no1_execution_readiness_controls.sql",
          "sha256": "6aa1318e2adc01d17066b905459091075048f6a8864b1662a7cc64bb561558af",
          "exists": true
        },
        {
          "file": "0045_no1_leadership_proof_controls.sql",
          "sha256": "cb5d5590e8b496d8016787ed6e79087b7447b383afb5b625915f70111466aef0",
          "exists": true
        },
        {
          "file": "0046_no1_productization_runtime_controls.sql",
          "sha256": "85cd3a134f569a586cd4e18cf30a43168d531703be6b926e68d1f476be47f96c",
          "exists": true
        },
        {
          "file": "0047_no1_operating_system_runtime_controls.sql",
          "sha256": "60bcdb3459d1aadc840b671aa9e52c5ba70b4e9836b852454c72dbc967e3b135",
          "exists": true
        },
        {
          "file": "0048_no1_future_simulation_market_twin_controls.sql",
          "sha256": "fb782fbdaad42379014b8ac98bbf9861864553922f31e1ef4632803842785eba",
          "exists": true
        },
        {
          "file": "0049_no1_commercialization_market_launch_controls.sql",
          "sha256": "ea206f98b39b6e025826f66d8f7fb382ab07e3b106e00a7cfe5480a963bd00bb",
          "exists": true
        },
        {
          "file": "0050_no1_growth_scale_enterprise_value_controls.sql",
          "sha256": "6b0e943f10560d08d55eff7cdc047e151e1fc23fd37973d7edbe6ccd19ffc671",
          "exists": true
        },
        {
          "file": "0051_no1_enterprise_scale_expansion_controls.sql",
          "sha256": "d26e2503b12dc8443fd8378260133fea907b71d64abe3fda37aec08eb80e3b3d",
          "exists": true
        },
        {
          "file": "0052_no1_global_leadership_autonomous_governance_controls.sql",
          "sha256": "aa628bff425ea45dc3f8a90e536e16bac0134a52ad5b9290859cb7a66e0148c6",
          "exists": true
        },
        {
          "file": "0053_no1_network_effects_partner_trust_moat_controls.sql",
          "sha256": "409a0b22c2376aa4185338c43c75bdae80952a9a8b21f16604a5cc3cd3fe4c86",
          "exists": true
        },
        {
          "file": "0054_no1_global_scale_localization_sovereign_controls.sql",
          "sha256": "7d13257f38817cd5871e7a24e925fb40e4020c188cda99531cd8defa0f18ad9a",
          "exists": true
        },
        {
          "file": "0055_no1_autonomous_market_mesh_proof_flywheel_controls.sql",
          "sha256": "9ad461cf68c87da8363f930a9d09f3cf6f73b7f8a4771aad5518a4aabb1ec499",
          "exists": true
        },
        {
          "file": "0056_no1_verified_market_network_policy_controls.sql",
          "sha256": "bd02b7ef1f8338a79454a9bc09128bbb548d05d0a17396c79d991199bcc865c5",
          "exists": true
        },
        {
          "file": "0057_no1_blueprint_completion_runtime_controls.sql",
          "sha256": "3faa439428ec603034ba3af0fe5f9cb6d7c31c4a2338e36c836504bcaf6b5270",
          "exists": true
        },
        {
          "file": "0058_no1_completion_workbench_surface_and_proof_controls.sql",
          "sha256": "b6c12788340b447cdbbc94024af7c99cb076a8d5a376da13df50b84c511bf2d5",
          "exists": true
        },
        {
          "file": "0059_no1_finish_line_runtime_and_surface_suite_controls.sql",
          "sha256": "2fa8e4fae9adb5a9cad04018dcc48973d2fba987cdd35ac57bc18838283cb0be",
          "exists": true
        },
        {
          "file": "0060_no1_launch_proof_execution_controls.sql",
          "sha256": "05d31e5d7c445ccbeac1d5e8553d5369cb19fe123eef790d8b79ca4d4004ceb4",
          "exists": true
        },
        {
          "file": "0061_no1_mortalytics_subscription_sales_controls.sql",
          "sha256": "59d8f304dd9f6b2930ba162fbfc49ac132644f33af8739204642bb53b0387a9d",
          "exists": true
        },
        {
          "file": "0062_no1_operational_proof_runtime_and_ecosystem_handoffs.sql",
          "sha256": "ad9d46904a6ac209fb55625412f34a1be587d88f82cb04131c4860ea958e831e",
          "exists": true
        },
        {
          "file": "0063_no1_external_readiness_runtime_and_scoreboard.sql",
          "sha256": "76283800b95e411c2bb3c88bcf9c1f25dad6dc54506ff237f579a6aa1972e85f",
          "exists": true
        },
        {
          "file": "0064_no1_completion_certification_runtime_and_weighted_report.sql",
          "sha256": "2a97d03e719ea5007b36d7d93eba50a218c7a5171ae74145e12d9ab5e11bcfe2",
          "exists": true
        },
        {
          "file": "0065_no1_live_evidence_execution_runtime_and_honest100.sql",
          "sha256": "df4df66d01629782d54e40b0a3c865b3e16a317016d1b2c681d5ec8d10b033db",
          "exists": true
        },
        {
          "file": "0066_no1_publishable_proof_runtime_and_packets.sql",
          "sha256": "51fb7d81fdd8e872ed69c3dab6032d1ea527791eb2bdc5d76cdd43d9c25999ad",
          "exists": true
        },
        {
          "file": "0067_no1_packet_publication_runtime_and_review_packets.sql",
          "sha256": "3d2f375cbdfa0daf6ddcef3204d2e49a4b37ba3eabe0ebd4f15f3614e2ba1bac",
          "exists": true
        },
        {
          "file": "0068_no1_publication_export_runtime_and_delivery_bundles.sql",
          "sha256": "7e737022f5f74734d22268d28323cb47c29531567a7cede26ab7eed161395e58",
          "exists": true
        },
        {
          "file": "0069_no1_external_review_execution_runtime_and_signed_reviews.sql",
          "sha256": "627d67e1c8f8c82be00ada0d2142a74146fce09f439d5d3dbfff122852d9710f",
          "exists": true
        },
        {
          "file": "0070_no1_artifact_integrity_size_audit_controls.sql",
          "sha256": "16cc91cf3495218324c063efc4f2cc64d039ff228a6de6378bbb4d47d8ca6766",
          "exists": true
        },
        {
          "file": "0071_no1_review_artifact_export_controls.sql",
          "sha256": "74fd903a775d272c7a9c1f76df8590eed16cfb276bf8157b4a293a3d66fd3037",
          "exists": true
        },
        {
          "file": "0072_no1_formal_delivery_runtime_and_export_packets.sql",
          "sha256": "7280acc6de6daff233c25d6e7ff110d886b7bf3598fb7777f2d43818292c6165",
          "exists": true
        },
        {
          "file": "0073_no1_builderai_checkpoint_bridge_controls.sql",
          "sha256": "5c01e138434d4efb32b2d8274a965c5339306dfcb67f5be51ac82be605d54d69",
          "exists": true
        },
        {
          "file": "0074_no1_runtime_execution_dependency_and_artifact_controls.sql",
          "sha256": "1c3ff3ec03c652be36ec16379185913840e6b244786aa022fbdc2a43dd034ce3",
          "exists": true
        },
        {
          "file": "0075_no1_dependency_environment_execution_controls.sql",
          "sha256": "a13512d3a30bc154512681e6237ec514bf7e380d681f88cf175a9b31e3f01ff0",
          "exists": true
        },
        {
          "file": "0076_no1_production_process_execution_controls.sql",
          "sha256": "24c44255dbe9768b1f456eafcad4baed2d9edcec969369b362b0bd30f1c66f06",
          "exists": true
        },
        {
          "file": "0077_no1_final_execution_artifact_controls.sql",
          "sha256": "ef217289abac81331aec701b7de7b5a2adfe124ba59e74326e7c9d6cc06a4ea4",
          "exists": true
        },
        {
          "file": "0078_no1_live_infrastructure_execution_receipts.sql",
          "sha256": "7aa0df9aaa71cf89bd65c18bf2fdbf51b11e4d2b6b08d4243f63455910d2aea4",
          "exists": true
        },
        {
          "file": "0079_no1_live_proof_closure_controls.sql",
          "sha256": "cb7a3f6c19df07f901ae336de90763da0686a7541c8c14656cfb82e1fe93371d",
          "exists": true
        },
        {
          "file": "0080_no1_receipt_file_generation_controls.sql",
          "sha256": "1cce20e924a2f130b2c7dbeb699220b3e7fa3202efcdd4d1ee3e43dfaba20e2a",
          "exists": true
        },
        {
          "file": "0081_no1_external_execution_artifact_controls.sql",
          "sha256": "e2d9b5275ee90a79b94b90c07337676c23cf8b0405946f9f917df4abf24f8287",
          "exists": true
        },
        {
          "file": "0082_no1_external_execution_validation_controls.sql",
          "sha256": "7bdb0faf031df1281c85a2582927aae89f419b8ad9488eed8143e46b969a7493",
          "exists": true
        },
        {
          "description": "No. 1 formal binder/report controls",
          "file": "0083_no1_formal_binder_report_controls.sql",
          "id": "0083",
          "sha256": "2af12e6b7160d5d745a023a5f24299be13b4d9670e81cf119771456e65f3b6c1",
          "exists": true
        },
        {
          "description": "No. 1 report/binder execution controls",
          "file": "0084_no1_report_binder_execution_controls.sql",
          "id": "0084",
          "sha256": "e5e5eec5a1881cf64dc3f708e2d2e381c783156984d1c493603800005af75d47",
          "exists": true
        },
        {
          "description": "No. 1 document/binder delivery controls",
          "file": "0085_no1_document_binder_delivery_controls.sql",
          "id": "0085",
          "sha256": "021bb736f212fa5262dc50b66e4b558e144eed8ca0a52d71d85ec3073eaabbe6",
          "exists": true
        },
        {
          "file": "0086_no1_external_evidence_attachment_controls.sql",
          "sha256": "b3d37645ba347bb8e21c689a56eb60e243edde7896568babfdcbf48a47d6337d",
          "exists": true
        },
        {
          "file": "0087_no1_real_receipt_intake_controls.sql",
          "sha256": "dec849dd033c1c05cec6c4243991dcdd13015673a192dfba3f01709e6004fe05",
          "exists": true
        },
        {
          "file": "0088_no1_real_receipt_verification_controls.sql",
          "sha256": "2774384b75bc1f17f63bd609e7f502ca18eb4ee5dc4cba210783f965e8c9e178",
          "exists": true
        },
        {
          "file": "0089_no1_receipt_verification_execution_controls.sql",
          "sha256": "7338f9c85ad402da35ffb3662a6e9fced1391ccceb57fd6575461343a24e17fa",
          "exists": true
        },
        {
          "file": "0090_no1_http_receipt_verification_controls.sql",
          "sha256": "d775f70bf11243b4b14b96720d130808ee57a480aed1e10fbc0963a64e5b183e",
          "exists": true
        },
        {
          "file": "0091_no1_post_mutation_validation_controls.sql",
          "sha256": "1aa1dad89185f53dca59f81117de3d8e2b728d05b8498bb6d709375ae000f783",
          "exists": true
        },
        {
          "file": "0092_no1_broader_mutation_budget_controls.sql",
          "sha256": "afb580bc6addbd713f1c4e83921fd2527930c57ad395d4c95d6635d1f359e6b5",
          "exists": true
        },
        {
          "file": "0093_no1_production_http_execution_controls.sql",
          "sha256": "336ed5a3fc7a92bae37d2bfb5937ff7332c23294c8acb9f5a1018652bab759bb",
          "exists": true
        },
        {
          "file": "0094_no1_full_http_execution_controls.sql",
          "sha256": "e582c4faa39630f7a38c9fbeba4c8e9724f0e303cbd90b11b71e89b9ba89b96b",
          "exists": true
        },
        {
          "file": "0095_no1_http_sla_closure_controls.sql",
          "sha256": "56e82c6aacae592eb8bb77007fbf80e5128fba353651fcb5bd5446973edb3035",
          "exists": true
        },
        {
          "file": "0096_no1_dependency_http_validation_controls.sql",
          "sha256": "38c8e7776d520f1a8ec520416d6bbfe17013094330c4930dcd6ac44ac3343269",
          "exists": true
        },
        {
          "description": "No. 1 broader production HTTP closure controls",
          "file": "0097_no1_broader_production_http_closure_controls.sql",
          "sha256": "f0af05ffacb2734c1f6f2c1e282ea2347e161e7056d37153bbfa4101e27b74b8",
          "exists": true
        },
        {
          "file": "0098_no1_dependency_closure_execution_controls.sql",
          "sha256": "cafa22f563f6634debdffcb8ce2aa8b82f47e6b5f1322549d83171312d978ef4",
          "exists": true
        },
        {
          "description": "No. 1 canonical lineage continuity controls",
          "file": "0099_no1_canonical_lineage_continuity_controls.sql",
          "sha256": "b6d2c39226eca8541ece6eb85c458001a18ced9b238f81c12ef8d99f805f91e4",
          "exists": true
        },
        {
          "description": "No. 1 evidence merge and upgrade controls",
          "file": "0100_no1_evidence_merge_upgrade_controls.sql",
          "sha256": "6960ca38ca370f5422426aae0f601274df657816aa5190b2a2f7639513d385ec",
          "exists": true
        },
        {
          "description": "No. 1 v6.86 artifact consolidation controls",
          "file": "0101_no1_v86_artifact_consolidation_controls.sql",
          "sha256": "02a8cee6ab157f0de769de515d278e7d4719e4957ec36791d6950a07c8724dfa",
          "exists": true
        },
        {
          "description": "No. 1 v6.87 artifact merge controls",
          "file": "0102_no1_v87_artifact_merge_controls.sql",
          "sha256": "666b49d3546c24f0f12d36684dba6275741decab36a7defae73a01d1139a2eea",
          "exists": true
        },
        {
          "description": "No. 1 v6.88 continuity upgrade controls",
          "file": "0103_no1_v88_continuity_upgrade_controls.sql",
          "sha256": "dcc176bdc746d29dda4b1bd306581efb7db34cceb8330590f4cb966b7bcc2ffc",
          "exists": true
        },
        {
          "description": "No. 1 v6.90 source/evidence reconciliation and v89 artifact-merge restoration controls",
          "file": "0104_no1_v90_source_evidence_reconciliation_controls.sql",
          "sha256": "dd8ca6e94c0fadca149fe0af8ddff210eb27be2384cc6cc6da15eb5ddfd84513",
          "exists": true
        },
        {
          "description": "No. 1 v6.91 continuity-upgrade controls",
          "file": "0105_no1_v91_continuity_upgrade_controls.sql",
          "sha256": "5e8989d912dc36e98ff1517f4bfba9023444ba69a4d6ec695576a63436716e44",
          "exists": true
        },
        {
          "description": "No. 1 v6.92 evidence continuity controls",
          "file": "0106_no1_v92_evidence_continuity_controls.sql",
          "sha256": "ea00f963090f0f64f21581277902d500a8a5bd5ead339d60b8653be982bea74f",
          "exists": true
        },
        {
          "file": "0107_no1_v93_evidence_import_controls.sql",
          "sha256": "1c4aafddc5be21a79591b14c16b55f6b5b2ff63e6ff0971ad19527ca2a0eb426",
          "exists": true
        },
        {
          "file": "0108_no1_v95_full_source_reconciliation_controls.sql",
          "sha256": "775fd3c9c212cf059587a009f85f63039a382f71cda925f7cb9cb5008ab1dfd1",
          "exists": true
        },
        {
          "description": "No. 1 v6.97 staging HTTP closure, receipt SLA execution, and claim-freeze continuity controls",
          "file": "0109_no1_v97_staging_http_closure_controls.sql",
          "sha256": "9e08ef5516c424e482ea2573ad2602bce18d01f3d85590a3a2f5ea176d3be150",
          "exists": true
        },
        {
          "description": "No. 1 v6.97 execution closure controls",
          "file": "0110_no1_v97_execution_closure_controls.sql",
          "sha256": "cb880a2de3194a646c8cb7e91af2467fe03bb335ae6201b93eb27bef23370de2",
          "exists": true
        },
        {
          "description": "No. 1 v6.96 continuity receipt dispatch controls",
          "file": "0111_no1_v96_continuity_receipt_dispatch_controls.sql",
          "sha256": "3434d800535241ac054c5bae31361012cada6d8f748e9ee4f83c2cb50ac3f175",
          "exists": true
        },
        {
          "description": "No. 1 v6.98 verified live-receipt closure and claim-freeze controls",
          "file": "0112_no1_v98_verified_receipt_closure_controls.sql",
          "sha256": "93a08be844c7d8c28b9e07fb4d27106d21855e8e150feaae48fd70290343d85c",
          "exists": true
        },
        {
          "file": "0113_no1_v99_claim_readiness_gate_controls.sql",
          "sha256": "9585159805960f8778df6e21bf278b53938d7e4eff45222171e0fb764d2898f2",
          "exists": true
        },
        {
          "description": "No. 1 v7 claim eligibility, verified receipt closure, and publication guard controls",
          "file": "0114_no1_v7_claim_eligibility_controls.sql",
          "sha256": "e767cb8f3e599253c23d5e1cb3626427788687ccbeeed122be30d7a26b872ddb",
          "exists": true
        },
        {
          "description": "No. 1 v7 claim review, verified receipt authenticity, publication lock, and receipt SLA closure controls",
          "file": "0115_no1_v7_claim_review_controls.sql",
          "sha256": "bb887cc9ff2bb8eb3d9b75203466e05ac142b50bf96557ba4884ca10c33845bf",
          "exists": true
        },
        {
          "description": "No. 1 v7 receipt claim-review eligibility and verified receipt controls",
          "file": "0116_no1_v7_receipt_claim_review_controls.sql",
          "sha256": "4fc89111fcd1b4253bfac2a48847403e6471d329ab7b74a746ef2f1bb4edc155",
          "exists": true
        },
        {
          "description": "No. 1 v7.1 receipt attachment workbench, weighted evidence delta, and claim-freeze continuity controls",
          "file": "0117_no1_v71_receipt_attachment_workbench_controls.sql",
          "sha256": "c228e41978b92ca244d2aae2314da8d00a945d3a6ab60d229947a6a06e386b8f",
          "exists": true
        },
        {
          "file": "0118_no1_v72_receipt_authenticity_controls.sql",
          "sha256": "603037ef6ef0bfc6a5600ec18d1dcc2d1b960a2bb45d4c5b855565b730bdb668",
          "exists": true
        },
        {
          "description": "No. 1 v7.2 verified receipt orchestration, issuer trust, SLA dispatch, failure routing, and claim-release lockdown controls",
          "file": "0119_no1_v72_verified_receipt_orchestration_controls.sql",
          "sha256": "ffb553cf02430d0084aa913827f94c09cc90037a56b5c09952235388790ef4b5",
          "exists": true
        },
        {
          "description": "No. 1 v7.3 verified receipt payload intake, issuer/signature/freshness verification, SLA burndown, and claim-freeze publication lock controls",
          "file": "0120_no1_v73_verified_receipt_payload_controls.sql",
          "sha256": "43d2e396ef16b0f5539ca976fdc62f2d2ac9318533a9d0e199166e05f699a8c2",
          "exists": true
        },
        {
          "description": "No. 1 v7.4 receipt verification depth, issuer trust, signature/freshness/revocation, source digest, claim-scope, conflict routing, weighted refresh, and claim-freeze board review controls",
          "file": "0121_no1_v74_receipt_verification_depth_controls.sql",
          "sha256": "0b065fd0732bf6ded8633d9a82902de2cb4948bede4a668426131f81f5f970d1",
          "exists": true
        },
        {
          "file": "0122_no1_v75_receipt_authority_vault_controls.sql",
          "sha256": "a4064421f7c8b5382886dce0ca7201b1fafdb8e3b52ad9b0887d04db6f6fe6d6",
          "exists": true
        },
        {
          "description": "No. 1 v7.6 receipt payload fixture vault, issuer authority, signature/freshness/revocation, source digest, reviewer attestation, claim-scope, conflict routing, and weighted payload delta controls",
          "file": "0123_no1_v76_receipt_payload_verification_controls.sql",
          "sha256": "51c9f1861c8287ac0bed618ba0e002f75d89b25c16e7d5d569f3b3f7315953ba",
          "exists": true
        },
        {
          "description": "No. 1 v7.6 receipt chain-of-custody, issuer attestation, signature/revocation/freshness, source hash consistency, SLA closure, and claim-unlock precheck controls",
          "file": "0124_no1_v76_receipt_chain_of_custody_controls.sql",
          "sha256": "eb5546c28b7a2f5c3aa8e03e14bf3499eba5bd214817e15dcbb21f071f83c1e1",
          "exists": true
        },
        {
          "description": "No. 1 v7.7 trusted receipt evidence controls for trusted example receipts, claim freeze, and non-live receipt separation",
          "file": "0125_no1_v77_trusted_receipt_evidence_controls.sql",
          "sha256": "2127d63a33e98f234ff17be10b3c45912dec519dc44f5aacd40e753448d23208",
          "exists": true
        },
        {
          "description": "No. 1 v7.7 trusted receipt examples controls for external receipt sample payloads, issuer trust, source hash, reviewer attestation, and claim-freeze continuity",
          "file": "0126_no1_v77_trusted_receipt_examples_controls.sql",
          "sha256": "b4964dde5f016d993490a23bb339f1d3e3bb05d52dc176d9d6211002422002b1",
          "exists": true
        },
        {
          "description": "No. 1 v7.7 trusted external receipt execution, issuer trust, signature/freshness/revocation execution, source hash crosscheck, reviewer conflict routing, SLA closure, claim unlock guard, and weighted verified receipt delta controls",
          "file": "0127_no1_v77_trusted_receipt_execution_controls.sql",
          "sha256": "503b8139ce878e34b2540c615ea68f3ca9ee23d10e30bfa40c2c584487404454",
          "exists": true
        },
        {
          "description": "No. 1 v7.8 live receipt attestation, issuer authority chain, signature/freshness/revocation, source digest, conflict routing, SLA burndown, weighted coverage, and claim-freeze continuity controls",
          "file": "0128_no1_v78_live_receipt_attestation_controls.sql",
          "sha256": "e2ae69874274a462c2f910a23a979b9b152d504d5a500dd7e03eb265b852a506",
          "exists": true
        },
        {
          "description": "No. 1 v7.9 receipt authority replay, external issuer attestation, signature/freshness/revocation replay, source digest lineage, SLA escalation, weighted authority delta, and claim-unlock guardrail controls",
          "file": "0129_no1_v79_receipt_authority_replay_controls.sql",
          "sha256": "9760bbdc8436a146a0599e1bbed8fd39383b8ccef84ee859a416b3b38a8dc0a9",
          "exists": true
        },
        {
          "description": "No. 1 v7.10 v7.9 artifact merge, checksum continuity, route/HTTP evidence import, validation/test import, receipt example import, and claim-freeze continuity controls",
          "file": "0130_no1_v710_v79_artifact_merge_controls.sql",
          "sha256": "4c2aef298f954c4e7f6aab59c291fd4858a1b7eb92b0c6d6cdca092e62e97171",
          "exists": true
        },
        {
          "description": "No. 1 v7.11 v7.10 continuity import, package pair integrity, download-safe evidence references, receipt SLA closure board, re-verification failure routing, and claim-freeze continuity controls",
          "file": "0131_no1_v711_v710_continuity_controls.sql",
          "sha256": "b27302b1b4edd9479feebb3e1cc784e1b47d13aa696c23f1337bf2994774f8fd",
          "exists": true
        },
        {
          "description": "No. 1 v7.12 live receipt claim-review, real receipt attachment intake, issuer/signature/freshness verification, SLA closure, weighted completion review, and publication claim-freeze guard controls",
          "file": "0132_no1_v712_live_receipt_claim_review_controls.sql",
          "sha256": "fe8eecfd7ef302faad2b8adc1bea8993a51644c2ef28bb639e6018a0f1b74193",
          "exists": true
        },
        {
          "description": "No. 1 v7.13 real receipt file attachment, issuer authority, signature/freshness/revocation, source digest, reviewer identity, SLA claim-unlock, weighted receipt delta, and publication claim-freeze controls",
          "file": "0133_no1_v713_real_receipt_file_verification_controls.sql",
          "sha256": "db3a2da4042e140cc51db224e848251a0f8cfe2dc190f35e56e086dcaf556dee",
          "exists": true
        },
        {
          "description": "No. 1 v7.14 real receipt attachment execution, issuer authority, signature/freshness/revocation, source digest, reviewer claim scope, SLA execution, weighted live receipt refresh, and publication claim-freeze controls",
          "file": "0134_no1_v714_real_receipt_attachment_execution_controls.sql",
          "sha256": "1c1c657536c0b1e68b350276a8a8c1eec54ac69383e05a18403875bda77639b8",
          "exists": true
        },
        {
          "description": "No. 1 v7.15 v7.14 artifact single-bundle merge, package-pair integrity, validation/route/HTTP evidence import, receipt schema/template import, weighted evidence import, and claim-freeze continuity controls",
          "file": "0135_no1_v715_v714_artifact_single_bundle_controls.sql",
          "sha256": "c54cde53b3f455f40cf30c1eb8a91b78cdac6597fc59f3ed6ac0ee68f9788117",
          "exists": true
        },
        {
          "description": "No. 1 v7.16 v7.15 continuity import, download-safe artifact reference guard, receipt-owner SLA execution, live receipt intake guard, weighted claim-freeze export, and acceptance pack controls",
          "file": "0136_no1_v716_v715_continuity_controls.sql",
          "sha256": "3de487beaefe23f620bcb8b2e00b2c1d00785aa33cc1dc3f403b24a269ba893b",
          "exists": true
        },
        {
          "description": "No. 1 v7.17 live receipt intake execution, v7.16 continuity import, download-safe artifact references, issuer/signature/freshness reverification, source/reviewer claim-scope precheck, SLA escalation, and claim-freeze publication lock controls",
          "file": "0137_no1_v717_live_receipt_intake_execution_controls.sql",
          "sha256": "ee8de6c5709ff600075a7ed325979f646d7bcbca0f38af95b3a84f2a51bbcbe2",
          "exists": true
        },
        {
          "description": "No. 1 v7.18 live receipt verification workbench, v7.17 continuity import, download-safe artifact references, issuer/freshness/revocation guard, source/reviewer claim-scope gate, SLA resolution, and claim-freeze publication lock controls",
          "file": "0138_no1_v718_live_receipt_verification_workbench_controls.sql",
          "sha256": "0c2b27615673256952b310955e9a4927981b0739595cec49f2f07bd2920008c0",
          "exists": true
        },
        {
          "description": "No. 1 v7.19 live receipt closure, v7.18 continuity import, cross-family HTTP closure, receipt verification queues, issuer/source rechecks, SLA escalation, weighted completion refresh, and claim-freeze publication guard controls",
          "file": "0139_no1_v719_live_receipt_closure_controls.sql",
          "sha256": "6e0791ff732f8ab2785d63f246dc9a94f848b56e31b532fdf270470025105874",
          "exists": true
        },
        {
          "description": "No. 1 v7.20 live proof claim review, v7.19 continuity import, cross-family GET/POST closure, live receipt queues, issuer/source re-verification, SLA burndown, weighted completion refresh, and claim-release board lock controls",
          "file": "0140_no1_v720_live_proof_claim_review_controls.sql",
          "sha256": "af7ac850c246badbed7d4aede14622e2bbf5d1ee67867c69ae698c205976333a",
          "exists": true
        },
        {
          "description": "No. 1 v7.21 live receipt SLA verification, v7.20 continuity import, HTTP/POST gap review, receipt SLA dispatch, issuer/source recheck, weighted refresh, and publication claim-freeze controls",
          "file": "0141_no1_v721_live_receipt_sla_verification_controls.sql",
          "sha256": "1c04004c7413c0ad6971244ffbdcf42302b3ecbe20281dd0ee6db66bf6b24101",
          "exists": true
        },
        {
          "description": "No. 1 v7.22 live receipt closure, v7.21 continuity import, issuer/source/revocation gates, receipt SLA burndown, dependency HTTP follow-up, weighted receipt coverage refresh, and external claim-freeze controls",
          "file": "0142_no1_v722_live_receipt_closure_controls.sql",
          "sha256": "22bceb2ad712034bd14fd1ae6cfaa383f12f009c274f668affac3465b7974fe7",
          "exists": true
        },
        {
          "file": "0143_no1_v723_live_receipt_verification_execution_controls.sql",
          "sha256": "989ec937fd898cd594641ce1a5c7ac68aa447e2072f4cca485683308d6cdb1fa",
          "exists": true
        },
        {
          "file": "0144_no1_v724_live_receipt_claim_review_controls.sql",
          "sha256": "b96fab8515899bf57c5d36679649e1279c5cd957bb30abc602589ceb38e3f276",
          "exists": true
        },
        {
          "file": "0145_no1_v725_claim_eligibility_release_controls.sql",
          "sha256": "0741196149cc59b8123a6ecaf5bc10517ac338a7e2b842e8db966e2e9970c7f1",
          "exists": true
        },
        {
          "file": "0146_no1_v726_claim_release_verification_controls.sql",
          "sha256": "181f9c6e68e7f3fbbb4d77a6f830f6d5b3b4ec4bdc583d69f9c13f1d157cd2a1",
          "exists": true
        },
        {
          "file": "0147_no1_v727_claim_release_closure_controls.sql",
          "sha256": "2b3c2c19bd6b29b94d0719e03553b5770410c1349d3ff59d998ce070d7210b4d",
          "exists": true
        },
        {
          "file": "0148_no1_v728_claim_release_execution_controls.sql",
          "sha256": "d01778eb3ae2eaa1b783386a9c851408f989b4ba505f0bffbf803e1bc579f2f1",
          "exists": true
        },
        {
          "file": "0149_no1_v729_claim_release_evidence_closure_controls.sql",
          "sha256": "e9eba8e265764d603342dacfd224d1d75b7df8321da1e29cf1c99db47f24f74f",
          "exists": true
        },
        {
          "description": "No. 1 v7.29 claim-release evidence controls with v7.28 continuity import, board evidence queue, issuer/source reverification, receipt SLA dispatch, weighted claim-freeze refresh, and external claim publication locking.",
          "file": "0150_no1_v729_claim_release_evidence_controls.sql",
          "sha256": "e7013ceb652c16e76b88724e49b95e7fd9973cfcea5a0572196d7872d52466d6",
          "exists": true
        },
        {
          "description": "No. 1 v7.30 claim-release publication controls with v7.29 continuity import, verified receipt SLA burndown, issuer/source reverification, HTTP closure, weighted claim-freeze refresh, and external publication locks.",
          "file": "0151_no1_v730_claim_release_publication_controls.sql",
          "sha256": "b8ec6122ff7cffb14d4882ab959f8502c3b1efa763c2e920ca1ecd1e85373efa",
          "exists": true
        },
        {
          "file": "0152_no1_v731_claim_publication_audit_controls.sql",
          "sha256": "1f1c47e885ddbf9505b079aaae9a7ad0ff912ef60688255476d892a7a3ab83ee",
          "exists": true
        },
        {
          "description": "NexaMarket migration 0153_no1_v732_claim_publication_review_controls.sql",
          "file": "0153_no1_v732_claim_publication_review_controls.sql",
          "sha256": "9022a4e967c03b2f5de4a1146ccd3091ae89f99921b75bd19b6d137e79f3f7f8",
          "exists": true
        },
        {
          "description": "No. 1 v7.33 claim-publication evidence closure controls with v7.32 continuity import, SLA dispatch, issuer/freshness/source reverification, HTTP evidence closure, weighted claim-publication delta, and external claim freeze locking.",
          "file": "0154_no1_v733_claim_publication_evidence_closure_controls.sql",
          "sha256": "af12269c0925921540d53e09bf237820e7ffd4a2a64358a564e492deb1999652",
          "exists": true
        },
        {
          "description": "No. 1 v7.34 claim-publication verification controls with v7.33 continuity import, receipt SLA closure dispatch, issuer/signature/freshness/source verification, HTTP follow-up, weighted publication refresh, and external publication lock controls.",
          "file": "0155_no1_v734_claim_publication_verification_controls.sql",
          "sha256": "9a8259d528b54e38f63dd23d9d8d4b757a8a69d215a48402df0b0835bc3f0c30",
          "exists": true
        },
        {
          "description": "No. 1 v7.35 claim-publication approval controls with v7.34 continuity import, verified receipt SLA execution, issuer/signature/freshness/source reverification, HTTP closure, weighted readiness refresh, and external publication lock controls.",
          "file": "0156_no1_v735_claim_publication_approval_controls.sql",
          "sha256": "66bf57c77d6f2e37833c32ef49ad3e91981a040bd47b1306c939ed7f0a5af9a6",
          "exists": true
        },
        {
          "description": "NexaMarketAI v7.47 psychological UX foundation controls for goal-first context, recommendations, proof links, action previews, progress, social proof governance, feedback, metrics, and unverified UX scorecard evidence.",
          "file": "0157_psychological_ux_foundation_controls.sql",
          "sha256": "2e96804e3e1a5a3fa59e5c75a778c70866a1ef214d47faa738dba10fa31b4571",
          "exists": true
        },
        {
          "description": "NexaMarketAI v7.48 lean production beta persistence foundation for PostgreSQL tenant-scoped leads, evidence, approvals, handoffs, replay events, exports, audit events, and row-level-security readiness.",
          "file": "0158_lean_production_beta_foundation.sql",
          "sha256": "e04468d92d254b657ddab872d65529bf7362a076c79f0a56eff1ce3b9fa8fa49",
          "exists": true
        }
      ]
    },
    "data_classification": {
      "schema_version": "2026-04-30.112",
      "policy": "Classify before persistence, scope every query by tenant_id, and audit every export.",
      "domains": [
        {
          "domain": "identity",
          "tables": [
            "tenants",
            "users",
            "tenant_memberships",
            "role_assignments",
            "rbac_permission_grants"
          ],
          "classification": "confidential_pii",
          "pii_fields": [
            "email",
            "display_name",
            "external_subject"
          ],
          "retention": "active customer term plus legal hold window",
          "rbac": [
            "owner_admin",
            "security_admin"
          ]
        },
        {
          "domain": "crm",
          "tables": [
            "accounts",
            "contacts",
            "leads",
            "deals",
            "deal_timeline"
          ],
          "classification": "confidential_customer_data",
          "pii_fields": [
            "contacts.email",
            "contacts.phone",
            "leads.contact_email"
          ],
          "retention": "tenant policy; suppress/export/delete through privacy workflow",
          "rbac": [
            "sales",
            "manager",
            "customer_success",
            "analyst_read_filtered"
          ]
        },
        {
          "domain": "revenue",
          "tables": [
            "products",
            "price_books",
            "quotes",
            "quote_lines",
            "contracts",
            "invoices"
          ],
          "classification": "restricted_financial",
          "pii_fields": [],
          "retention": "finance/legal retention schedule",
          "rbac": [
            "manager",
            "finance_admin",
            "legal_reviewer"
          ]
        },
        {
          "domain": "workflow_runtime",
          "tables": [
            "workflow_blueprints",
            "workflow_runs",
            "workflow_steps",
            "runtime_jobs",
            "outbox_events",
            "rate_limit_counters",
            "object_versions"
          ],
          "classification": "confidential_operational",
          "pii_fields": [
            "payload_json when source object contains PII"
          ],
          "retention": "operational audit window plus incident/legal hold exceptions",
          "rbac": [
            "manager",
            "runtime_operator",
            "security_admin"
          ]
        },
        {
          "domain": "integrations",
          "tables": [
            "provider_integration_contracts",
            "webhook_deliveries",
            "outbox_events"
          ],
          "classification": "confidential_provider_operational",
          "pii_fields": [
            "payload_json when webhook payload contains contact/user details"
          ],
          "retention": "provider contract and webhook replay retention schedule",
          "rbac": [
            "owner_admin",
            "security_admin",
            "runtime_operator"
          ]
        },
        {
          "domain": "audit",
          "tables": [
            "audit_events",
            "idempotency_keys",
            "release_artifacts",
            "export_jobs"
          ],
          "classification": "immutable_restricted_audit",
          "pii_fields": [
            "actor_email",
            "ip_hash",
            "request_summary"
          ],
          "retention": "immutable audit retention; append-only and export controlled",
          "rbac": [
            "owner_admin",
            "security_admin",
            "auditor"
          ]
        },
        {
          "domain": "tenant_access",
          "tables": [
            "tenant_access_policies",
            "tenant_resource_views"
          ],
          "classification": "confidential_authorization_metadata",
          "pii_fields": [
            "actor_user_id when joined to users"
          ],
          "retention": "authorization evidence retained with audit policy",
          "rbac": [
            "owner_admin",
            "security_admin"
          ]
        },
        {
          "domain": "recovery",
          "tables": [
            "recovery_points",
            "restore_validations",
            "slo_snapshots"
          ],
          "classification": "restricted_operational_resilience",
          "pii_fields": [
            "backup payload references may contain tenant/customer data"
          ],
          "retention": "backup retention schedule plus legal hold exceptions",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability"
          ]
        },
        {
          "domain": "data_quality",
          "tables": [
            "data_quality_runs",
            "data_quality_findings",
            "repository_query_plans"
          ],
          "classification": "confidential_quality_evidence",
          "pii_fields": [
            "finding.message may reference customer/contact fields"
          ],
          "retention": "quality evidence retained with release and migration audit policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "revops_admin"
          ]
        },
        {
          "domain": "privacy_retention",
          "tables": [
            "privacy_retention_scans",
            "privacy_retention_actions",
            "secret_reference_inventory"
          ],
          "classification": "restricted_privacy_operations",
          "pii_fields": [
            "suppression/contact references",
            "actor_user_id"
          ],
          "retention": "privacy evidence retained under compliance schedule and legal hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "legal_reviewer"
          ]
        },
        {
          "domain": "policy_route_governance",
          "tables": [
            "policy_bundles",
            "policy_rules",
            "policy_evaluations",
            "policy_violations",
            "route_governance_routes",
            "route_control_coverage"
          ],
          "classification": "restricted_security_governance",
          "pii_fields": [
            "actor_user_id when joined to users",
            "context_json when source payload contains PII"
          ],
          "retention": "immutable security and route-change evidence retention schedule",
          "rbac": [
            "owner_admin",
            "security_admin",
            "auditor"
          ]
        },
        {
          "domain": "access_incident_slo",
          "tables": [
            "privileged_access_requests",
            "break_glass_sessions",
            "provider_contract_test_runs",
            "incident_records",
            "slo_snapshot_evidence"
          ],
          "classification": "restricted_operational_security",
          "pii_fields": [
            "reported_by",
            "requested_by",
            "actor_user_id"
          ],
          "retention": "incident/security evidence retention with legal hold exceptions",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability"
          ]
        },
        {
          "domain": "feature_dlp_deployment_scheduler",
          "tables": [
            "feature_flags",
            "feature_flag_changes",
            "feature_flag_evaluations",
            "dlp_scan_runs",
            "dlp_scan_findings",
            "deployment_changes",
            "scheduler_runs"
          ],
          "classification": "restricted_release_privacy_operations",
          "pii_fields": [
            "dlp_scan_findings.object_path",
            "feature_flag_evaluations.context_json",
            "scheduler_runs.actions_json when source job touches PII"
          ],
          "retention": "release, privacy, and operational evidence retained with audit/legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability"
          ]
        },
        {
          "domain": "service_artifact_webhook_synthetic",
          "tables": [
            "service_accounts",
            "service_account_events",
            "object_artifacts",
            "artifact_access_events",
            "webhook_replay_jobs",
            "synthetic_monitor_runs"
          ],
          "classification": "restricted_machine_identity_and_artifact_operations",
          "pii_fields": [
            "artifact_access_events.actor_user_id",
            "webhook_replay_jobs.payload_fingerprint when joined to webhook payload",
            "synthetic_monitor_runs.probe_results when diagnostic messages include customer identifiers"
          ],
          "retention": "machine-identity, artifact, webhook, and monitor evidence retained with security audit and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability"
          ]
        },
        {
          "domain": "api_compliance_residency_resilience_supply_chain",
          "tables": [
            "api_lifecycle_checks",
            "data_residency_assessments",
            "backup_drills",
            "compliance_evidence_packs",
            "supply_chain_scans"
          ],
          "classification": "restricted_release_compliance_and_resilience_evidence",
          "pii_fields": [
            "data_residency_assessments.findings_json when object paths reference customers",
            "compliance_evidence_packs.controls_json when evidence references actors",
            "supply_chain_scans.sbom_json when build metadata includes maintainer identifiers"
          ],
          "retention": "release, audit, compliance, residency, and backup evidence retained under legal-hold-aware security policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "consent_billing_resilience",
          "tables": [
            "consent_events",
            "data_residency_transfer_events",
            "billing_reconciliation_runs",
            "resilience_drill_runs"
          ],
          "classification": "restricted_privacy_finance_and_resilience_evidence",
          "pii_fields": [
            "consent_events.email",
            "consent_events.subject_ref",
            "billing_reconciliation_runs.findings_json when findings reference customers",
            "resilience_drill_runs.notes when operators include object references"
          ],
          "retention": "privacy/finance/resilience evidence retained with audit, legal hold, and customer data processing obligations",
          "rbac": [
            "owner_admin",
            "security_admin",
            "finance_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "telemetry_alert_lineage_capacity",
          "tables": [
            "telemetry_snapshots",
            "alerts",
            "data_lineage_runs",
            "capacity_assessments"
          ],
          "classification": "restricted_observability_security_and_revenue_lineage_evidence",
          "pii_fields": [
            "alerts.description when operators include customer names",
            "data_lineage_runs.findings_json when findings reference customers or contracts",
            "telemetry_snapshots.notes when operators include actor details"
          ],
          "retention": "operational telemetry, alert, lineage, and capacity evidence retained under security-audit and incident-response policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "security_assurance_runbook_sla",
          "tables": [
            "control_assessments",
            "threat_model_runs",
            "access_review_cycles",
            "runbook_executions",
            "sla_assessments"
          ],
          "classification": "restricted_security_assurance_and_customer_commitment_evidence",
          "pii_fields": [
            "access_review_cycles.certification_items_json when user display names or emails are included",
            "sla_assessments.findings_json when support tickets reference customer contacts",
            "runbook_executions.notes when operators include customer identifiers"
          ],
          "retention": "security assurance, access-review, runbook, and SLA evidence retained under audit, customer contract, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "customer_success_admin",
            "auditor"
          ]
        },
        {
          "domain": "kms_vulnerability_configuration_evidence",
          "tables": [
            "kms_keys",
            "kms_key_events",
            "vulnerability_scans",
            "vulnerability_scan_findings",
            "configuration_baselines",
            "configuration_baseline_evaluations",
            "evidence_seals",
            "evidence_seal_verifications"
          ],
          "classification": "restricted_security_configuration_and_evidence_integrity",
          "pii_fields": [
            "actor_id when joined to users",
            "vulnerability_scan_findings.evidence_json when a finding references a customer object path"
          ],
          "retention": "security, release, and compliance evidence retained with immutable audit and legal-hold controls",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "zero_trust_search_queue_migration",
          "tables": [
            "active_sessions",
            "session_risk_assessments",
            "search_index_runs",
            "search_index_documents",
            "queue_autoscaling_assessments",
            "migration_rollback_rehearsals"
          ],
          "classification": "restricted_zero_trust_runtime_and_schema_release_evidence",
          "pii_fields": [
            "active_sessions.actor_id when joined to users",
            "session_risk_assessments.resource when it references customer objects",
            "search_index_documents.text_hash/source_id when linked to customer records"
          ],
          "retention": "session, search, queue, and migration rollback evidence retained with security-audit and release-control policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "database_admin",
            "auditor"
          ]
        },
        {
          "domain": "database_cutover_query_archive_queue",
          "tables": [
            "database_cutover_rehearsals",
            "schema_drift_checks",
            "query_performance_assessments",
            "archive_lifecycle_runs",
            "archive_lifecycle_actions",
            "queue_sla_scans"
          ],
          "classification": "restricted_persistence_runtime_and_retention_evidence",
          "pii_fields": [
            "findings_json when findings reference customer records",
            "actions_json when archive candidates include customer object references",
            "actor_id when joined to users"
          ],
          "retention": "release cutover, schema, performance, queue, and archive lifecycle evidence retained with audit/legal-hold controls",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "database_admin",
            "auditor"
          ]
        },
        {
          "domain": "privacy_entitlement_network_release",
          "tables": [
            "privacy_subject_requests",
            "privacy_subject_request_events",
            "privacy_requests",
            "tenant_entitlement_assessments",
            "usage_metering_events",
            "network_posture_snapshots",
            "maintenance_windows",
            "vendor_risk_assessments",
            "revenue_recognition_runs",
            "model_risk_assessments",
            "trust_evidence_shares"
          ],
          "classification": "restricted_privacy_tenant_billing_network_and_release_evidence",
          "pii_fields": [
            "privacy_subject_requests.subject_ref",
            "privacy_subject_requests.email_hash_ref",
            "privacy_requests.subject_ref/email_hash_ref",
            "usage_metering_events.object_ref when linked to customer activity",
            "trust_evidence_shares.audience when linked to customer contacts",
            "maintenance_windows.notification_ref when linked to customer communications"
          ],
          "retention": "privacy/vendor-risk/revenue-recognition/model-risk/trust evidence retained under legal, finance, audit, and customer-contract obligations",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "site_reliability",
            "finance_admin",
            "auditor"
          ]
        },
        {
          "domain": "identity_tenant_evidence_oauth",
          "tables": [
            "identity_cutover_runs",
            "tenant_activation_runs",
            "evidence_vault_records",
            "provider_oauth_checks"
          ],
          "classification": "restricted_identity_tenant_audit_and_provider_secret_evidence",
          "pii_fields": [
            "identity_cutover_runs.actor_id when joined to users",
            "tenant_activation_runs.tenant_name/admin contact references",
            "evidence_vault_records.source_id when linked to customer evidence",
            "provider_oauth_checks.credential_ref metadata"
          ],
          "retention": "identity, tenant activation, evidence vault, and provider OAuth readiness retained under security audit, customer contract, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "tenant_admin",
            "provider_admin",
            "auditor"
          ]
        },
        {
          "domain": "database_directory_provider_custody_error_comms",
          "tables": [
            "database_operation_checks",
            "directory_sync_runs",
            "provider_sandbox_validations",
            "document_custody_records",
            "error_budget_reports",
            "customer_comms_events"
          ],
          "classification": "restricted_database_identity_provider_document_and_customer_ops_evidence",
          "pii_fields": [
            "directory_sync_runs.actor_id when joined to users",
            "document_custody_records.object_id when linked to contracts",
            "customer_comms_events.message/source_id when linked to customer contacts",
            "error_budget_reports.service when service names identify tenants"
          ],
          "retention": "database cutover, directory, provider, legal custody, SLO, and customer communications evidence retained under security audit, customer contract, finance/legal, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "provider_admin",
            "legal_reviewer",
            "customer_success_admin",
            "auditor"
          ]
        },
        {
          "domain": "client_privacy_support_environment",
          "tables": [
            "client_applications",
            "client_application_events",
            "data_minimization_assessments",
            "support_escalations",
            "environment_promotions"
          ],
          "classification": "restricted_client_security_privacy_support_and_release_evidence",
          "pii_fields": [
            "client_application_events.actor_id when joined to users",
            "data_minimization_assessments.findings_json when paths reference contacts",
            "support_escalations.customer_ref/description when customer contacts are included",
            "environment_promotions.notes when operators include actor or customer identifiers"
          ],
          "retention": "client security, privacy minimization, support escalation, and release promotion evidence retained under audit, privacy, customer contract, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "customer_success_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "migration_provider_notification_audit",
          "tables": [
            "data_migration_waves",
            "provider_action_runs",
            "notification_deliveries",
            "webhook_signature_verifications",
            "external_audit_engagements"
          ],
          "classification": "restricted_cutover_provider_customer_and_attestation_evidence",
          "pii_fields": [
            "notification_deliveries.audience when linked to contacts",
            "provider_action_runs.payload_ref when linked to provider customer data",
            "webhook_signature_verifications.event_id when linked to provider payloads",
            "external_audit_engagements.notes when operators include customer identifiers"
          ],
          "retention": "database cutover, provider execution, notification delivery, webhook assurance, and external audit evidence retained under security audit, customer contract, legal, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "provider_admin",
            "customer_success_admin",
            "auditor"
          ]
        },
        {
          "domain": "service_circuit_privacy_accessibility_cost_hypercare",
          "tables": [
            "service_catalog_entries",
            "service_catalog_events",
            "integration_circuit_breakers",
            "integration_circuit_breaker_events",
            "privacy_impact_assessments",
            "accessibility_scans",
            "cost_assessments",
            "hypercare_runs"
          ],
          "classification": "restricted_operational_governance_launch_evidence",
          "pii_fields": [
            "service_catalog_events.actor_id when joined to users",
            "privacy_impact_assessments.findings when processing details reference customers",
            "hypercare_runs.target_tenants when linked to customer organizations",
            "cost_assessments.notes when operators include vendor or customer references"
          ],
          "retention": "service ownership, provider circuit-breaker, privacy impact, accessibility, FinOps, and launch hypercare evidence retained under security audit, customer contract, privacy, and release-governance policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "privacy_admin",
            "finance_admin",
            "customer_success_admin",
            "auditor"
          ]
        },
        {
          "domain": "domain_warehouse_dr_finops_exceptions",
          "tables": [
            "domain_verifications",
            "domain_verification_events",
            "warehouse_sync_runs",
            "dr_failover_drills",
            "finops_assessments",
            "policy_exceptions"
          ],
          "classification": "restricted_tenant_domain_analytics_resilience_finops_and_risk_acceptance_evidence",
          "pii_fields": [
            "domain_verifications.domain when domain identifies a customer",
            "warehouse_sync_runs.notes when operators include customer identifiers",
            "dr_failover_drills.notes when incidents reference customers",
            "policy_exceptions.reason/notes when exceptions reference customer records"
          ],
          "retention": "custom-domain, warehouse sync, disaster-recovery, FinOps, and policy-exception evidence retained under security audit, customer contract, privacy, and release-governance policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "tenant_admin",
            "site_reliability",
            "finance_admin",
            "auditor"
          ]
        },
        {
          "domain": "api_sso_abuse_traffic_rollback",
          "tables": [
            "api_consumers",
            "api_consumer_events",
            "sso_claim_checks",
            "abuse_detection_scans",
            "abuse_detection_signals",
            "traffic_routes",
            "traffic_route_events",
            "rollback_runs"
          ],
          "classification": "restricted_api_identity_security_release_evidence",
          "pii_fields": [
            "api_consumers.owner when joined to user records",
            "sso_claim_checks.observed_claims metadata",
            "abuse_detection_signals.detail when signals reference customer objects",
            "rollback_runs.notes when operators include customer identifiers"
          ],
          "retention": "API consumer, SSO, abuse, traffic, and rollback evidence retained under security audit, incident response, customer contract, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "data_contract_egress_secret_payment_oncall_postmortem",
          "tables": [
            "data_contract_runs",
            "egress_policy_checks",
            "secret_rotation_campaigns",
            "payment_risk_assessments",
            "oncall_coverage_checks",
            "incident_postmortems"
          ],
          "classification": "restricted_release_security_finance_and_operational_evidence",
          "pii_fields": [
            "egress_policy_checks.destination when customer-specific endpoint is used",
            "payment_risk_assessments.customer_ref",
            "oncall_coverage_checks.primary_oncall",
            "incident_postmortems.root_cause/customer_impact when customer names are included"
          ],
          "retention": "release, payment-risk, incident-learning, and security evidence retained under audit, customer contract, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "finance_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "infrastructure_smoke_hold_revenue_support",
          "tables": [
            "infrastructure_policy_checks",
            "release_smoke_test_runs",
            "legal_hold_enforcement_runs",
            "revenue_close_validations",
            "support_readiness_runs"
          ],
          "classification": "restricted_launch_infrastructure_retention_revenue_and_customer_support_evidence",
          "pii_fields": [
            "support_readiness_runs.notes when operators include customer identifiers",
            "revenue_close_validations.sample_deal_id when joined to customers",
            "legal_hold_enforcement_runs.blocked_actions_json when action references identify customer records"
          ],
          "retention": "production launch, infrastructure policy, legal-hold, revenue closeout, and support readiness evidence retained under audit, customer contract, privacy, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "legal_reviewer",
            "customer_success_admin",
            "auditor"
          ]
        },
        {
          "domain": "backfill_email_contract_customer_knowledge",
          "tables": [
            "data_backfill_runs",
            "email_deliverability_assessments",
            "contract_obligations",
            "contract_obligation_events",
            "customer_health_assessments",
            "knowledge_reviews",
            "knowledge_review_events"
          ],
          "classification": "restricted_customer_contract_revenue_and_operational_knowledge_evidence",
          "pii_fields": [
            "email_deliverability_assessments.domain when tied to customer domain",
            "contract_obligations.owner",
            "customer_health_assessments.account_name/customer notes",
            "knowledge_reviews.notes when articles mention customer identifiers"
          ],
          "retention": "backfill, deliverability, contract obligation, customer health, and knowledge-review evidence retained under security audit, customer contract, privacy, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "legal_reviewer",
            "customer_success_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "audit_retention_entitlement_renewal_runtime_guardrails",
          "tables": [
            "audit_export_batches",
            "retention_execution_runs",
            "entitlement_reconciliation_runs",
            "contract_renewal_reviews",
            "contract_renewal_events",
            "runtime_guardrail_checks"
          ],
          "classification": "restricted_audit_privacy_revenue_contract_and_runtime_evidence",
          "pii_fields": [
            "audit_export_batches.actor_id when joined to users",
            "retention_execution_runs.blocked_actions when object refs identify customers",
            "entitlement_reconciliation_runs.tenant_id when tied to customer",
            "contract_renewal_reviews.account_id/customer notes",
            "runtime_guardrail_checks.blocked_actions when workflow payloads identify customers"
          ],
          "retention": "audit export, retention execution, entitlement reconciliation, contract renewal, and runtime guardrail evidence retained under immutable audit, customer contract, privacy, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "legal_reviewer",
            "finance_admin",
            "customer_success_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "permission_export_erasure_incident_workflow",
          "tables": [
            "permission_matrix_runs",
            "export_watermark_checks",
            "erasure_verifications",
            "incident_comms_approvals",
            "workflow_sandbox_runs"
          ],
          "classification": "restricted_security_privacy_export_incident_and_workflow_evidence",
          "pii_fields": [
            "erasure_verifications.subject_ref",
            "export_watermark_checks.recipient_ref",
            "incident_comms_approvals.audience/message_ref when linked to customer notices",
            "workflow_sandbox_runs.failed_steps when payloads reference customers"
          ],
          "retention": "permission, export, privacy erasure, incident communications, and workflow sandbox evidence retained under immutable audit, privacy, incident-response, customer contract, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "legal_reviewer",
            "customer_success_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "integrity_provider_tenant_workflow_acceptance",
          "tables": [
            "data_integrity_runs",
            "provider_sla_assessments",
            "tenant_lifecycle_runs",
            "workflow_recovery_drills",
            "release_acceptance_packs"
          ],
          "classification": "restricted_launch_integrity_provider_tenant_and_workflow_evidence",
          "pii_fields": [
            "tenant_lifecycle_runs.tenant_name when tenant identifies a customer",
            "data_integrity_runs.findings_json when findings reference customer objects",
            "release_acceptance_packs.gate_results when linked to customer launch evidence"
          ],
          "retention": "production data-integrity, provider SLA, tenant lifecycle, workflow recovery, and release-acceptance evidence retained under audit, customer contract, privacy, and legal-hold policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "provider_admin",
            "tenant_admin",
            "site_reliability",
            "auditor"
          ]
        },
        {
          "domain": "production_binding_repository_worker_provider",
          "tables": [
            "repository_cutover_runs",
            "route_modularization_runs",
            "identity_enforcement_runs",
            "worker_runtime_bindings",
            "provider_adapter_bindings",
            "production_binding_acceptance_packs"
          ],
          "classification": "restricted_launch_infrastructure_binding_evidence",
          "pii_fields": [
            "identity_enforcement_runs.actor_id when joined to users",
            "provider_adapter_bindings.credential_ref metadata",
            "production_binding_acceptance_packs.gate_results when linked to tenant launch evidence"
          ],
          "retention": "repository cutover, route refactor, identity enforcement, worker runtime, provider adapter, and production binding acceptance evidence retained under immutable release, audit, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "site_reliability",
            "provider_admin",
            "auditor"
          ]
        },
        {
          "domain": "transaction_worker_adapter_ui_cutover",
          "tables": [
            "repository_transaction_runs",
            "worker_lease_cycles",
            "provider_adapter_executions",
            "ui_surface_contracts",
            "cutover_readiness_packs"
          ],
          "classification": "restricted_final_cutover_execution_evidence",
          "pii_fields": [
            "repository_transaction_runs.actor_id when joined to users",
            "provider_adapter_executions.credential_ref metadata",
            "ui_surface_contracts.role/API paths when linked to tenant launch evidence",
            "cutover_readiness_packs.gate_results when linked to customer cutover"
          ],
          "retention": "repository transaction, worker lease, provider execution, UI/API surface, and final cutover readiness evidence retained under immutable release, audit, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "site_reliability",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "launch_binding_repository_auth_worker_webhook_ui",
          "tables": [
            "postgres_repository_runtime_checks",
            "authz_decision_checks",
            "durable_worker_queue_runs",
            "provider_webhook_runtime_checks",
            "ui_api_regression_runs",
            "launch_binding_packs"
          ],
          "classification": "restricted_launch_infrastructure_binding_and_runtime_enforcement_evidence",
          "pii_fields": [
            "authz_decision_checks.actor_id when joined to users",
            "provider_webhook_runtime_checks.provider_name when customer-specific connectors are used",
            "ui_api_regression_runs.api_paths when tenant-specific routes are tested",
            "launch_binding_packs.gate_results when linked to customer cutovers"
          ],
          "retention": "repository runtime, authorization, worker, webhook, UI/API regression, and launch binding evidence retained under immutable release, security, audit, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "site_reliability",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "repository_auth_worker_provider_dataplane",
          "tables": [
            "repository_adapter_verifications",
            "auth_gateway_verifications",
            "worker_supervision_checks",
            "provider_live_cutover_runs",
            "data_plane_acceptance_packs"
          ],
          "classification": "restricted_data_plane_cutover_and_launch_acceptance_evidence",
          "pii_fields": [
            "auth_gateway_verifications.actor_id when joined to users",
            "provider_live_cutover_runs.provider_name when customer-specific connector names are used",
            "data_plane_acceptance_packs.gate_results when linked to tenant launch evidence"
          ],
          "retention": "repository adapter, auth gateway, worker supervision, provider cutover, and data-plane acceptance evidence retained under immutable release, security, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "site_reliability",
            "provider_admin",
            "auditor"
          ]
        },
        {
          "domain": "runtime_launch_cutover_execution",
          "tables": [
            "repository_live_cutovers",
            "authorization_enforcement_checks",
            "worker_job_batches",
            "provider_webhook_cutovers",
            "frontend_navigation_contracts",
            "runtime_cutover_acceptance_packs"
          ],
          "classification": "restricted_runtime_launch_execution_evidence",
          "pii_fields": [
            "authorization_enforcement_checks.actor_id when joined to users",
            "repository_live_cutovers.tenant_scope when linked to customer tenants",
            "provider_webhook_cutovers.provider_name when tenant-specific connector names are used",
            "frontend_navigation_contracts.role/API paths when linked to launch tenants"
          ],
          "retention": "runtime launch cutover evidence retained under immutable release, security, provider, audit, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "database_admin",
            "site_reliability",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "dependency_rls_worker_webhook_launch",
          "tables": [
            "dependency_topology_checks",
            "repository_rls_proofs",
            "worker_failover_rehearsals",
            "provider_webhook_bindings",
            "production_launch_acceptance_packs"
          ],
          "classification": "restricted_live_launch_infrastructure_acceptance_evidence",
          "pii_fields": [
            "actor_id when joined to users",
            "tenant_id when linked to customer launch",
            "provider webhook metadata when customer-specific provider names are used"
          ],
          "retention": "production launch dependency, tenant-isolation, worker failover, webhook binding, and acceptance evidence retained under immutable release, security, and audit policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "database_admin",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "infrastructure_execution_runtime_binding",
          "tables": [
            "database_repository_bindings",
            "auth_middleware_enforcements",
            "worker_daemon_operations",
            "provider_connector_operations",
            "observability_trace_bindings",
            "infrastructure_execution_acceptance_packs"
          ],
          "classification": "restricted_infrastructure_execution_and_runtime_binding_evidence",
          "pii_fields": [
            "actor_id when joined to users",
            "tenant_id when linked to launch customers",
            "provider connector names when customer-specific connectors are used",
            "observability log samples when operators include customer identifiers"
          ],
          "retention": "database repository binding, auth middleware enforcement, worker daemon, provider connector, observability, and infrastructure execution acceptance evidence retained under immutable release, security, audit, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "database_admin",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "live_runtime_execution_binding",
          "tables": [
            "repository_connection_pool_checks",
            "identity_token_runtime_checks",
            "worker_orchestration_runs",
            "provider_connector_health_checks",
            "evidence_pipeline_runs",
            "live_runtime_acceptance_packs"
          ],
          "classification": "restricted_live_runtime_infrastructure_and_evidence_delivery",
          "pii_fields": [
            "actor_id when joined to users",
            "tenant_id when linked to launch customers",
            "identity token claim metadata",
            "provider connector names when customer-specific connectors are used",
            "evidence pipeline payload references when linked to restricted exports"
          ],
          "retention": "live runtime connection-pool, identity-token, worker orchestration, provider health, evidence-pipeline, and acceptance evidence retained under immutable release, audit, security, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "database_admin",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "runtime_operations_tenant_repository_worker_provider_slo",
          "tables": [
            "tenant_data_boundary_checks",
            "repository_snapshot_consistency_checks",
            "worker_backpressure_runs",
            "provider_failback_runs",
            "observability_slo_burn_checks",
            "runtime_operations_acceptance_packs"
          ],
          "classification": "restricted_runtime_operations_and_launch_acceptance_evidence",
          "pii_fields": [
            "actor_id when joined to users",
            "tenant_id when linked to launch customers",
            "provider connector names when customer-specific connectors are used",
            "observability burn evidence when routes or traces reference customer identifiers"
          ],
          "retention": "runtime operations, tenant-boundary, repository consistency, worker backpressure, provider failback, SLO burn, and acceptance evidence retained under immutable release, audit, security, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "database_admin",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "go_live_tenant_edge_billing_compliance_hypercare",
          "tables": [
            "tenant_migration_cutovers",
            "edge_gateway_checks",
            "billing_subscription_cutovers",
            "provider_rate_limit_budgets",
            "compliance_attestations",
            "hypercare_command_runs",
            "go_live_acceptance_packs"
          ],
          "classification": "restricted_go_live_execution_and_customer_launch_evidence",
          "pii_fields": [
            "actor_id when joined to users",
            "tenant_id and tenant_ids when linked to launch customers",
            "billing and provider metadata when customer-specific",
            "support and hypercare references when tied to customer incidents"
          ],
          "retention": "go-live execution, migration, billing, compliance, provider budget, hypercare, and acceptance evidence retained under immutable release, audit, security, finance, and customer launch policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "finance_admin",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_leadership_proof",
          "tables": [
            "no1_benchmark_suites",
            "no1_customer_pilot_evidence",
            "no1_market_data_rights_reviews",
            "no1_crm_handoff_contracts",
            "no1_ux_polish_reviews",
            "no1_leadership_claim_reviews",
            "no1_investor_customer_proof_packs",
            "no1_leadership_proof_acceptance_packs"
          ],
          "classification": "restricted_market_leadership_claim_and_customer_proof_evidence",
          "pii_fields": [
            "tenant_id when linked to pilot customers",
            "customer_proof_refs when linked to named customers",
            "screenshot_refs when screenshots include tenant/customer data"
          ],
          "retention": "benchmark, pilot, UX, claim, market-data-rights, CRM handoff, and leadership-proof evidence retained under release, audit, privacy, and customer-contract policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_productization_runtime",
          "tables": [
            "no1_market_signal_ingestions",
            "no1_target_queue_runs",
            "no1_proof_pack_workflows",
            "no1_campaign_lab_runs",
            "no1_safe_outreach_sequences",
            "no1_crm_promotion_receipts",
            "no1_trust_portal_packets",
            "no1_boardroom_operating_snapshots",
            "no1_productization_acceptance_packs"
          ],
          "classification": "restricted_no1_market_productization_and_workflow_evidence",
          "pii_fields": [
            "tenant_id when linked to customer pilots",
            "target queue and CRM promotion references when linked to prospects or customers",
            "trust portal packet references when customer-specific evidence is included"
          ],
          "retention": "No. 1 signal, target, proof, campaign, outreach, CRM handoff, trust portal, boardroom, and productization acceptance evidence retained under release, audit, privacy, marketing, and customer-contract policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "customer_launch_cache_queue_provider_support",
          "tables": [
            "customer_launch_waves",
            "cache_coherency_checks",
            "queue_replay_runs",
            "provider_credential_attestations",
            "support_access_runtime_checks",
            "launch_wave_acceptance_packs"
          ],
          "classification": "restricted_customer_launch_and_runtime_operations_evidence",
          "pii_fields": [
            "actor_id when joined to users",
            "tenant_id and tenant_ids when linked to launch customers",
            "provider credential reference metadata",
            "support access tenant references"
          ],
          "retention": "customer launch wave, cache, queue replay, provider credential, support access, and launch acceptance evidence retained under immutable release, audit, security, and customer support policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "site_reliability",
            "provider_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_enterprise_scale_runtime",
          "tables": [
            "no1_enterprise_procurement_readiness",
            "no1_security_questionnaire_automations",
            "no1_data_rights_license_packs",
            "no1_implementation_success_programs",
            "no1_expansion_revenue_forecasts",
            "no1_partner_channel_activations",
            "no1_market_leadership_certifications",
            "no1_enterprise_scale_acceptance_packs"
          ],
          "classification": "restricted_enterprise_scale_customer_procurement_and_market_leadership_evidence",
          "pii_fields": [
            "tenant_id when linked to pilot or enterprise customers",
            "customer reference and analyst packet references",
            "procurement/security questionnaire contacts when operator-provided",
            "NexaCRM handoff references when tied to named accounts"
          ],
          "retention": "enterprise procurement, questionnaire, data-rights, implementation, expansion, partner-channel, leadership-certification, and acceptance evidence retained under release, audit, privacy, security, and customer-contract policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "customer_success_admin",
            "partner_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_global_leadership_runtime",
          "tables": [
            "no1_global_regulatory_readiness",
            "no1_customer_advisory_councils",
            "no1_trust_marketplace_publications",
            "no1_benchmark_observatory_runs",
            "no1_ecosystem_quality_assessments",
            "no1_autonomous_governance_reviews",
            "no1_ai_model_drift_monitors",
            "no1_market_leadership_command_rooms",
            "no1_global_leadership_acceptance_packs"
          ],
          "classification": "restricted_global_leadership_regulatory_customer_ai_and_market_claim_evidence",
          "pii_fields": [
            "tenant_id when linked to enterprise customers",
            "customer advisory references",
            "customer reference and analyst packet evidence",
            "AI/model evaluation records when tied to users or prospects"
          ],
          "retention": "global leadership, regulatory, customer advisory, public trust, benchmark observatory, ecosystem quality, autonomous governance, AI drift, command-room, and acceptance evidence retained under release, audit, privacy, security, customer-contract, and claim-safety policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_network_effects_runtime",
          "tables": [
            "no1_ecosystem_network_maps",
            "no1_federated_proof_exchanges",
            "no1_partner_co_sell_motions",
            "no1_trust_score_runtime",
            "no1_community_feedback_loops",
            "no1_competitive_moat_reviews",
            "no1_category_leadership_indexes",
            "no1_network_effects_acceptance_packs"
          ],
          "classification": "restricted_no1_network_effects_partner_trust_and_moat_evidence",
          "pii_fields": [
            "tenant_id when linked to customers or partners",
            "customer/community feedback when tied to named accounts",
            "proof exchange references when tied to prospects or customer trust packets",
            "partner co-sell records when linked to customer accounts"
          ],
          "retention": "network-effect, federated-proof, partner co-sell, trust-score, community, moat, leadership-index, and acceptance evidence retained under release, audit, privacy, partner, customer-contract, and claim-safety policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "customer_success_admin",
            "partner_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_autonomous_market_mesh_runtime",
          "tables": [
            "no1_market_mesh_topologies",
            "no1_agent_decision_rights",
            "no1_proof_ledger_interop",
            "no1_mesh_privacy_benchmarks",
            "no1_ecosystem_incentive_alignments",
            "no1_real_time_risk_commands",
            "no1_flywheel_compounding_reviews",
            "no1_autonomous_mesh_acceptance_packs"
          ],
          "classification": "restricted_no1_autonomous_market_mesh_proof_privacy_benchmark_and_flywheel_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "source_references when evidence includes customer or market data",
            "benchmark participant references"
          ],
          "retention": "No. 1 autonomous-market-mesh proof retained with trust, benchmark, legal-review, release, and customer-reference evidence; legal/privacy review required before public sharing.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "revops_admin",
            "partner_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_verified_market_network_runtime",
          "tables": [
            "no1_verified_market_networks",
            "no1_consent_token_ledgers",
            "no1_agent_certifications",
            "no1_proof_exchange_policies",
            "no1_benchmark_consortiums",
            "no1_customer_value_guarantees",
            "no1_market_policy_packs",
            "no1_verified_network_acceptance_packs"
          ],
          "classification": "restricted_no1_verified_market_network_consent_proof_exchange_and_agent_certification_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "consent token references",
            "customer proof references",
            "benchmark participant references",
            "customer value guarantee references"
          ],
          "retention": "No. 1 verified-market-network proof retained with consent-token, proof-exchange, agent-certification, benchmark, legal/privacy, release, and customer-reference evidence; public sharing requires legal/privacy and claim-safety review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "partner_manager",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_blueprint_completion_runtime",
          "tables": [
            "no1_cockpit_experience_releases",
            "no1_market_graph_activations",
            "no1_provider_live_certifications",
            "no1_market_data_rights_licenses",
            "no1_ai_evaluation_proofs",
            "no1_pilot_customer_proofs",
            "no1_trust_publication_reviews",
            "no1_blueprint_completion_acceptance_packs"
          ],
          "classification": "restricted_no1_blueprint_completion_customer_provider_ai_rights_and_public_trust_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "customer reference and case-study links",
            "provider credential references",
            "licensed-source contracts when linked to vendors",
            "AI evaluation artifacts when tied to customers or prospects"
          ],
          "retention": "No. 1 blueprint-completion evidence retained with release, legal/privacy, provider certification, customer proof, AI evaluation, and claim-safety policies; public publication requires legal/privacy and overclaim review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_finish_line_runtime",
          "tables": [
            "no1_surface_suite_releases",
            "no1_provider_install_kits",
            "no1_rights_aware_ingestions",
            "no1_eval_scorecard_releases",
            "no1_customer_reference_packets",
            "no1_trust_publication_binders",
            "no1_year1_target_acceptance_packs"
          ],
          "classification": "restricted_no1_finish_line_surface_provider_data_ai_customer_and_trust_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "customer reference approvals",
            "provider credential references",
            "licensed-source and vendor contract references",
            "AI evaluation artifacts when tied to named customers or prospects"
          ],
          "retention": "No. 1 finish-line evidence retained with release, legal/privacy, customer-reference, provider-certification, AI evaluation, and claim-safety policies; public publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_launch_proof_runtime",
          "tables": [
            "no1_provider_live_receipts",
            "no1_rights_contract_executions",
            "no1_ai_eval_publications",
            "no1_customer_proof_releases",
            "no1_trust_packet_exports",
            "no1_launch_proof_acceptance_packs"
          ],
          "classification": "restricted_no1_launch_proof_live_provider_data_ai_customer_and_trust_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "customer reference approvals",
            "provider credential references",
            "licensed-source and vendor contract references",
            "AI evaluation artifacts when tied to named customers or prospects"
          ],
          "retention": "No. 1 launch-proof evidence retained with provider certification, legal/privacy review, customer proof, trust publication, AI evaluation, and release acceptance policies; public publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_mortalytics_subscription_runtime",
          "tables": [
            "no1_mortalytics_proof_pack_engines",
            "no1_mortalytics_approved_claim_libraries",
            "no1_mortalytics_objection_response_libraries",
            "no1_mortalytics_offer_message_experiments",
            "no1_mortalytics_persona_battlecards",
            "no1_mortalytics_partner_content_kits",
            "no1_mortalytics_retrieval_content_services",
            "no1_mortalytics_proof_refresh_loops",
            "no1_mortalytics_subscription_acceptance_packs"
          ],
          "classification": "restricted_mortalytics_subscription_sales_proof_claims_objections_experiments_and_retrieval_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "customer reference and case-study links",
            "CRM feedback signal references",
            "BuilderAI coaching signal references",
            "partner proof-kit exports when tied to named partners or buyers"
          ],
          "retention": "Mortalytics subscription-sales evidence retained with release, legal/privacy, customer-proof, retrieval-trace, CRM-handoff, and claim-safety policies; public publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_operational_proof_runtime",
          "tables": [
            "no1_surface_polish_deliveries",
            "no1_provider_secret_vault_bindings",
            "no1_provider_install_receipts",
            "no1_rights_registry_executions",
            "no1_ecosystem_handoff_contracts",
            "no1_ai_eval_batch_operations",
            "no1_customer_reference_publications",
            "no1_trust_bundle_distributions",
            "no1_operational_proof_acceptance_packs"
          ],
          "classification": "restricted_no1_operational_proof_provider_rights_ai_customer_trust_and_handoff_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "provider credential references",
            "licensed-source contracts",
            "customer proof references",
            "CRM and BuilderAI handoff traces when tied to named buyers or reps"
          ],
          "retention": "Operational-proof evidence retained with release, legal/privacy, customer-proof, provider-certification, rights-registry, AI evaluation, and claim-safety policies; public publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_external_readiness_runtime",
          "tables": [
            "no1_provider_live_evidence_bundles",
            "no1_rights_contract_packets",
            "no1_ai_eval_publication_bundles",
            "no1_customer_reference_packets",
            "no1_trust_review_packets",
            "no1_blueprint_progress_scorecards",
            "no1_external_readiness_acceptance_packs"
          ],
          "classification": "restricted_no1_external_readiness_provider_rights_ai_customer_trust_and_blueprint_score_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "provider credential references",
            "licensed-source contracts",
            "customer reference approvals",
            "trust-review export references",
            "weighted blueprint readiness and blocker inventories when tied to named customers or providers"
          ],
          "retention": "External-readiness evidence retained with release, legal/privacy, customer-proof, provider-certification, rights-contract, AI evaluation, trust-publication, and claim-safety policies; public publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_completion_certification_runtime",
          "tables": [
            "no1_provider_activation_certificates",
            "no1_rights_execution_certificates",
            "no1_ai_benchmark_certificates",
            "no1_customer_proof_approval_workflows",
            "no1_trust_publication_signoffs",
            "no1_weighted_completion_reports",
            "no1_completion_certification_acceptance_packs"
          ],
          "classification": "restricted_no1_completion_certification_provider_rights_ai_customer_trust_and_weighted_report_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "provider credential references",
            "licensed-source contracts",
            "customer reference approvals",
            "weighted completion reports when tied to named customers or providers"
          ],
          "retention": "Completion-certification evidence retained with release, legal/privacy, customer-proof, provider-certification, rights execution, AI benchmark, trust-publication, and claim-safety policies; public publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_live_evidence_execution_runtime",
          "tables": [
            "no1_provider_activation_runs",
            "no1_rights_ingestion_runs",
            "no1_ai_benchmark_publication_runs",
            "no1_pilot_wave_metric_captures",
            "no1_procurement_trust_exports",
            "no1_honest_100_scoreboards",
            "no1_live_evidence_execution_acceptance_packs"
          ],
          "classification": "restricted_no1_live_evidence_execution_provider_rights_ai_pilot_trust_and_honest_100_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "provider secret refs",
            "licensed-source contracts",
            "customer reference approvals",
            "pilot metrics when tied to named customers or reps",
            "honest-100 scoreboards when tied to named providers or customers"
          ],
          "retention": "Live-evidence execution receipts retained with release, legal/privacy, provider activation, rights-aware ingestion, AI benchmark publication, pilot/customer proof, trust export, and claim-safety policies; external publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_publishable_proof_runtime",
          "tables": [
            "no1_provider_activation_bundles",
            "no1_rights_receipt_bundles",
            "no1_ai_benchmark_packets",
            "no1_customer_reference_reviews",
            "no1_procurement_trust_packets",
            "no1_completion_report_packets",
            "no1_publishable_proof_acceptance_packs"
          ],
          "classification": "restricted_no1_publishable_proof_provider_rights_ai_customer_trust_and_report_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "provider secret refs",
            "licensed-source contracts",
            "customer reference approvals",
            "publishable customer-safe language blocks",
            "completion report packet content when tied to named providers or customers"
          ],
          "retention": "Publishable-proof packets retained with release, legal/privacy, provider activation, rights execution, AI benchmark, customer proof, procurement trust, and completion-report policies; external publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_publication_export_runtime",
          "tables": [
            "no1_provider_activation_export_bundles",
            "no1_rights_receipt_export_bundles",
            "no1_ai_benchmark_export_bundles",
            "no1_customer_reference_export_bundles",
            "no1_procurement_trust_bundles",
            "no1_completion_report_export_bundles",
            "no1_publication_export_acceptance_packs"
          ],
          "classification": "restricted_no1_publication_export_provider_rights_ai_customer_trust_and_completion_delivery_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "provider secret refs",
            "licensed-source contracts",
            "customer reference approvals",
            "customer-safe export bundles",
            "completion report delivery content when tied to named providers or customers"
          ],
          "retention": "Publication-export bundles retained with release, legal/privacy, provider activation, rights execution, AI benchmark, customer proof, procurement trust, and completion-report policies; external publication requires legal/privacy and customer-safe review.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_external_review_execution_runtime",
          "tables": [
            "no1_provider_external_review_sessions",
            "no1_rights_external_review_sessions",
            "no1_ai_benchmark_external_review_sessions",
            "no1_customer_reference_external_review_sessions",
            "no1_procurement_external_review_sessions",
            "no1_completion_report_board_reviews",
            "no1_external_review_execution_acceptance_packs"
          ],
          "classification": "restricted_no1_external_review_signed_provider_rights_ai_customer_procurement_and_board_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "reviewer identities",
            "customer reference permissions",
            "provider review sessions",
            "rights contract review details",
            "procurement questionnaire answers",
            "board review notes when tied to named customers or providers"
          ],
          "retention": "External-review execution sessions retained with release, legal/privacy, provider activation, rights, AI benchmark, customer reference, procurement, and board governance policies; external claims require signed approvals and delivery receipts.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "provider_admin",
            "customer_success_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_dependency_environment_runtime",
          "tables": [
            "no1_app_startup_execution_profiles",
            "no1_flask_route_client_smoke_runs",
            "no1_mutation_route_client_smoke_runs",
            "no1_gunicorn_gap_closure_reports",
            "no1_signed_artifact_file_exports",
            "no1_weighted_report_file_exports",
            "no1_dependency_environment_acceptance_packs"
          ],
          "classification": "restricted_no1_dependency_environment_startup_route_gunicorn_artifact_and_report_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "reviewer identities",
            "customer proof report artifacts",
            "route execution notes when tied to named tenants"
          ],
          "retention": "Dependency environment, route-client, Gunicorn gap, signed artifact, and weighted report evidence retained with release, audit, and claim-safety policies.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "revops_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_live_infrastructure_runtime",
          "tables": [
            "no1_postgres_rls_execution_receipts",
            "no1_redis_worker_queue_receipts",
            "no1_object_worm_storage_receipts",
            "no1_identity_binding_receipts",
            "no1_provider_live_binding_receipts",
            "no1_observability_incident_receipts",
            "no1_live_infrastructure_acceptance_packs"
          ],
          "classification": "restricted_live_infrastructure_database_worker_storage_identity_provider_observability_receipt_evidence"
        },
        {
          "domain": "no1_final_execution_runtime",
          "tables": [
            "no1_gunicorn_boot_handoff_artifacts",
            "no1_expanded_route_matrix_artifacts",
            "no1_signed_delivery_export_files",
            "no1_template_completion_report_artifacts",
            "no1_live_infrastructure_receipt_collections",
            "no1_external_review_packet_indexes",
            "no1_final_execution_acceptance_packs"
          ],
          "classification": "restricted_no1_final_execution_artifact_route_matrix_report_and_infrastructure_receipt_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "reviewer names",
            "customer proof references",
            "provider credential references"
          ],
          "retention": "Final execution artifacts retained under release, audit, procurement, privacy, customer-proof, and claim-safety policies.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_runtime_execution_runtime",
          "tables": [
            "no1_dependency_ready_startup_certificates",
            "no1_flask_route_client_execution_certificates",
            "no1_gunicorn_process_readiness_certificates",
            "no1_signed_delivery_artifact_bundles",
            "no1_weighted_completion_report_artifacts",
            "no1_ecosystem_retrieval_trace_exports",
            "no1_runtime_execution_acceptance_packs"
          ],
          "classification": "restricted_no1_runtime_execution_dependency_route_artifact_and_retrieval_trace_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "reviewer identities",
            "customer proof artifacts",
            "retrieval traces when tied to named accounts or sellers"
          ],
          "retention": "Runtime execution, route-client, signed artifact, completion report, and retrieval trace evidence retained under release, audit, privacy, customer-proof, and claim-safety policies.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_global_scale_runtime",
          "tables": [
            "no1_regional_launch_readiness",
            "no1_localization_compliance_packs",
            "no1_global_billing_tax_readiness",
            "no1_follow_the_sun_support",
            "no1_sovereign_data_controls",
            "no1_global_partner_channels",
            "no1_global_scale_acceptance_packs"
          ],
          "classification": "restricted_no1_global_scale_localization_sovereign_data_and_support_evidence",
          "pii_fields": [
            "tenant_id when linked to regional launches",
            "support-region records when tied to customer incidents",
            "billing and tax evidence when tied to invoices or entitlements",
            "partner-channel references when tied to named regional partners"
          ],
          "retention": "global regional launch, localization, billing/tax, follow-the-sun support, sovereign data, global partner-channel, and acceptance evidence retained under release, audit, privacy, finance, tax, security, and customer-contract policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "finance_admin",
            "customer_success_admin",
            "partner_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_growth_scale_runtime",
          "tables": [
            "no1_enterprise_expansion_readiness",
            "no1_onboarding_success_factories",
            "no1_customer_value_realizations",
            "no1_win_loss_intelligence_reviews",
            "no1_marketplace_distribution_scales",
            "no1_benchmark_publication_guards",
            "no1_lifecycle_retention_loops",
            "no1_growth_scale_acceptance_packs"
          ],
          "classification": "restricted_no1_growth_scale_customer_value_and_market_evidence",
          "pii_fields": [
            "tenant_id when linked to customer cohorts",
            "customer-value and win/loss references when linked to named accounts",
            "marketplace or lifecycle records when tied to customer support or renewal data"
          ],
          "retention": "growth-scale, enterprise expansion, onboarding, value, win/loss, marketplace, benchmark, lifecycle, and acceptance evidence retained under release, audit, privacy, customer-contract, and claim-safety policy",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "customer_success_admin",
            "partner_admin",
            "release_manager",
            "auditor"
          ]
        },
        {
          "domain": "no1_real_receipt_verification_runtime",
          "tables": [
            "no1_provider_receipt_verifications",
            "no1_market_data_receipt_verifications",
            "no1_ai_benchmark_receipt_verifications",
            "no1_customer_reference_receipt_verifications",
            "no1_legal_privacy_receipt_verifications",
            "no1_cockpit_demo_receipt_verifications",
            "no1_infrastructure_receipt_verifications",
            "no1_weighted_completion_refreshes",
            "no1_real_receipt_verification_acceptance_packs"
          ],
          "classification": "restricted_no1_real_receipt_verification_and_claim_safety_evidence",
          "pii_fields": [
            "tenant_id",
            "actor_id",
            "customer reference identities when attached",
            "reviewer identities",
            "provider credential references"
          ],
          "retention": "Receipt verification, weighted completion, and claim-safety evidence retained under release, audit, privacy, customer-proof, and legal-review policy.",
          "rbac": [
            "owner_admin",
            "security_admin",
            "privacy_admin",
            "revops_admin",
            "release_manager",
            "auditor"
          ]
        }
      ]
    },
    "data_quality_runs": [],
    "data_quality_summary": {
      "total_runs": 0,
      "latest_run_id": null,
      "latest_score": null,
      "latest_decision": null,
      "latest_finding_count": 0
    },
    "retention_scans": [],
    "retention_scan_summary": {
      "total_scans": 0,
      "latest_scan_id": null,
      "latest_decision": null,
      "latest_action_count": 0
    },
    "retention_control_plan": {
      "version": "2026-04-20.5",
      "mode": "evidence_only_until_external_retention_jobs_configured",
      "configured": {
        "database_url": false,
        "object_store_url": false,
        "retention_scans_required": false
      },
      "required_controls": [
        "Retention policies must be versioned and mapped to data classifications.",
        "Legal holds must block purge/archive actions until released by authorized legal/security users.",
        "Expired export artifacts must be destroyed or re-keyed by an asynchronous object-store worker.",
        "Suppression and consent records must remain available even when marketing contact data is minimized.",
        "Every retention action must create immutable audit evidence and a recovery point reference."
      ]
    },
    "repository_contracts": {
      "version": "2026-04-20.5",
      "status": "compatibility_contracts_declared",
      "persistence_boundary": "PostgreSQL repositories with JSON-state compatibility fallback",
      "global_requirements": [
        "Every repository method must accept actor_id, role, tenant_id, correlation_id, and request scope.",
        "Every list method must require explicit pagination and enforce tenant_id predicates.",
        "Every mutation must create an audit event and, when external effects are needed, an outbox event in the same transaction.",
        "Repository DTOs must classify PII/restricted fields before returning API payloads.",
        "Destructive changes must check legal hold, retention policy, and restore-point availability before execution."
      ],
      "contracts": [
        {
          "domain": "identity",
          "repositories": [
            "TenantRepository",
            "UserRepository",
            "MembershipRepository",
            "RoleGrantRepository"
          ],
          "tables": [
            "tenants",
            "users",
            "tenant_memberships",
            "rbac_permission_grants"
          ],
          "required_predicates": [
            "tenant_id",
            "deleted_at IS NULL",
            "membership.status = active"
          ],
          "required_guards": [
            "OIDC subject mapping",
            "MFA capability gate",
            "server-side RBAC decision"
          ],
          "write_pattern": "transactional_write_plus_audit_event",
          "read_pattern": "tenant_scoped_query_with_role_filter"
        },
        {
          "domain": "crm",
          "repositories": [
            "AccountRepository",
            "ContactRepository",
            "LeadRepository",
            "DealRepository",
            "TimelineRepository"
          ],
          "tables": [
            "accounts",
            "contacts",
            "leads",
            "deals",
            "deal_timeline"
          ],
          "required_predicates": [
            "tenant_id",
            "owner visibility OR cross_tenant role",
            "retention_status != purged"
          ],
          "required_guards": [
            "field-level PII redaction for analyst roles",
            "duplicate detection before canonical merge"
          ],
          "write_pattern": "idempotent_upsert_with_canonical_id",
          "read_pattern": "paginated_resource_envelope"
        },
        {
          "domain": "revenue",
          "repositories": [
            "ProductRepository",
            "QuoteRepository",
            "ContractRepository",
            "InvoiceRepository",
            "ApprovalRepository"
          ],
          "tables": [
            "products",
            "quote_headers",
            "quote_lines",
            "contracts",
            "invoices",
            "approval_requests"
          ],
          "required_predicates": [
            "tenant_id",
            "financial_permission",
            "approval_state"
          ],
          "required_guards": [
            "CPQ validation before quote persistence",
            "contract authority check before execution",
            "finance MFA for invoice exports"
          ],
          "write_pattern": "transactional_domain_event_outbox",
          "read_pattern": "tenant_scoped_query_with_finance_redaction"
        },
        {
          "domain": "provider_runtime",
          "repositories": [
            "ProviderConnectionRepository",
            "WebhookReceiptRepository",
            "OutboxRepository",
            "RuntimeJobRepository"
          ],
          "tables": [
            "provider_integration_contracts",
            "webhook_deliveries",
            "outbox_events",
            "runtime_jobs"
          ],
          "required_predicates": [
            "tenant_id",
            "provider_family",
            "idempotency_key"
          ],
          "required_guards": [
            "signed webhook verification",
            "retry budget",
            "dead-letter escalation",
            "secret reference only"
          ],
          "write_pattern": "inbox_outbox_with_idempotency_key",
          "read_pattern": "operator_or_security_scoped_queue_view"
        },
        {
          "domain": "governance_resilience",
          "repositories": [
            "AuditRepository",
            "ExportJobRepository",
            "RecoveryRepository",
            "RetentionRepository"
          ],
          "tables": [
            "audit_events",
            "export_jobs",
            "recovery_points",
            "restore_validations",
            "privacy_retention_scans"
          ],
          "required_predicates": [
            "tenant_id",
            "legal_hold",
            "retention_policy"
          ],
          "required_guards": [
            "append-only audit",
            "expiring export artifacts",
            "manual restore approval",
            "destructive-action hold check"
          ],
          "write_pattern": "append_only_evidence_event",
          "read_pattern": "security_admin_or_auditor_scoped_evidence_view"
        }
      ],
      "production_blockers_when_missing": [
        "DATABASE_URL",
        "Alembic or equivalent migration runner",
        "tenant-aware SQL repositories",
        "transactional audit/outbox writes",
        "row-level backup/restore runbooks"
      ]
    },
    "secret_reference_summary": {
      "total_references": 5,
      "configured_stub_credentials": 5,
      "rotation_due_within_30_days": 5,
      "plaintext_secret_findings": 0
    },
    "policy_bundle": {
      "version": "2026-04-20.6",
      "mode": "policy_as_code_seed",
      "configured": {
        "policy_bundle_required": false,
        "tenant_isolation_required": false,
        "secret_reference_enforcement_required": false
      },
      "policies": [
        {
          "id": "POL-EXPORT-001",
          "name": "Restricted exports require privileged role and MFA",
          "severity": "critical",
          "applies_to": [
            "export_job",
            "audit_events",
            "invoices",
            "contracts",
            "security_events"
          ],
          "obligations": [
            "mfa_verified",
            "export_audit_event",
            "tenant_scope_filter",
            "artifact_expiration"
          ]
        },
        {
          "id": "POL-TENANT-001",
          "name": "Cross-tenant access requires admin override evidence",
          "severity": "critical",
          "applies_to": [
            "resource_read",
            "resource_mutation",
            "export_job",
            "recovery_point"
          ],
          "obligations": [
            "tenant_id_predicate",
            "cross_tenant_reason",
            "audit_event"
          ]
        },
        {
          "id": "POL-PROVIDER-001",
          "name": "Provider credentials must be managed secret references",
          "severity": "critical",
          "applies_to": [
            "provider_connection",
            "provider_sync",
            "webhook_ingest"
          ],
          "obligations": [
            "credential_ref_only",
            "rotation_evidence",
            "secret_manager_pointer"
          ]
        },
        {
          "id": "POL-WEBHOOK-001",
          "name": "Provider webhooks require signature and idempotency evidence",
          "severity": "critical",
          "applies_to": [
            "webhook_ingest"
          ],
          "obligations": [
            "hmac_signature",
            "timestamp_window",
            "event_id_idempotency",
            "payload_fingerprint"
          ]
        },
        {
          "id": "POL-RETENTION-001",
          "name": "Legal hold blocks destructive retention",
          "severity": "critical",
          "applies_to": [
            "retention_delete",
            "privacy_purge"
          ],
          "obligations": [
            "legal_hold_check",
            "recovery_point_reference",
            "privacy_audit_event"
          ]
        },
        {
          "id": "POL-AI-001",
          "name": "High-risk agent action requires human review",
          "severity": "high",
          "applies_to": [
            "agent_action",
            "model_action",
            "autonomous_workflow"
          ],
          "obligations": [
            "risk_classification",
            "human_review",
            "guardrail_trace",
            "approval_id"
          ]
        },
        {
          "id": "POL-FINANCE-001",
          "name": "Large or non-standard revenue actions require approval evidence",
          "severity": "high",
          "applies_to": [
            "quote",
            "contract",
            "invoice",
            "settlement"
          ],
          "obligations": [
            "approval_evidence",
            "authority_matrix",
            "finance_audit_event"
          ]
        }
      ],
      "promotion_controls": [
        "Policy changes require route-governance impact review.",
        "High/critical denials must be preserved as immutable audit events.",
        "Production policy bundles must be signed or pinned by release digest.",
        "Policy evaluation receipts must include actor, tenant, resource, decision, and obligation evidence."
      ]
    },
    "policy_evaluations": [],
    "policy_evaluation_summary": {
      "total_evaluations": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_policy_bundle_version": "2026-04-20.6"
    },
    "access_governance": {
      "version": "2026-04-20.6",
      "mode": "privileged_access_and_break_glass_evidence",
      "configured": {
        "access_governance_required": false,
        "break_glass_controls_required": false,
        "incident_pager_configured": false
      },
      "required_controls": [
        "Privileged access must be requested with capability, reason, tenant, duration, and MFA evidence.",
        "Approvals and denials must be recorded as immutable audit evidence.",
        "Break-glass sessions must be short-lived, explicitly justified, visible to security, and revocable.",
        "Production deployment should wire these receipts to the identity provider and SIEM."
      ],
      "capabilities": [
        "security_admin",
        "provider_admin",
        "finance_admin",
        "runtime_operator",
        "legal_reviewer",
        "cross_tenant_support"
      ]
    },
    "access_requests": [],
    "break_glass_sessions": [],
    "access_governance_summary": {
      "access_request_total": 0,
      "access_requests_by_status": {},
      "break_glass_session_total": 0,
      "break_glass_sessions_by_status": {}
    },
    "provider_contract_test_catalog": {
      "version": "2026-04-20.6",
      "mode": "contract_first_provider_validation",
      "configured": {
        "provider_contract_tests_required": false,
        "webhook_signature_required": false,
        "provider_connection_count": 5
      },
      "provider_families_present": [
        "calendar",
        "crm",
        "email",
        "esign",
        "finance"
      ],
      "tests": [
        {
          "id": "identity_oidc_metadata",
          "provider_family": "identity",
          "severity": "critical",
          "assertion": "OIDC issuer metadata and JWKS are reachable before trusted identity headers are enabled."
        },
        {
          "id": "email_suppression_sync",
          "provider_family": "email",
          "severity": "high",
          "assertion": "Outbound email provider honors consent and suppression mappings."
        },
        {
          "id": "calendar_oauth_refresh",
          "provider_family": "calendar",
          "severity": "medium",
          "assertion": "Calendar OAuth token refresh and invite reconciliation are verified."
        },
        {
          "id": "esign_webhook_idempotency",
          "provider_family": "esign",
          "severity": "critical",
          "assertion": "E-sign callbacks are signed, idempotent, and produce contract execution evidence."
        },
        {
          "id": "billing_payment_webhook",
          "provider_family": "billing",
          "severity": "critical",
          "assertion": "Payment webhooks are signed, idempotent, and reconciled with invoice state."
        },
        {
          "id": "crm_source_mapping",
          "provider_family": "crm",
          "severity": "high",
          "assertion": "CRM bridge maps accounts, contacts, leads, deals, and duplicate keys deterministically."
        }
      ],
      "required_controls": [
        "Provider adapters must pass contract tests before production promotion.",
        "Webhook replay/idempotency tests must be run for e-sign, billing, CRM, and provider sync callbacks.",
        "Credential tests must use secret references and never expose raw secret material."
      ]
    },
    "provider_contract_test_runs": [],
    "provider_contract_test_summary": {
      "total_runs": 0,
      "by_status": {},
      "latest_status": null,
      "latest_run_id": null
    },
    "incident_response_plan": {
      "version": "2026-04-20.6",
      "mode": "incident_response_and_slo_evidence",
      "configured": {
        "incident_response_required": false,
        "slo_evidence_required": false,
        "pager_url_configured": false
      },
      "severity_model": [
        {
          "severity": "sev1",
          "target_ack_minutes": 5,
          "target_resolve_hours": 4,
          "examples": [
            "data exposure",
            "full outage",
            "payment/webhook corruption"
          ]
        },
        {
          "severity": "sev2",
          "target_ack_minutes": 15,
          "target_resolve_hours": 8,
          "examples": [
            "provider outage",
            "workflow backlog",
            "export failure"
          ]
        },
        {
          "severity": "sev3",
          "target_ack_minutes": 60,
          "target_resolve_hours": 48,
          "examples": [
            "degraded dashboard",
            "non-critical connector failure"
          ]
        }
      ],
      "runbooks": [
        "provider_outage",
        "failed_webhook",
        "queue_backlog",
        "stale_workflow_lock",
        "export_failure",
        "security_incident",
        "data_corruption"
      ]
    },
    "incidents": [],
    "incident_summary": {
      "total_incidents": 0,
      "by_status": {},
      "by_severity": {},
      "open": 0
    },
    "slo_snapshots": [
      {
        "id": "slo_0822ed650938",
        "window": "seed",
        "status": "within_target",
        "api_availability_pct": 99.95,
        "workflow_completion_pct": 99.0,
        "provider_webhook_backlog": 0,
        "data_quality_score": 100,
        "open_incidents": 0,
        "actor_id": "system",
        "tenant_id": "tenant_default",
        "created_at": "2026-07-09T19:05:10Z",
        "catalog_version": "2026-04-20.6"
      }
    ],
    "slo_summary": {
      "total_snapshots": 1,
      "latest_snapshot_id": "slo_0822ed650938",
      "latest_status": "within_target",
      "latest_api_availability_pct": 99.95,
      "latest_workflow_completion_pct": 99.0
    },
    "feature_flag_catalog": {
      "version": "2026-04-20.7",
      "mode": "audited_feature_flag_and_kill_switch_control",
      "configured": {
        "feature_flags_required": false,
        "policy_bundle_required": false
      },
      "required_controls": [
        "Every production-risk feature must have an owner, risk tier, default state, and rollback path.",
        "High-risk features must be gated by policy evaluation, MFA-backed operator access, and release-change approval.",
        "Flag changes must emit audit/outbox evidence and should be synchronized to the runtime configuration store.",
        "Compatibility flags should default to disabled in production."
      ],
      "default_flags": [
        {
          "key": "strict_tenant_scope",
          "name": "Strict tenant scope",
          "enabled": true,
          "category": "security",
          "description": "Fail closed when a record cannot be scoped to the requesting tenant.",
          "risk": "critical"
        },
        {
          "key": "async_exports_enforced",
          "name": "Async governed exports",
          "enabled": true,
          "category": "privacy",
          "description": "Require export jobs, expiration, checksums, and audit receipts for sensitive datasets.",
          "risk": "high"
        },
        {
          "key": "provider_live_mode",
          "name": "Live provider integrations",
          "enabled": false,
          "category": "integrations",
          "description": "Allow production provider adapters to call live external APIs.",
          "risk": "critical"
        },
        {
          "key": "agent_autonomy_limited",
          "name": "Limited agent autonomy",
          "enabled": false,
          "category": "ai_governance",
          "description": "Allow low-risk agent actions without manual approval while preserving policy receipts.",
          "risk": "critical"
        },
        {
          "key": "legacy_full_state_payload",
          "name": "Legacy full-state payload compatibility",
          "enabled": false,
          "category": "compatibility",
          "description": "Permit legacy clients to request broad state payloads outside role-filtered resources.",
          "risk": "high"
        },
        {
          "key": "break_glass_enabled",
          "name": "Emergency break-glass access",
          "enabled": true,
          "category": "security",
          "description": "Allow short-lived, MFA-backed emergency access sessions with audit and revocation evidence.",
          "risk": "critical"
        }
      ]
    },
    "feature_flags": [
      {
        "key": "strict_tenant_scope",
        "name": "Strict tenant scope",
        "enabled": true,
        "category": "security",
        "description": "Fail closed when a record cannot be scoped to the requesting tenant.",
        "risk": "critical",
        "id": "flag_5aa71898c1b3",
        "status": "active",
        "environment": "all",
        "owner": "platform_security",
        "created_at": "2026-07-09T19:05:10Z",
        "updated_at": "2026-07-09T19:05:10Z",
        "last_changed_by": "seed",
        "reason": "production baseline"
      },
      {
        "key": "async_exports_enforced",
        "name": "Async governed exports",
        "enabled": true,
        "category": "privacy",
        "description": "Require export jobs, expiration, checksums, and audit receipts for sensitive datasets.",
        "risk": "high",
        "id": "flag_bd96a5addcca",
        "status": "active",
        "environment": "all",
        "owner": "platform_security",
        "created_at": "2026-07-09T19:05:10Z",
        "updated_at": "2026-07-09T19:05:10Z",
        "last_changed_by": "seed",
        "reason": "production baseline"
      },
      {
        "key": "provider_live_mode",
        "name": "Live provider integrations",
        "enabled": false,
        "category": "integrations",
        "description": "Allow production provider adapters to call live external APIs.",
        "risk": "critical",
        "id": "flag_3857cf19b644",
        "status": "active",
        "environment": "all",
        "owner": "platform_security",
        "created_at": "2026-07-09T19:05:10Z",
        "updated_at": "2026-07-09T19:05:10Z",
        "last_changed_by": "seed",
        "reason": "production baseline"
      },
      {
        "key": "agent_autonomy_limited",
        "name": "Limited agent autonomy",
        "enabled": false,
        "category": "ai_governance",
        "description": "Allow low-risk agent actions without manual approval while preserving policy receipts.",
        "risk": "critical",
        "id": "flag_5c57da64907f",
        "status": "active",
        "environment": "all",
        "owner": "platform_security",
        "created_at": "2026-07-09T19:05:10Z",
        "updated_at": "2026-07-09T19:05:10Z",
        "last_changed_by": "seed",
        "reason": "production baseline"
      },
      {
        "key": "legacy_full_state_payload",
        "name": "Legacy full-state payload compatibility",
        "enabled": false,
        "category": "compatibility",
        "description": "Permit legacy clients to request broad state payloads outside role-filtered resources.",
        "risk": "high",
        "id": "flag_6c0e31cee4e1",
        "status": "active",
        "environment": "all",
        "owner": "platform_security",
        "created_at": "2026-07-09T19:05:10Z",
        "updated_at": "2026-07-09T19:05:10Z",
        "last_changed_by": "seed",
        "reason": "production baseline"
      },
      {
        "key": "break_glass_enabled",
        "name": "Emergency break-glass access",
        "enabled": true,
        "category": "security",
        "description": "Allow short-lived, MFA-backed emergency access sessions with audit and revocation evidence.",
        "risk": "critical",
        "id": "flag_8edac4efc595",
        "status": "active",
        "environment": "all",
        "owner": "platform_security",
        "created_at": "2026-07-09T19:05:10Z",
        "updated_at": "2026-07-09T19:05:10Z",
        "last_changed_by": "seed",
        "reason": "production baseline"
      }
    ],
    "feature_flag_summary": {
      "total_flags": 6,
      "enabled_flags": 3,
      "disabled_flags": 3,
      "critical_enabled_flags": 2
    },
    "dlp_control_plan": {
      "version": "2026-04-20.7",
      "mode": "pii_dlp_classification_and_secret_leak_prevention",
      "configured": {
        "dlp_scans_required": false,
        "object_store_configured": false,
        "secret_manager_configured": false
      },
      "classification_rules": [
        {
          "key": "email_address",
          "classification": "personal_data",
          "default_action": "classify_and_scope"
        },
        {
          "key": "phone_number",
          "classification": "personal_data",
          "default_action": "classify_and_scope"
        },
        {
          "key": "payment_card",
          "classification": "regulated_financial_data",
          "default_action": "block_and_remediate"
        },
        {
          "key": "national_identifier",
          "classification": "sensitive_personal_data",
          "default_action": "block_and_remediate"
        },
        {
          "key": "secret_material",
          "classification": "credential_secret",
          "default_action": "block_and_rotate"
        },
        {
          "key": "inline_export_artifact",
          "classification": "sensitive_artifact",
          "default_action": "move_to_object_store"
        }
      ],
      "required_controls": [
        "Run DLP scans before production release and before sensitive export enablement.",
        "Store export/contract artifacts in object storage and keep only metadata plus SHA-256 digests in application state.",
        "Persist only secret references, never provider credentials, tokens, or private keys.",
        "Treat finance, contract, and identity records as restricted collections with MFA-backed export authorization."
      ]
    },
    "dlp_scans": [],
    "dlp_scan_summary": {
      "total_scans": 0,
      "latest_scan_id": null,
      "latest_decision": null,
      "latest_finding_count": 0,
      "latest_blocking_finding_count": 0
    },
    "deployment_control_plan": {
      "version": "2026-04-21.28",
      "mode": "release_change_control_and_promotion_evidence",
      "configured": {
        "deployment_change_control_required": false,
        "release_manifest_required": false,
        "data_quality_gates_required": false,
        "dlp_scans_required": false,
        "provider_contract_tests_required": false,
        "billing_reconciliation_required": false,
        "consent_ledger_required": false,
        "resilience_drills_required": false,
        "identity_cutover_required": false,
        "tenant_activation_required": false,
        "evidence_vault_required": false,
        "provider_oauth_required": false,
        "api_consumer_governance_required": false,
        "sso_claim_mapping_required": false,
        "abuse_detection_required": false,
        "traffic_management_required": false,
        "rollback_execution_required": false,
        "data_contract_enforcement_required": false,
        "egress_gateway_required": false,
        "secret_rotation_campaigns_required": false,
        "payment_risk_controls_required": false,
        "oncall_coverage_required": false,
        "incident_postmortems_required": false,
        "data_backfill_required": false,
        "email_deliverability_required": false,
        "contract_obligations_required": false,
        "customer_health_governance_required": false,
        "knowledge_governance_required": false,
        "infrastructure_policy_required": false,
        "release_smoke_tests_required": false,
        "legal_hold_enforcement_required": false,
        "revenue_close_validation_required": false,
        "support_readiness_required": false,
        "data_integrity_required": false,
        "provider_sla_required": false,
        "tenant_lifecycle_required": false,
        "workflow_recovery_required": false,
        "release_acceptance_required": false
      },
      "required_controls": [
        "Production releases must have a change record with risk, target environment, release version, approver, and rollback plan.",
        "Promotion gates must reference release evidence, data-quality status, DLP status, consent/privacy status, billing reconciliation, provider contract-test status, incidents, resilience drills, and SLO snapshots.",
        "High and critical risk changes require explicit approval before promotion.",
        "Promotions must emit outbox/audit evidence so deployment activity is visible to SIEM and release records."
      ],
      "promotion_gates": [
        "release_manifest",
        "api_lifecycle",
        "data_quality",
        "dlp",
        "privacy_subject_rights",
        "privacy_requests",
        "tenant_entitlements",
        "network_perimeter",
        "maintenance_window",
        "vendor_risk",
        "revenue_recognition",
        "model_risk",
        "trust_evidence",
        "identity_cutover",
        "tenant_activation",
        "evidence_vault",
        "provider_oauth",
        "api_consumer_governance",
        "sso_claim_mapping",
        "abuse_detection",
        "traffic_management",
        "rollback_execution",
        "data_contract_enforcement",
        "egress_gateway",
        "secret_rotation_campaigns",
        "payment_risk_controls",
        "oncall_coverage",
        "incident_postmortems",
        "data_backfill",
        "email_deliverability",
        "contract_obligations",
        "customer_health_governance",
        "knowledge_governance",
        "infrastructure_policy",
        "release_smoke_tests",
        "legal_hold_enforcement",
        "revenue_close_validation",
        "support_readiness",
        "data_integrity",
        "provider_sla",
        "tenant_lifecycle",
        "workflow_recovery",
        "release_acceptance",
        "audit_export",
        "retention_execution",
        "entitlement_reconciliation",
        "contract_renewal_governance",
        "runtime_guardrails",
        "consent_ledger",
        "data_residency",
        "billing_reconciliation",
        "resilience_drill",
        "provider_contract_tests",
        "supply_chain",
        "backup_drill",
        "open_incidents",
        "slo_snapshot",
        "synthetic_monitoring",
        "artifact_lifecycle",
        "compliance_evidence",
        "rollback_plan"
      ]
    },
    "deployment_changes": [],
    "deployment_change_summary": {
      "total_changes": 0,
      "by_status": {},
      "latest_change_id": null,
      "latest_status": null
    },
    "synthetic_monitor_runs": [],
    "api_lifecycle_checks": [],
    "data_residency_assessments": [],
    "backup_drills": [],
    "supply_chain_scans": [],
    "compliance_evidence_packs": [],
    "billing_reconciliation_runs": [],
    "resilience_drill_runs": [],
    "data_residency_transfer_events": [],
    "tenant_entitlement_assessments": [],
    "network_posture_snapshots": [],
    "vendor_risk_assessments": [],
    "revenue_recognition_runs": [],
    "model_risk_assessments": [],
    "trust_evidence_shares": [],
    "identity_cutover_runs": [],
    "tenant_activation_runs": [],
    "provider_oauth_checks": [],
    "sso_claim_checks": [],
    "abuse_detection_scans": [],
    "traffic_routes": [],
    "rollback_runs": [],
    "data_contract_runs": [],
    "egress_policy_checks": [],
    "payment_risk_assessments": [],
    "oncall_coverage_checks": [],
    "data_backfill_runs": [],
    "email_deliverability_assessments": [],
    "customer_health_assessments": [],
    "infrastructure_policy_checks": [],
    "release_smoke_test_runs": [],
    "legal_hold_enforcement_runs": [],
    "revenue_close_validations": [],
    "support_readiness_runs": [],
    "data_integrity_runs": [],
    "provider_sla_assessments": [],
    "tenant_lifecycle_runs": [],
    "workflow_recovery_drills": [],
    "release_acceptance_packs": [],
    "audit_export_batches": [],
    "retention_execution_runs": [],
    "entitlement_reconciliation_runs": [],
    "contract_renewal_reviews": [],
    "runtime_guardrail_checks": [],
    "latest_promotion_evidence": {
      "version": "2026-04-21.28",
      "release_version": "7.35.0",
      "target_environment": "development",
      "generated_at": "2026-07-27T15:37:40Z",
      "release_manifest_present": true,
      "latest_api_lifecycle_check": null,
      "latest_dlp_scan": null,
      "latest_data_quality_run": null,
      "latest_contract_test_run": null,
      "latest_slo_snapshot": {
        "id": "slo_0822ed650938",
        "status": "within_target"
      },
      "latest_synthetic_monitor_run": null,
      "latest_data_residency_assessment": null,
      "latest_data_transfer_event": null,
      "latest_billing_reconciliation_run": null,
      "latest_resilience_drill_run": null,
      "consent_summary": {
        "total_events": 0,
        "by_action": {},
        "by_channel": {},
        "suppressed_contacts": 0,
        "opted_out_contacts": 0,
        "latest_event_id": null
      },
      "latest_backup_drill": null,
      "latest_supply_chain_scan": null,
      "latest_compliance_evidence_pack": null,
      "artifact_summary": {
        "total_artifacts": 0,
        "by_status": {},
        "by_classification": {},
        "pending_malware_scans": 0,
        "missing_checksum_count": 0,
        "access_event_count": 0
      },
      "privacy_subject_summary": {
        "total_requests": 0,
        "by_status": {},
        "by_type": {},
        "overdue_requests": 0,
        "latest_request_at": null
      },
      "privacy_request_summary": {
        "total_requests": 0,
        "by_status": {},
        "by_type": {},
        "latest_request_at": null
      },
      "latest_entitlement_assessment": null,
      "latest_network_posture_snapshot": null,
      "maintenance_window_summary": {
        "total_windows": 0,
        "by_status": {},
        "active_freeze_windows": 0,
        "latest_window_at": null
      },
      "latest_vendor_risk_assessment": null,
      "latest_revenue_recognition_run": null,
      "latest_model_risk_assessment": null,
      "latest_trust_evidence_share": null,
      "latest_identity_cutover_run": null,
      "latest_tenant_activation_run": null,
      "evidence_vault_summary": {
        "total_records": 0,
        "by_status": {},
        "by_classification": {},
        "latest_record_at": null
      },
      "latest_provider_oauth_check": null,
      "api_consumer_summary": {
        "total_consumers": 0,
        "active_consumers": 0,
        "revoked_consumers": 0,
        "by_status": {},
        "by_type": {},
        "latest_created_at": null
      },
      "latest_sso_claim_check": null,
      "latest_abuse_detection_scan": null,
      "latest_traffic_route": null,
      "latest_rollback_run": null,
      "latest_data_contract_run": null,
      "latest_egress_policy_check": null,
      "secret_rotation_summary": {
        "total_campaigns": 0,
        "open_campaigns": 0,
        "completed_campaigns": 0,
        "blocked_campaigns": 0,
        "by_status": {},
        "by_scope": {}
      },
      "latest_payment_risk_assessment": null,
      "latest_oncall_coverage_check": null,
      "incident_postmortem_summary": {
        "total_postmortems": 0,
        "open_postmortems": 0,
        "completed_postmortems": 0,
        "open_action_items": 0,
        "by_status": {},
        "by_severity": {}
      },
      "latest_data_backfill_run": null,
      "latest_email_deliverability_assessment": null,
      "contract_obligation_summary": {
        "total_obligations": 0,
        "open_obligations": 0,
        "completed_obligations": 0,
        "overdue_obligations": 0,
        "by_status": {}
      },
      "latest_customer_health_assessment": null,
      "knowledge_governance_summary": {
        "total_reviews": 0,
        "approved_reviews": 0,
        "blocked_reviews": 0,
        "pending_reviews": 0,
        "by_status": {},
        "latest_article_ref": null
      },
      "latest_infrastructure_policy_check": null,
      "latest_release_smoke_test_run": null,
      "latest_legal_hold_enforcement_run": null,
      "latest_revenue_close_validation": null,
      "latest_support_readiness_run": null,
      "latest_data_integrity_run": null,
      "latest_provider_sla_assessment": null,
      "latest_tenant_lifecycle_run": null,
      "latest_workflow_recovery_drill": null,
      "latest_release_acceptance_pack": null,
      "latest_audit_export_batch": null,
      "latest_retention_execution_run": null,
      "latest_entitlement_reconciliation_run": null,
      "latest_contract_renewal_review": null,
      "latest_runtime_guardrail_check": null,
      "open_incident_count": 0,
      "blockers": [],
      "warnings": [
        {
          "gate": "api_lifecycle",
          "message": "No API lifecycle compatibility check has been captured."
        },
        {
          "gate": "dlp",
          "message": "No DLP scan has been captured for this state."
        },
        {
          "gate": "data_quality",
          "message": "No data-quality run has been captured for this state."
        },
        {
          "gate": "data_residency",
          "message": "No data residency assessment has been captured."
        },
        {
          "gate": "billing_reconciliation",
          "message": "No billing reconciliation run has been captured."
        },
        {
          "gate": "resilience_drill",
          "message": "No operational resilience drill has been captured."
        },
        {
          "gate": "provider_contract_tests",
          "message": "No provider contract-test run has been captured."
        },
        {
          "gate": "slo_snapshot",
          "message": "Latest SLO status is degraded.",
          "snapshot_id": "slo_0822ed650938",
          "status": "within_target"
        },
        {
          "gate": "supply_chain",
          "message": "No supply-chain/SBOM scan has been captured."
        },
        {
          "gate": "backup_drill",
          "message": "No backup drill has been captured."
        },
        {
          "gate": "compliance_evidence",
          "message": "No compliance evidence pack has been generated."
        },
        {
          "gate": "synthetic_monitoring",
          "message": "No synthetic monitor run captured."
        },
        {
          "gate": "tenant_entitlements",
          "message": "No tenant entitlement/quota assessment has been captured."
        },
        {
          "gate": "network_perimeter",
          "message": "No network perimeter posture snapshot has been captured."
        },
        {
          "gate": "vendor_risk",
          "message": "No vendor-risk assessment has been captured for live providers."
        },
        {
          "gate": "revenue_recognition",
          "message": "No revenue-recognition check has been captured."
        },
        {
          "gate": "model_risk",
          "message": "No model/agent risk assessment has been captured."
        },
        {
          "gate": "trust_evidence",
          "message": "No customer trust-evidence share has been captured."
        },
        {
          "gate": "identity_cutover",
          "message": "No identity-provider cutover rehearsal has been captured."
        },
        {
          "gate": "evidence_vault",
          "message": "No evidence vault records have been sealed for this release."
        },
        {
          "gate": "provider_oauth",
          "message": "No provider OAuth health check has been captured."
        },
        {
          "gate": "api_consumer_governance",
          "message": "No active API consumer credentials are registered for production traffic."
        },
        {
          "gate": "sso_claim_mapping",
          "message": "No SSO claim mapping verification has been captured."
        },
        {
          "gate": "abuse_detection",
          "message": "No abuse detection scan has been captured."
        },
        {
          "gate": "rollback_execution",
          "message": "No rollback execution rehearsal has been captured."
        },
        {
          "gate": "data_contract_enforcement",
          "message": "No data-contract enforcement run has been captured."
        },
        {
          "gate": "egress_gateway",
          "message": "No provider egress policy check has been captured."
        },
        {
          "gate": "payment_risk_controls",
          "message": "No payment-risk assessment has been captured."
        },
        {
          "gate": "oncall_coverage",
          "message": "No on-call coverage check has been captured."
        },
        {
          "gate": "data_backfill",
          "message": "No production data backfill/remediation run has been captured."
        },
        {
          "gate": "email_deliverability",
          "message": "No email deliverability assessment has been captured."
        },
        {
          "gate": "customer_health_governance",
          "message": "No customer health assessment has been captured."
        },
        {
          "gate": "infrastructure_policy",
          "message": "No infrastructure policy check has been captured."
        },
        {
          "gate": "release_smoke_tests",
          "message": "No release smoke-test run has been captured."
        },
        {
          "gate": "legal_hold_enforcement",
          "message": "No legal-hold enforcement run has been captured."
        },
        {
          "gate": "revenue_close_validation",
          "message": "No revenue closeout validation has been captured."
        },
        {
          "gate": "support_readiness",
          "message": "No customer support readiness run has been captured."
        },
        {
          "gate": "data_integrity",
          "message": "No data-integrity run has been captured."
        },
        {
          "gate": "provider_sla",
          "message": "No provider SLA assessment has been captured."
        },
        {
          "gate": "tenant_lifecycle",
          "message": "No tenant lifecycle run has been captured."
        },
        {
          "gate": "workflow_recovery",
          "message": "No workflow recovery drill has been captured."
        },
        {
          "gate": "release_acceptance",
          "message": "No release acceptance pack has been captured."
        },
        {
          "gate": "audit_export",
          "message": "No audit export batch evidence has been captured."
        },
        {
          "gate": "retention_execution",
          "message": "No retention execution run has been captured."
        },
        {
          "gate": "entitlement_reconciliation",
          "message": "No entitlement reconciliation run has been captured."
        },
        {
          "gate": "contract_renewal_governance",
          "message": "No contract renewal governance review has been captured."
        },
        {
          "gate": "runtime_guardrails",
          "message": "No runtime guardrail check has been captured."
        }
      ],
      "decision": "eligible_with_warnings"
    },
    "scheduler_plan": {
      "version": "2026-04-21.28",
      "mode": "scheduled_operations_control_and_run_evidence",
      "configured": {
        "scheduler_required": false,
        "redis_configured": false,
        "metrics_enabled": true
      },
      "required_controls": [
        "Production operational jobs must be scheduled outside request handlers and must record run evidence.",
        "Outbox, DLP, retention, consent, data-quality, billing reconciliation, SLO, provider contract-test, resilience, and recovery jobs require owner and cadence evidence.",
        "Workers must be idempotent, emit audit/outbox evidence, and expose failures to incident response."
      ],
      "tasks": [
        {
          "key": "outbox_drain",
          "cadence": "every_minute",
          "domain": "runtime",
          "required_external": "redis_worker"
        },
        {
          "key": "data_quality_scan",
          "cadence": "daily",
          "domain": "data_quality",
          "required_external": "scheduler"
        },
        {
          "key": "dlp_scan",
          "cadence": "daily",
          "domain": "privacy",
          "required_external": "scheduler"
        },
        {
          "key": "retention_scan",
          "cadence": "daily",
          "domain": "privacy",
          "required_external": "scheduler"
        },
        {
          "key": "provider_contract_tests",
          "cadence": "before_release",
          "domain": "integrations",
          "required_external": "ci"
        },
        {
          "key": "slo_snapshot",
          "cadence": "hourly",
          "domain": "observability",
          "required_external": "monitoring"
        },
        {
          "key": "recovery_point",
          "cadence": "daily",
          "domain": "recovery",
          "required_external": "backup_orchestrator"
        },
        {
          "key": "synthetic_monitor",
          "cadence": "every_5_minutes",
          "domain": "observability",
          "required_external": "monitoring"
        },
        {
          "key": "api_lifecycle_check",
          "cadence": "before_release",
          "domain": "api",
          "required_external": "ci"
        },
        {
          "key": "data_residency_assessment",
          "cadence": "daily",
          "domain": "privacy",
          "required_external": "scheduler"
        },
        {
          "key": "backup_drill",
          "cadence": "monthly",
          "domain": "resilience",
          "required_external": "backup_orchestrator"
        },
        {
          "key": "supply_chain_scan",
          "cadence": "every_release",
          "domain": "security",
          "required_external": "ci"
        },
        {
          "key": "compliance_evidence_pack",
          "cadence": "before_audit_or_release",
          "domain": "compliance",
          "required_external": "release_manager"
        },
        {
          "key": "consent_ledger_review",
          "cadence": "daily",
          "domain": "privacy",
          "required_external": "scheduler"
        },
        {
          "key": "billing_reconciliation",
          "cadence": "daily",
          "domain": "finance",
          "required_external": "scheduler"
        },
        {
          "key": "resilience_drill",
          "cadence": "monthly",
          "domain": "resilience",
          "required_external": "incident_manager"
        },
        {
          "key": "privacy_subject_rights_review",
          "cadence": "daily",
          "domain": "privacy",
          "required_external": "scheduler"
        },
        {
          "key": "tenant_entitlement_assessment",
          "cadence": "daily",
          "domain": "tenancy",
          "required_external": "scheduler"
        },
        {
          "key": "network_posture_snapshot",
          "cadence": "before_release",
          "domain": "security",
          "required_external": "release_manager"
        },
        {
          "key": "vendor_risk_assessment",
          "cadence": "before_provider_go_live",
          "domain": "security",
          "required_external": "security_review"
        },
        {
          "key": "revenue_recognition_check",
          "cadence": "month_end",
          "domain": "finance",
          "required_external": "finance_close"
        },
        {
          "key": "model_risk_assessment",
          "cadence": "before_ai_release",
          "domain": "ai_governance",
          "required_external": "model_governance"
        },
        {
          "key": "identity_cutover_rehearsal",
          "cadence": "before_release",
          "domain": "security",
          "required_external": "identity_admin"
        },
        {
          "key": "tenant_activation_check",
          "cadence": "before_customer_go_live",
          "domain": "tenancy",
          "required_external": "customer_ops"
        },
        {
          "key": "evidence_vault_seal",
          "cadence": "every_release",
          "domain": "audit",
          "required_external": "evidence_vault"
        },
        {
          "key": "provider_oauth_health",
          "cadence": "daily",
          "domain": "integrations",
          "required_external": "provider_admin"
        },
        {
          "key": "api_consumer_review",
          "cadence": "daily",
          "domain": "security",
          "required_external": "api_gateway"
        },
        {
          "key": "sso_claim_mapping_check",
          "cadence": "before_release",
          "domain": "security",
          "required_external": "identity_admin"
        },
        {
          "key": "abuse_detection_scan",
          "cadence": "hourly",
          "domain": "security",
          "required_external": "siem_or_api_gateway"
        },
        {
          "key": "traffic_route_review",
          "cadence": "during_release",
          "domain": "deployment",
          "required_external": "traffic_controller"
        },
        {
          "key": "rollback_execution_rehearsal",
          "cadence": "before_release",
          "domain": "deployment",
          "required_external": "release_manager"
        },
        {
          "key": "data_backfill_run",
          "cadence": "before_database_cutover",
          "domain": "data",
          "required_external": "database_worker"
        },
        {
          "key": "email_deliverability_assessment",
          "cadence": "before_email_go_live",
          "domain": "customer",
          "required_external": "email_provider"
        },
        {
          "key": "contract_obligation_review",
          "cadence": "daily",
          "domain": "contracts",
          "required_external": "contract_repository"
        },
        {
          "key": "customer_health_assessment",
          "cadence": "daily",
          "domain": "customer",
          "required_external": "customer_success_system"
        },
        {
          "key": "knowledge_governance_review",
          "cadence": "weekly",
          "domain": "ops",
          "required_external": "knowledge_base"
        },
        {
          "key": "infrastructure_policy_check",
          "cadence": "before_release",
          "domain": "infrastructure",
          "required_external": "iac_policy_engine"
        },
        {
          "key": "release_smoke_test",
          "cadence": "every_release",
          "domain": "release",
          "required_external": "smoke_test_runner"
        },
        {
          "key": "legal_hold_enforcement",
          "cadence": "before_retention_jobs",
          "domain": "privacy",
          "required_external": "evidence_vault"
        },
        {
          "key": "revenue_close_validation",
          "cadence": "before_closeout_automation",
          "domain": "revenue",
          "required_external": "release_manager"
        },
        {
          "key": "support_readiness",
          "cadence": "before_customer_go_live",
          "domain": "customer",
          "required_external": "support_system"
        },
        {
          "key": "data_integrity_scan",
          "cadence": "before_release",
          "domain": "data",
          "required_external": "database_worker"
        },
        {
          "key": "provider_sla_assessment",
          "cadence": "daily",
          "domain": "integrations",
          "required_external": "provider_monitoring"
        },
        {
          "key": "tenant_lifecycle_review",
          "cadence": "before_customer_go_live",
          "domain": "tenancy",
          "required_external": "tenant_admin"
        },
        {
          "key": "workflow_recovery_drill",
          "cadence": "before_release",
          "domain": "workflow",
          "required_external": "workflow_worker"
        },
        {
          "key": "release_acceptance_pack",
          "cadence": "every_release",
          "domain": "release",
          "required_external": "release_manager"
        },
        {
          "key": "audit_export_batch",
          "cadence": "hourly",
          "domain": "audit",
          "required_external": "siem_or_evidence_vault"
        },
        {
          "key": "retention_execution_review",
          "cadence": "daily",
          "domain": "privacy",
          "required_external": "privacy_worker"
        },
        {
          "key": "entitlement_reconciliation",
          "cadence": "daily",
          "domain": "tenancy",
          "required_external": "billing_system"
        },
        {
          "key": "contract_renewal_review",
          "cadence": "daily",
          "domain": "contracts",
          "required_external": "contract_repository"
        },
        {
          "key": "runtime_guardrail_check",
          "cadence": "before_runtime_release",
          "domain": "runtime",
          "required_external": "workflow_worker"
        }
      ]
    },
    "scheduler_runs": [],
    "scheduler_summary": {
      "total_runs": 0,
      "by_status": {},
      "latest_run_id": null,
      "latest_status": null
    },
    "service_account_plan": {
      "version": "2026-04-20.8",
      "mode": "service_account_and_api_credential_governance",
      "configured": {
        "service_accounts_required": false,
        "api_auth_required": false,
        "secret_manager_configured": false,
        "token_rotation_days": 90
      },
      "allowed_scopes": [
        "admin:read",
        "artifacts:read",
        "artifacts:write",
        "contracts:write",
        "crm:read",
        "crm:write",
        "exports:read",
        "providers:manage",
        "quotes:write",
        "runtime:drain",
        "security:evidence",
        "webhooks:replay"
      ],
      "required_controls": [
        "Service-account credentials are represented as managed secret references, never as plaintext tokens in application state.",
        "Every service account must be tenant-scoped, purpose-bound, scope-limited, and auditable.",
        "Credential rotation and revocation must produce immutable audit/outbox evidence.",
        "Production machine-to-machine integrations must use service accounts or OIDC workload identity instead of shared human API keys."
      ]
    },
    "service_accounts": [],
    "service_account_events": [],
    "service_account_summary": {
      "total_accounts": 0,
      "by_status": {},
      "active_accounts": 0,
      "revoked_accounts": 0,
      "stale_token_count": 0,
      "event_count": 0
    },
    "artifact_lifecycle_plan": {
      "version": "2026-04-20.8",
      "mode": "object_storage_artifact_lifecycle_and_integrity_evidence",
      "configured": {
        "object_store_configured": false,
        "object_artifacts_required": false,
        "default_retention_days": 365
      },
      "required_controls": [
        "Large exports, contracts, audit bundles, provider payloads, and recovery manifests must live in object storage, not inline JSON state.",
        "Every persisted artifact must have checksum, content type, classification, tenant, retention, and malware-scan evidence.",
        "Sensitive artifacts must expire or be retained under legal hold policy, with access/download activity auditable.",
        "Production object keys must point to managed storage such as S3/GCS/Azure Blob with encryption and lifecycle policies."
      ],
      "classifications": [
        "confidential",
        "internal",
        "public",
        "regulated",
        "restricted"
      ],
      "artifact_types": [
        "audit_bundle",
        "contract",
        "customer_document",
        "export",
        "invoice",
        "other",
        "provider_payload",
        "recovery_manifest",
        "release_manifest"
      ]
    },
    "object_artifacts": [],
    "artifact_access_events": [],
    "artifact_summary": {
      "total_artifacts": 0,
      "by_status": {},
      "by_classification": {},
      "pending_malware_scans": 0,
      "missing_checksum_count": 0,
      "access_event_count": 0
    },
    "webhook_replay_plan": {
      "version": "2026-04-20.8",
      "mode": "signed_webhook_replay_and_dead_letter_governance",
      "configured": {
        "webhook_replay_required": false,
        "webhook_signature_required": false,
        "queue_configured": false,
        "outbox_required": false
      },
      "required_controls": [
        "Duplicate provider webhooks must be idempotent and replay-safe by provider, event ID, and payload fingerprint.",
        "Failed webhook processing must move to a reviewable dead-letter/replay path with actor, reason, and tenant evidence.",
        "Replay jobs must never bypass signature verification evidence; production replay should enqueue worker-owned delivery work.",
        "Replay attempts must create audit and outbox records so provider incidents can be reconstructed."
      ],
      "allowed_modes": [
        "dry_run",
        "queued",
        "replay_compatibility"
      ]
    },
    "webhook_replay_jobs": [],
    "webhook_replay_summary": {
      "total_jobs": 0,
      "by_status": {},
      "failed_or_unverified_receipt_count": 0,
      "latest_job_id": null
    },
    "synthetic_monitor_plan": {
      "version": "2026-04-20.10",
      "mode": "synthetic_canary_and_runtime_assurance_evidence",
      "configured": {
        "synthetic_monitoring_required": false,
        "metrics_enabled": true,
        "scheduler_required": false
      },
      "required_controls": [
        "Production must continuously probe health, readiness, OpenAPI availability, outbox backlog, DLP evidence, and deployment gates.",
        "Synthetic monitor results must be retained as release and incident evidence with tenant and actor context.",
        "Failed critical probes should page incident response and block production promotion until resolved.",
        "Canary checks must be safe, side-effect free, and runnable from private monitoring infrastructure."
      ],
      "default_probes": [
        {
          "key": "healthz",
          "domain": "api",
          "severity": "critical"
        },
        {
          "key": "readiness",
          "domain": "api",
          "severity": "critical"
        },
        {
          "key": "openapi_contract",
          "domain": "api",
          "severity": "high"
        },
        {
          "key": "outbox_backlog",
          "domain": "runtime",
          "severity": "high"
        },
        {
          "key": "dlp_latest",
          "domain": "privacy",
          "severity": "medium"
        },
        {
          "key": "deployment_gate",
          "domain": "release",
          "severity": "high"
        },
        {
          "key": "api_lifecycle_latest",
          "domain": "api",
          "severity": "medium"
        },
        {
          "key": "data_residency_latest",
          "domain": "privacy",
          "severity": "medium"
        },
        {
          "key": "supply_chain_latest",
          "domain": "security",
          "severity": "medium"
        }
      ]
    },
    "synthetic_monitor_summary": {
      "total_runs": 0,
      "by_status": {},
      "latest_run_id": null,
      "latest_status": null,
      "latest_failed_probe_count": 0
    },
    "api_lifecycle_plan": {
      "version": "2026-04-20.10",
      "mode": "api_versioning_deprecation_and_backward_compatibility_governance",
      "current_version": "v1",
      "application_version": "7.35.0",
      "configured": {
        "api_lifecycle_required": false,
        "api_deprecation_notice_days": 180,
        "openapi_version": "3.1.0"
      },
      "required_controls": [
        "Every public API route must be represented in OpenAPI and assigned an API lifecycle state.",
        "Breaking changes require deprecation windows, release evidence, compatibility checks, and customer-facing migration notes.",
        "Critical revenue and control-plane routes must remain stable across releases unless a replacement route is active.",
        "Compatibility checks must run in CI and before deployment promotion."
      ],
      "lifecycle_states": [
        "active",
        "deprecated",
        "sunset_scheduled",
        "internal_only"
      ],
      "critical_routes": [
        "/api/export-jobs",
        "/api/openapi.json",
        "/api/state",
        "/api/system/api-lifecycle",
        "/api/system/readiness",
        "/api/system/release-evidence",
        "/healthz",
        "/readyz"
      ]
    },
    "api_lifecycle_summary": {
      "total_checks": 0,
      "by_status": {},
      "latest_check_id": null,
      "latest_status": null,
      "latest_missing_critical_route_count": 0
    },
    "data_residency_plan": {
      "version": "2026-04-20.10",
      "mode": "tenant_data_residency_and_cross_region_transfer_control",
      "configured": {
        "data_residency_required": false,
        "cross_border_export_review_required": false,
        "default_data_region": "US",
        "allowed_data_regions": [
          "AU",
          "CA",
          "EU",
          "UK",
          "US"
        ],
        "database_configured": false,
        "object_store_configured": false
      },
      "required_controls": [
        "Every tenant must have a declared home data region before production onboarding.",
        "Cross-region transfers must record purpose, data class, source, destination, legal basis, and approver evidence.",
        "Restricted financial, PII, regulated, and immutable audit data must fail closed unless the destination region is approved and a legal basis is recorded.",
        "Data residency policy must apply equally to database rows, object artifacts, webhook payloads, exports, backups, and analytics syncs."
      ],
      "restricted_data_classes": [
        "confidential_pii",
        "immutable_restricted_audit",
        "regulated",
        "restricted_financial"
      ],
      "approved_legal_basis": [
        "consent",
        "contract",
        "controller_approved",
        "legal_obligation",
        "legitimate_interest",
        "processor_dpa"
      ]
    },
    "data_residency_summary": {
      "total_assessments": 0,
      "blocked_assessments": 0,
      "by_status": {},
      "by_decision": {},
      "latest_assessment_id": null,
      "latest_decision": null,
      "latest_finding_count": 0,
      "total_transfer_events": 0,
      "blocked_transfer_events": 0,
      "transfer_events_by_status": {},
      "transfer_events_by_target_region": {}
    },
    "consent_control_plan": {
      "version": "2026-04-20.10",
      "mode": "consent_preference_and_suppression_evidence",
      "configured": {
        "consent_ledger_required": false,
        "retention_scans_required": false,
        "dlp_scans_required": false
      },
      "supported_channels": [
        "email",
        "linkedin",
        "phone",
        "sms",
        "whatsapp"
      ],
      "supported_actions": [
        "grant",
        "request_delete",
        "request_export",
        "request_review",
        "revoke",
        "suppress",
        "unsuppress"
      ],
      "required_controls": [
        "Consent changes must create a ledger event with actor, source, lawful basis, channel, and subject reference.",
        "Suppression should fail closed for outbound workflows until explicitly unsuppressed with evidence.",
        "Privacy requests must preserve legal-hold and audit evidence while propagating safe redaction/deletion tasks to workers.",
        "Production consent records must be tenant-scoped and exported only through governed export jobs."
      ]
    },
    "consent_events": [],
    "consent_summary": {
      "total_events": 0,
      "by_action": {},
      "by_channel": {},
      "suppressed_contacts": 0,
      "opted_out_contacts": 0,
      "latest_event_id": null
    },
    "billing_reconciliation_plan": {
      "version": "2026-04-20.10",
      "mode": "invoice_payment_settlement_reconciliation_control",
      "configured": {
        "billing_reconciliation_required": false,
        "database_configured": false,
        "outbox_required": false
      },
      "required_controls": [
        "Executed contracts must have invoice evidence before revenue closeout.",
        "Paid invoices must reconcile to provider payment and settlement evidence before payout/recognition is marked complete.",
        "Duplicate provider payments, stale open invoices, and missing settlement batches must create findings and outbox remediation events.",
        "Production reconciliation jobs should run through workers and preserve immutable finance/audit evidence."
      ],
      "supported_modes": [
        "dry_run",
        "queue_adjustments",
        "record_only"
      ]
    },
    "billing_reconciliation_summary": {
      "total_runs": 0,
      "by_decision": {},
      "latest_run_id": null,
      "latest_decision": null,
      "latest_finding_count": 0
    },
    "resilience_drill_plan": {
      "version": "2026-04-20.10",
      "mode": "operational_resilience_game_day_and_failure_drill_evidence",
      "configured": {
        "resilience_drills_required": false,
        "incident_response_required": false,
        "backup_plan_required": false,
        "scheduler_required": false
      },
      "scenarios": [
        {
          "key": "database_restore",
          "domain": "recovery",
          "expected_controls": [
            "recovery_points",
            "restore_validations",
            "slo_snapshots"
          ]
        },
        {
          "key": "duplicate_webhook",
          "domain": "webhooks",
          "expected_controls": [
            "signed_webhook_receipts",
            "idempotency_ledger",
            "webhook_replay"
          ]
        },
        {
          "key": "object_store_loss",
          "domain": "artifacts",
          "expected_controls": [
            "object_artifacts",
            "artifact_verify",
            "recovery_points"
          ]
        },
        {
          "key": "provider_outage",
          "domain": "integrations",
          "expected_controls": [
            "provider_contract_tests",
            "incident_response",
            "outbox_retries"
          ]
        },
        {
          "key": "queue_backlog",
          "domain": "runtime",
          "expected_controls": [
            "outbox_summary",
            "scheduler_runs",
            "worker_drain"
          ]
        },
        {
          "key": "stale_workflow_lock",
          "domain": "workflow",
          "expected_controls": [
            "workflow_locks",
            "recovery_points",
            "incident_response"
          ]
        }
      ],
      "supported_modes": [
        "game_day",
        "record_only",
        "release_gate"
      ],
      "required_controls": [
        "Production operators must run recurring game-day drills for provider outage, duplicate webhooks, queue backlog, stale locks, object storage loss, and database restore.",
        "Every drill must record observed controls, gaps, owner, tenant, decision, and follow-up evidence.",
        "Release gates should block when critical resilience scenarios have never passed or when latest drill evidence is stale."
      ]
    },
    "resilience_drill_summary": {
      "total_runs": 0,
      "by_scenario": {},
      "by_decision": {},
      "latest_run_id": null,
      "latest_decision": null,
      "latest_gap_count": 0
    },
    "backup_drill_plan": {
      "version": "2026-04-20.10",
      "mode": "backup_restore_rehearsal_and_rto_rpo_evidence",
      "configured": {
        "backup_drill_required": false,
        "backup_rto_minutes": 240,
        "backup_rpo_minutes": 60,
        "object_store_configured": false,
        "database_configured": false
      },
      "required_controls": [
        "Production backup drills must validate database, object artifacts, audit logs, and recovery-point manifests on a cadence.",
        "Restore rehearsals must record measured RTO/RPO, state digest evidence, and known gaps.",
        "Legal holds and retention windows must be preserved during backup restore and purge workflows.",
        "Failed drills must create incident/change evidence before production promotion."
      ],
      "drill_modes": [
        "tabletop",
        "manifest_validate",
        "restore_rehearsal"
      ]
    },
    "backup_drill_summary": {
      "total_drills": 0,
      "by_status": {},
      "latest_drill_id": null,
      "latest_status": null,
      "latest_rto_minutes": null,
      "latest_rpo_minutes": null
    },
    "supply_chain_plan": {
      "version": "2026-04-20.10",
      "mode": "sbom_dependency_release_artifact_and_supply_chain_evidence",
      "configured": {
        "supply_chain_required": false,
        "sbom_required": false,
        "release_manifest_required": false
      },
      "required_controls": [
        "Every release must include deterministic file hashes and an SBOM/dependency inventory.",
        "Dependencies should be version-pinned and reviewed before production promotion.",
        "Release-critical scripts, migrations, and security-control services must be represented in the release manifest.",
        "Supply-chain scans should run in CI and generate evidence for compliance packs and deployment gates."
      ]
    },
    "supply_chain_summary": {
      "total_scans": 0,
      "by_status": {},
      "latest_scan_id": null,
      "latest_status": null,
      "latest_finding_count": 0,
      "latest_package_count": 0
    },
    "compliance_evidence_plan": {
      "version": "2026-04-20.10",
      "mode": "compliance_control_mapping_and_evidence_pack_generation",
      "configured": {
        "compliance_evidence_required": false,
        "audit_log_configured": true,
        "metrics_enabled": true
      },
      "required_controls": [
        "Security, availability, confidentiality, privacy, and change-management controls must map to concrete product evidence.",
        "Evidence packs must include control status, source collections, generated timestamps, actors, tenant scope, and release version.",
        "Missing or stale control evidence must be represented as gaps instead of silent pass decisions.",
        "Evidence packs are operational artifacts; they are not a substitute for legal, privacy, or audit professional review."
      ],
      "frameworks": [
        "soc2_security",
        "soc2_availability",
        "gdpr_privacy",
        "iso27001_foundation"
      ]
    },
    "compliance_evidence_summary": {
      "total_packs": 0,
      "by_decision": {},
      "latest_pack_id": null,
      "latest_decision": null,
      "latest_gap_count": 0
    },
    "kms_control_plan": {
      "version": "2026-04-20.10",
      "mode": "managed_key_and_encryption_governance",
      "configured": {
        "kms_controls_required": false,
        "data_encryption_required": false,
        "kms_provider_configured": false,
        "secret_manager_configured": false,
        "rotation_days": 365
      },
      "allowed_purposes": [
        "artifact_encryption",
        "audit_signing",
        "backup_encryption",
        "data_encryption",
        "token_wrapping",
        "webhook_signing"
      ],
      "required_controls": [
        "Application state may only store key aliases and KMS references, never plaintext key material.",
        "Every restricted artifact, export, backup, token wrapper, and webhook signing key must be tenant-scoped and auditable.",
        "Key creation and rotation must emit audit and outbox evidence before production use.",
        "Production readiness should block unless a managed KMS or cloud key provider is configured."
      ]
    },
    "kms_keys": [],
    "kms_key_events": [],
    "kms_key_summary": {
      "total_keys": 0,
      "by_status": {},
      "active_keys": 0,
      "retired_keys": 0,
      "stale_key_count": 0,
      "event_count": 0
    },
    "vulnerability_management_plan": {
      "version": "2026-04-20.10",
      "mode": "configuration_dependency_and_release_vulnerability_evidence",
      "configured": {
        "vulnerability_scans_required": false,
        "dependency_scans_required": false,
        "release_manifest_required": false,
        "environment": "development"
      },
      "scopes": [
        "all",
        "dependencies",
        "release_artifact",
        "runtime_config"
      ],
      "required_controls": [
        "Run vulnerability scans before release promotion and after security-relevant configuration changes.",
        "Treat default secrets, open APIs, missing KMS, missing signed webhooks, and unconfigured durable persistence as blocking production findings.",
        "Attach dependency and release-manifest evidence to every deployment change record.",
        "Escalate critical/high findings to incident response or change-control before customer production traffic."
      ]
    },
    "vulnerability_scans": [],
    "vulnerability_scan_summary": {
      "total_scans": 0,
      "by_status": {},
      "latest_status": null,
      "latest_decision": null,
      "latest_blocking_findings": 0,
      "latest_critical_findings": 0
    },
    "configuration_baseline_plan": {
      "version": "2026-04-20.10",
      "mode": "runtime_configuration_drift_baseline",
      "profiles": [
        "local_compatibility",
        "production",
        "regulated_production",
        "staging"
      ],
      "configured": {
        "configuration_baseline_required": false,
        "environment": "development",
        "kms_controls_required": false,
        "vulnerability_scans_required": false,
        "evidence_seals_required": false
      },
      "required_controls_by_profile": {
        "local_compatibility": [
          "runtime_environment",
          "migration_manifest",
          "release_manifest",
          "audit_log"
        ],
        "staging": [
          "runtime_environment",
          "secret_key",
          "api_auth_gate",
          "database",
          "queue_backend",
          "object_storage",
          "secret_manager",
          "identity_provider",
          "allowed_origins",
          "csrf_protection",
          "signed_webhooks",
          "migration_manifest",
          "release_manifest",
          "tenant_isolation",
          "outbox_delivery",
          "rate_limiting",
          "kms_controls",
          "vulnerability_scans"
        ],
        "production": [
          "runtime_environment",
          "secret_key",
          "api_auth_gate",
          "database",
          "queue_backend",
          "object_storage",
          "secret_manager",
          "identity_provider",
          "allowed_origins",
          "csrf_protection",
          "signed_webhooks",
          "migration_manifest",
          "release_manifest",
          "tenant_isolation",
          "outbox_delivery",
          "repository_contracts",
          "data_quality_gates",
          "secret_reference_enforcement",
          "policy_bundle",
          "route_governance",
          "access_governance",
          "break_glass_controls",
          "provider_contract_tests",
          "incident_response",
          "slo_evidence",
          "feature_flags",
          "deployment_change_control",
          "dlp_scans",
          "scheduler_controls",
          "service_accounts",
          "object_artifacts",
          "webhook_replay",
          "synthetic_monitoring",
          "api_lifecycle",
          "data_residency",
          "consent_ledger",
          "billing_reconciliation",
          "resilience_drills",
          "backup_drills",
          "compliance_evidence",
          "supply_chain",
          "kms_controls",
          "vulnerability_scans",
          "configuration_baseline",
          "evidence_seals",
          "metrics_endpoint",
          "audit_log",
          "demo_reset"
        ],
        "regulated_production": [
          "runtime_environment",
          "secret_key",
          "api_auth_gate",
          "database",
          "queue_backend",
          "object_storage",
          "secret_manager",
          "identity_provider",
          "allowed_origins",
          "csrf_protection",
          "signed_webhooks",
          "migration_manifest",
          "release_manifest",
          "tenant_isolation",
          "outbox_delivery",
          "repository_contracts",
          "data_quality_gates",
          "retention_scans",
          "secret_reference_enforcement",
          "policy_bundle",
          "route_governance",
          "access_governance",
          "break_glass_controls",
          "provider_contract_tests",
          "incident_response",
          "slo_evidence",
          "feature_flags",
          "deployment_change_control",
          "dlp_scans",
          "scheduler_controls",
          "service_accounts",
          "object_artifacts",
          "webhook_replay",
          "synthetic_monitoring",
          "api_lifecycle",
          "data_residency",
          "consent_ledger",
          "billing_reconciliation",
          "resilience_drills",
          "backup_drills",
          "compliance_evidence",
          "supply_chain",
          "kms_controls",
          "vulnerability_scans",
          "configuration_baseline",
          "evidence_seals",
          "metrics_endpoint",
          "audit_log",
          "demo_reset"
        ]
      },
      "required_controls": [
        "Capture immutable runtime-configuration baselines before staging and production promotion.",
        "Evaluate the active baseline before release promotion, security reviews, and incident recovery.",
        "Treat readiness-control drift, missing controls, and default secrets as blocking in production profiles.",
        "Attach baseline evaluation evidence to deployment changes and compliance packs."
      ]
    },
    "configuration_baselines": [],
    "configuration_baseline_evaluations": [],
    "configuration_baseline_summary": {
      "total_baselines": 0,
      "total_evaluations": 0,
      "by_profile": {},
      "by_decision": {},
      "latest_decision": null,
      "latest_drift_count": 0,
      "latest_missing_control_count": 0
    },
    "evidence_seal_plan": {
      "version": "2026-04-20.10",
      "mode": "tamper_evident_control_plane_attestations",
      "configured": {
        "evidence_seals_required": false,
        "secret_manager_configured": false,
        "kms_provider_configured": false,
        "default_signing_secret_active": false
      },
      "sources": [
        "audit_events",
        "compliance_evidence_packs",
        "configuration_baselines",
        "export_jobs",
        "kms_keys",
        "migration_manifest",
        "outbox_events",
        "recovery_points",
        "release_manifest",
        "vulnerability_scans"
      ],
      "purposes": [
        "audit_evidence",
        "backup_restore",
        "compliance_pack",
        "customer_assurance",
        "incident_review",
        "release_gate"
      ],
      "required_controls": [
        "Seal release, migration, audit, export, recovery, and compliance evidence before production promotion.",
        "Verify seals before incident review, customer assurance packets, and restore cutovers.",
        "Use managed secrets/KMS-backed signing keys in production; local HMAC is compatibility evidence only.",
        "Never include plaintext secrets or large artifact blobs in the canonical sealed payload."
      ]
    },
    "evidence_seals": [],
    "evidence_seal_summary": {
      "total_seals": 0,
      "by_source": {},
      "by_status": {},
      "latest_status": null
    },
    "telemetry_pipeline_plan": {
      "version": "2026-04-20.12",
      "mode": "production_telemetry_export_and_siem_readiness",
      "configured": {
        "metrics_enabled": true,
        "otel_exporter_otlp_configured": false,
        "log_shipping_required": false,
        "siem_export_configured": false,
        "sampling_ratio": 0.1
      },
      "signals": [
        {
          "key": "api_request",
          "pipeline": "structured_logs",
          "required_context": [
            "correlation_id",
            "actor_id",
            "tenant_id",
            "route",
            "latency_ms"
          ]
        },
        {
          "key": "provider_call",
          "pipeline": "otel_traces",
          "required_context": [
            "provider",
            "operation",
            "duration_ms",
            "status"
          ]
        },
        {
          "key": "workflow_step",
          "pipeline": "otel_traces",
          "required_context": [
            "workflow_run_id",
            "step_key",
            "attempt",
            "decision"
          ]
        },
        {
          "key": "audit_event",
          "pipeline": "siem_export",
          "required_context": [
            "actor_id",
            "action",
            "object_ref",
            "decision"
          ]
        },
        {
          "key": "security_posture",
          "pipeline": "metrics",
          "required_context": [
            "readiness_key",
            "status",
            "severity"
          ]
        }
      ],
      "required_controls": [
        "Every request, workflow step, provider call, security decision, and export should carry correlation, actor, tenant, and object context.",
        "Trace export must use OTLP or an equivalent collector instead of local-only state.",
        "Security/audit telemetry must be ship-ready for immutable storage or SIEM correlation.",
        "Metrics, traces, and logs must be retained independently so evidence survives application restarts."
      ]
    },
    "telemetry_snapshots": [],
    "telemetry_snapshot_summary": {
      "total": 0,
      "by_status": {},
      "latest_snapshot_at": null
    },
    "alert_routing_plan": {
      "version": "2026-04-20.12",
      "mode": "production_alert_routing_and_acknowledgement_control",
      "configured": {
        "alert_routing_required": false,
        "incident_pager_configured": false,
        "status_page_configured": false
      },
      "routes": [
        {
          "signal": "readiness_fail",
          "minimum_severity": "sev2",
          "target": "incident_pager"
        },
        {
          "signal": "webhook_dead_letter",
          "minimum_severity": "sev3",
          "target": "provider_ops"
        },
        {
          "signal": "security_policy_deny",
          "minimum_severity": "sev2",
          "target": "security"
        },
        {
          "signal": "export_blocked",
          "minimum_severity": "sev3",
          "target": "security_and_revops"
        },
        {
          "signal": "capacity_saturation",
          "minimum_severity": "sev2",
          "target": "runtime_ops"
        }
      ],
      "required_controls": [
        "Critical readiness failures, failed production promotions, and security events must produce actionable alert evidence.",
        "Every alert must support acknowledgement, resolution, status, severity, source, entity reference, actor, and tenant context.",
        "Open critical alerts should block release promotion unless a break-glass or explicit risk acceptance exists."
      ]
    },
    "alerts": [],
    "alert_summary": {
      "total": 0,
      "by_status": {},
      "by_severity": {},
      "open_critical": 0
    },
    "data_lineage_plan": {
      "version": "2026-04-20.12",
      "mode": "production_data_lineage_and_provenance_evidence",
      "configured": {
        "data_lineage_required": false
      },
      "critical_edges": [
        "lead -> account/contact/deal",
        "deal -> quote -> contract -> invoice",
        "contract -> invoice -> settlement/reconciliation",
        "workflow_run -> workflow_step -> outbox_event",
        "export_job -> artifact/evidence seal/audit event"
      ],
      "required_controls": [
        "Customer, revenue, workflow, export, and audit objects must preserve source and downstream object references.",
        "Lineage scans should block release promotion when high-value objects are missing tenant, actor, or source references.",
        "Provider/import/sync objects should keep external IDs separate from internal canonical IDs."
      ]
    },
    "data_lineage_runs": [],
    "data_lineage_summary": {
      "total": 0,
      "by_decision": {},
      "latest_run_at": null
    },
    "capacity_plan": {
      "version": "2026-04-20.12",
      "mode": "production_capacity_and_saturation_evidence",
      "configured": {
        "capacity_tests_required": false,
        "p95_latency_target_ms": 750,
        "min_available_workers": 2,
        "redis_configured": false
      },
      "capacity_dimensions": [
        "api_latency",
        "worker_leases",
        "outbox_backlog",
        "export_queue",
        "provider_webhook_backlog",
        "object_storage"
      ],
      "required_controls": [
        "Production release promotion should have recent capacity evidence for API latency, worker pools, outbox backlog, and export generation.",
        "Saturation evidence must include p95 latency, expected RPS, worker count, backlog counts, and remediation guidance.",
        "Capacity gates should page runtime operations when saturation exceeds configured thresholds."
      ]
    },
    "capacity_assessments": [],
    "capacity_assessment_summary": {
      "total": 0,
      "by_decision": {},
      "latest_assessment_at": null
    },
    "control_objectives": {
      "version": "2026-04-20.12",
      "mode": "production_control_objective_mapping_and_release_attestation",
      "configured": {
        "control_objectives_required": false,
        "compliance_evidence_required": false,
        "evidence_seals_required": false
      },
      "objectives": [
        {
          "key": "access_control",
          "family": "security",
          "objective": "Authenticate, authorize, and tenant-scope every production route and privileged action.",
          "frameworks": [
            "soc2_security",
            "iso27001_foundation"
          ],
          "readiness_keys": [
            "authentication",
            "trusted_identity_boundary",
            "tenant_isolation",
            "access_governance",
            "break_glass_controls"
          ],
          "evidence_collections": [
            "audit_events",
            "access_requests",
            "break_glass_sessions",
            "access_review_cycles"
          ]
        },
        {
          "key": "change_management",
          "family": "availability",
          "objective": "Require release evidence, deployment approval, feature flags, rollback, and route-change governance before production promotion.",
          "frameworks": [
            "soc2_security",
            "soc2_availability",
            "iso27001_foundation"
          ],
          "readiness_keys": [
            "release_manifest",
            "deployment_change_control",
            "feature_flags",
            "route_governance",
            "configuration_baseline"
          ],
          "evidence_collections": [
            "deployment_changes",
            "feature_flag_changes",
            "configuration_baselines",
            "control_assessments"
          ]
        },
        {
          "key": "data_protection",
          "family": "privacy",
          "objective": "Protect customer, revenue, identity, artifact, and export data with DLP, retention, consent, KMS, and residency controls.",
          "frameworks": [
            "soc2_security",
            "gdpr_privacy",
            "iso27001_foundation"
          ],
          "readiness_keys": [
            "dlp_scans",
            "retention_scans",
            "consent_ledger",
            "kms_controls",
            "data_residency"
          ],
          "evidence_collections": [
            "dlp_scans",
            "retention_scans",
            "consent_events",
            "kms_keys",
            "data_residency_assessments"
          ]
        },
        {
          "key": "operational_resilience",
          "family": "availability",
          "objective": "Demonstrate recovery, alert routing, telemetry, capacity, backup drill, and runbook evidence for operational incidents.",
          "frameworks": [
            "soc2_availability",
            "iso27001_foundation"
          ],
          "readiness_keys": [
            "backup_drills",
            "telemetry_pipeline",
            "alert_routing",
            "capacity_tests",
            "metrics_endpoint"
          ],
          "evidence_collections": [
            "backup_drills",
            "telemetry_snapshots",
            "alerts",
            "capacity_assessments",
            "runbook_executions"
          ]
        },
        {
          "key": "integrations_and_supply_chain",
          "family": "vendor_risk",
          "objective": "Verify providers, signed webhooks, outbox delivery, supply-chain artifacts, vulnerabilities, and contract tests.",
          "frameworks": [
            "soc2_security",
            "iso27001_foundation"
          ],
          "readiness_keys": [
            "provider_contract_tests",
            "signed_webhooks",
            "outbox_delivery",
            "supply_chain",
            "vulnerability_scans"
          ],
          "evidence_collections": [
            "provider_contract_test_runs",
            "webhook_receipts",
            "outbox_events",
            "supply_chain_scans",
            "vulnerability_scans"
          ]
        }
      ],
      "required_controls": [
        "Every control objective must map to readiness checks, durable evidence collections, and at least one release gate.",
        "A production promotion should include a recent control assessment with no critical blockers or an explicit risk acceptance.",
        "Control evidence should be sealed or exported to immutable audit/SIEM storage for customer assurance reviews."
      ]
    },
    "control_assessments": [],
    "control_assessment_summary": {
      "total": 0,
      "by_decision": {},
      "latest_coverage_pct": 0,
      "latest_assessment_at": null
    },
    "threat_model_plan": {
      "version": "2026-04-20.12",
      "mode": "production_threat_model_and_abuse_case_assurance",
      "configured": {
        "threat_model_required": false,
        "policy_bundle_required": false,
        "signed_webhooks_required": false
      },
      "scenarios": [
        {
          "key": "tenant_data_exposure",
          "domain": "data",
          "severity": "critical",
          "controls": [
            "tenant_isolation",
            "rbac",
            "dlp",
            "audit"
          ]
        },
        {
          "key": "privileged_account_takeover",
          "domain": "identity",
          "severity": "critical",
          "controls": [
            "mfa",
            "access_review",
            "break_glass",
            "alert_routing"
          ]
        },
        {
          "key": "webhook_replay_or_spoofing",
          "domain": "provider",
          "severity": "high",
          "controls": [
            "signed_webhooks",
            "idempotency",
            "webhook_replay",
            "outbox"
          ]
        },
        {
          "key": "artifact_or_export_leak",
          "domain": "privacy",
          "severity": "high",
          "controls": [
            "object_storage",
            "export_governance",
            "dlp",
            "kms"
          ]
        },
        {
          "key": "workflow_or_agent_unsafe_action",
          "domain": "runtime",
          "severity": "high",
          "controls": [
            "policy_bundle",
            "approval",
            "feature_flag",
            "audit"
          ]
        },
        {
          "key": "supply_chain_or_dependency_compromise",
          "domain": "supply_chain",
          "severity": "high",
          "controls": [
            "sbom",
            "vulnerability_scan",
            "release_manifest",
            "evidence_seal"
          ]
        }
      ],
      "required_controls": [
        "Threat-model runs should be executed before new high-risk provider, workflow, export, or identity changes are promoted.",
        "Every high or critical scenario should map to readiness evidence, policy obligations, and an incident/runbook path.",
        "Threat findings must be recorded with actor, tenant, release, scope, and decision metadata."
      ]
    },
    "threat_model_runs": [],
    "threat_model_summary": {
      "total": 0,
      "by_decision": {},
      "latest_run_at": null
    },
    "access_review_cycle_plan": {
      "version": "2026-04-20.12",
      "mode": "production_periodic_access_certification",
      "configured": {
        "access_review_cycles_required": false,
        "trusted_identity_headers": false,
        "mfa_required_for_sensitive_routes": false
      },
      "review_scopes": [
        "all",
        "privileged",
        "service_accounts",
        "break_glass",
        "mfa_gaps"
      ],
      "required_controls": [
        "Privileged users, service accounts, stale access, MFA gaps, and break-glass sessions must be periodically certified.",
        "Every cycle must preserve certification items, due dates, reviewers, disposition, and evidence exports.",
        "Production releases should block or warn when no recent access review exists for privileged access."
      ]
    },
    "access_review_cycles": [],
    "access_review_cycle_summary": {
      "total": 0,
      "by_status": {},
      "latest_cycle_at": null
    },
    "runbook_plan": {
      "version": "2026-04-20.12",
      "mode": "production_runbook_execution_and_operational_evidence",
      "configured": {
        "runbook_automation_required": false,
        "incident_response_required": false,
        "alert_routing_required": false
      },
      "runbooks": [
        {
          "key": "provider_outage",
          "severity": "sev3",
          "owner": "provider_ops",
          "actions": [
            "confirm provider health",
            "pause sync jobs",
            "drain outbox retries",
            "notify affected tenants"
          ]
        },
        {
          "key": "failed_webhook_replay",
          "severity": "sev3",
          "owner": "provider_ops",
          "actions": [
            "verify signatures",
            "inspect dead letters",
            "create replay job",
            "confirm idempotency"
          ]
        },
        {
          "key": "queue_backlog",
          "severity": "sev2",
          "owner": "runtime_ops",
          "actions": [
            "inspect outbox backlog",
            "scale workers",
            "lease and drain",
            "alert runtime team"
          ]
        },
        {
          "key": "sensitive_export_review",
          "severity": "sev2",
          "owner": "security",
          "actions": [
            "confirm MFA",
            "review DLP",
            "seal export evidence",
            "expire artifact"
          ]
        },
        {
          "key": "stale_workflow_lock",
          "severity": "sev4",
          "owner": "workflow_ops",
          "actions": [
            "identify lock owner",
            "review workflow attempts",
            "release or escalate",
            "record compensation if needed"
          ]
        },
        {
          "key": "security_incident_intake",
          "severity": "sev1",
          "owner": "security",
          "actions": [
            "open incident",
            "page on-call",
            "preserve evidence",
            "run threat model",
            "capture postmortem"
          ]
        }
      ],
      "required_controls": [
        "Every production failure mode must have an executable runbook with owner, severity, action checklist, and evidence outputs.",
        "Runbook executions must be linked to incidents, alerts, provider events, workflow runs, or release changes when applicable.",
        "Game-day and incident runbook runs should feed SLO, alert, and compliance evidence packs."
      ]
    },
    "runbook_executions": [],
    "runbook_execution_summary": {
      "total": 0,
      "by_status": {},
      "latest_execution_at": null
    },
    "sla_management_plan": {
      "version": "2026-04-20.12",
      "mode": "production_customer_sla_and_credit_governance",
      "configured": {
        "sla_controls_required": false,
        "incident_response_required": false,
        "status_page_configured": false
      },
      "tiers": {
        "standard": {
          "first_response_minutes": 480,
          "resolution_hours": 72,
          "credit_policy": "case_by_case"
        },
        "priority": {
          "first_response_minutes": 120,
          "resolution_hours": 24,
          "credit_policy": "contractual_review"
        },
        "enterprise": {
          "first_response_minutes": 60,
          "resolution_hours": 8,
          "credit_policy": "contractual_credit"
        }
      },
      "required_controls": [
        "Customer-facing SLA assessments should connect support tickets, incidents, SLO snapshots, credits, and contract obligations.",
        "Potential credits must create finance/customer-success evidence and never silently bypass approval.",
        "SLA assessments should be exportable and tenant-scoped for customer assurance and QBR review."
      ]
    },
    "sla_assessments": [],
    "sla_assessment_summary": {
      "total": 0,
      "by_decision": {},
      "latest_assessment_at": null
    },
    "session_governance_plan": {
      "version": "2026-04-20.12",
      "mode": "zero_trust_session_and_risk_evidence",
      "configured": {
        "zero_trust_sessions_required": false,
        "session_risk_required": false,
        "session_max_age_minutes": 480,
        "identity_boundary_configured": false,
        "mfa_header_enforced": false
      },
      "risk_signals": [
        "mfa_not_verified",
        "local_simulated_identity",
        "privileged_role",
        "cross_tenant_scope",
        "break_glass_session_active",
        "unknown_session_age"
      ],
      "required_controls": [
        "Every production session must map to a tenant-scoped actor, role, MFA state, and identity source.",
        "Privileged sessions should receive explicit risk scoring before exports, security actions, provider changes, and finance operations.",
        "Revocation records must be written as auditable evidence and shipped to the identity provider/session store."
      ]
    },
    "active_sessions": [],
    "session_risk_assessments": [],
    "session_governance_summary": {
      "active_sessions": 0,
      "total_sessions": 0,
      "total_assessments": 0,
      "by_status": {},
      "by_decision": {},
      "latest_assessment_at": null
    },
    "search_index_plan": {
      "version": "2026-04-20.12",
      "mode": "production_search_index_and_discovery_evidence",
      "configured": {
        "search_index_required": false,
        "search_index_backend_configured": false,
        "database_configured": false,
        "max_documents_per_run": 5000
      },
      "domains": [
        "crm",
        "operations",
        "revenue",
        "workflow"
      ],
      "required_controls": [
        "Search results must be tenant-scoped and permission-aware before documents leave transactional tables.",
        "Index rebuilds must record document counts, missing tenant keys, stale references, and release/search coverage evidence.",
        "External search backends must consume redacted/indexable views rather than raw unrestricted state."
      ]
    },
    "search_index_runs": [],
    "search_index_documents": [],
    "search_index_summary": {
      "total_runs": 0,
      "indexed_documents": 0,
      "by_decision": {},
      "latest_run_at": null,
      "latest_document_count": 0
    },
    "queue_autoscaling_plan": {
      "version": "2026-04-20.12",
      "mode": "production_queue_autoscaling_and_backlog_evidence",
      "configured": {
        "queue_autoscaling_required": false,
        "redis_configured": false,
        "min_available_workers": 2,
        "queue_max_backlog": 100
      },
      "queue_families": [
        "outbox_delivery",
        "export_generation",
        "webhook_replay",
        "scheduler_jobs",
        "provider_sync",
        "runtime_jobs"
      ],
      "required_controls": [
        "Backlog, worker capacity, and queue saturation evidence must be captured before deployment promotion and during incidents.",
        "Queue scaling decisions should be driven by durable queue depth rather than request-thread side effects.",
        "Critical provider/webhook/payment queues must page before customer-visible failure thresholds are crossed."
      ]
    },
    "queue_autoscaling_assessments": [],
    "queue_autoscaling_summary": {
      "total_assessments": 0,
      "by_decision": {},
      "latest_assessment_at": null,
      "latest_recommended_workers": 0
    },
    "migration_rollback_plan": {
      "version": "2026-04-20.12",
      "mode": "production_migration_rollback_and_rehearsal_evidence",
      "configured": {
        "migration_rollback_required": false,
        "database_configured": false,
        "backup_plan_required": false,
        "backup_drill_required": false
      },
      "required_controls": [
        "Every schema promotion must have a rollback or compensating migration plan tied to a recent recovery point.",
        "Rollback rehearsals must capture target migration, prerequisites, blockers, and a release-gate decision.",
        "Destructive migrations must require backup-drill evidence and explicit approval before production promotion."
      ]
    },
    "migration_rollback_rehearsals": [],
    "migration_rollback_summary": {
      "total_rehearsals": 0,
      "by_decision": {},
      "latest_rehearsal_at": null
    },
    "privacy_rights_plan": {
      "version": "2026-04-20.13",
      "mode": "privacy_subject_rights_and_erasure_evidence",
      "configured": {
        "privacy_subject_rights_required": false,
        "privacy_identity_verification_required": false,
        "privacy_request_sla_days": 30,
        "retention_scans_required": false,
        "legal_hold_awareness": true
      },
      "request_types": [
        "access",
        "correction",
        "deletion",
        "objection",
        "portability",
        "restriction",
        "suppression"
      ],
      "required_controls": [
        "Data-subject access, deletion, restriction, suppression, and portability requests must produce immutable request, verification, fulfillment, and legal-hold evidence.",
        "Deletion and restriction requests must fail closed when legal holds, finance retention, or contract retention blockers are present.",
        "Fulfillment records must include matched-record counts and action manifests without exposing full PII in unrestricted responses."
      ]
    },
    "privacy_subject_requests": [],
    "privacy_subject_request_summary": {
      "total_requests": 0,
      "by_status": {},
      "by_type": {},
      "overdue_requests": 0,
      "latest_request_at": null
    },
    "entitlement_control_plan": {
      "version": "2026-04-20.13",
      "mode": "tenant_entitlement_quota_and_usage_metering_governance",
      "configured": {
        "tenant_entitlements_required": false,
        "usage_metering_required": false,
        "quota_enforcement_required": false,
        "billing_reconciliation_required": false,
        "default_plan": "growth"
      },
      "meters": [
        "api_requests",
        "exports",
        "storage_mb",
        "workflows"
      ],
      "required_controls": [
        "Every tenant should have an explicit plan, entitlement source, quota limits, and usage-metering evidence before customer production traffic.",
        "Usage events must be tenant scoped and reconciled to billing/provider evidence before finance reporting.",
        "Quota violations should produce auditable warnings or blockers, not silent throttling decisions."
      ]
    },
    "usage_metering_events": [],
    "entitlement_summary": {
      "total_usage_events": 0,
      "total_assessments": 0,
      "usage_by_meter": {},
      "by_decision": {},
      "latest_assessment_at": null
    },
    "network_perimeter_plan": {
      "version": "2026-04-20.13",
      "mode": "network_perimeter_mtls_egress_and_api_gateway_evidence",
      "configured": {
        "network_perimeter_required": false,
        "mtls_required": false,
        "service_mesh_required": false,
        "egress_allowlist_required": false,
        "egress_allowlist_configured": false,
        "waf_enabled": false,
        "allowed_origins_configured": false
      },
      "required_controls": [
        "Production API ingress should be behind an API gateway or WAF with explicit origin, auth, rate-limit, and body-size controls.",
        "Provider and worker egress should be constrained to an allow-list and audited before enabling live integrations.",
        "Internal service-to-service traffic should use mTLS or a service-mesh equivalent when production workloads are distributed."
      ]
    },
    "network_posture_summary": {
      "total_snapshots": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_snapshot_at": null
    },
    "maintenance_window_plan": {
      "version": "2026-04-20.13",
      "mode": "maintenance_window_change_freeze_and_customer_notification_evidence",
      "configured": {
        "maintenance_windows_required": false,
        "release_freeze_required": false,
        "status_page_configured": false,
        "deployment_change_control_required": false
      },
      "freeze_levels": [
        "none",
        "advisory",
        "standard",
        "strict"
      ],
      "required_controls": [
        "Production deployments should reference an approved change window or explicitly document emergency override evidence.",
        "Strict release freezes must block non-emergency promotions and produce customer/status notification evidence.",
        "Maintenance windows should be tenant/customer scoped when they may affect a subset of revenue workflows or integrations."
      ]
    },
    "maintenance_windows": [],
    "maintenance_window_summary": {
      "total_windows": 0,
      "by_status": {},
      "active_freeze_windows": 0,
      "latest_window_at": null
    },
    "vendor_risk_plan": {
      "version": "2026-04-20.13",
      "mode": "production_third_party_vendor_risk_and_provider_due_diligence",
      "configured": {
        "vendor_risk_required": false,
        "third_party_register_configured": false,
        "provider_contract_tests_required": false,
        "data_residency_required": false
      },
      "families": {
        "identity": {
          "risk": "critical",
          "required_evidence": [
            "soc2",
            "dpa",
            "subprocessor_review",
            "incident_contact"
          ]
        },
        "email": {
          "risk": "high",
          "required_evidence": [
            "dpa",
            "spam_compliance",
            "bounce_webhook_test"
          ]
        },
        "calendar": {
          "risk": "medium",
          "required_evidence": [
            "oauth_scope_review",
            "dpa"
          ]
        },
        "esign": {
          "risk": "high",
          "required_evidence": [
            "soc2",
            "dpa",
            "webhook_signature_test"
          ]
        },
        "billing": {
          "risk": "critical",
          "required_evidence": [
            "pci_attestation",
            "soc2",
            "dpa",
            "webhook_signature_test"
          ]
        },
        "crm": {
          "risk": "high",
          "required_evidence": [
            "dpa",
            "field_mapping_review",
            "data_residency_review"
          ]
        },
        "observability": {
          "risk": "high",
          "required_evidence": [
            "log_redaction_review",
            "dpa",
            "subprocessor_review"
          ]
        }
      },
      "required_controls": [
        "Every production provider must have a vendor-risk assessment before live credentials are promoted.",
        "High and critical vendors require DPA/SOC2 or equivalent evidence, subprocessor review, incident contact, and contract-test linkage.",
        "Vendor-risk records must be tenant-scoped, export-controlled, and included in release/compliance evidence packs."
      ]
    },
    "vendor_risk_summary": {
      "total_assessments": 0,
      "by_decision": {},
      "by_family": {},
      "latest_assessment_at": null
    },
    "privacy_request_plan": {
      "version": "2026-04-20.13",
      "mode": "production_dsar_privacy_request_and_suppression_fulfillment",
      "configured": {
        "privacy_requests_required": false,
        "consent_ledger_required": false,
        "privacy_request_sla_days": 30,
        "dlp_scans_required": false
      },
      "request_types": [
        "access",
        "correct",
        "correction",
        "delete",
        "deletion",
        "export",
        "opt_out",
        "restrict_processing"
      ],
      "required_controls": [
        "Privacy requests must verify identity, inspect legal holds, coordinate suppression/deletion/export actions, and retain evidence.",
        "Deletion and export requests must be blocked or escalated when legal holds, retention obligations, or restricted data classifications apply.",
        "Privacy request fulfillment must update consent/suppression evidence and be tenant-scoped for customer audits."
      ]
    },
    "privacy_requests": [],
    "privacy_request_summary": {
      "total_requests": 0,
      "by_status": {},
      "by_type": {},
      "latest_request_at": null
    },
    "revenue_recognition_plan": {
      "version": "2026-04-20.13",
      "mode": "production_revenue_recognition_and_finance_close_controls",
      "configured": {
        "revenue_recognition_required": false,
        "revenue_recognition_policy_configured": false,
        "billing_reconciliation_required": false
      },
      "required_controls": [
        "Contract execution, invoices, payment state, and revenue schedules must reconcile before revenue is recognized.",
        "Finance exceptions must create approval/audit evidence and cannot silently recognize revenue on mismatched contract/invoice state.",
        "Revenue recognition runs should be tied to month-end close evidence and provider-payment reconciliation results."
      ]
    },
    "revenue_recognition_summary": {
      "total_runs": 0,
      "by_decision": {},
      "latest_run_at": null
    },
    "model_risk_plan": {
      "version": "2026-04-20.13",
      "mode": "production_ai_model_agent_risk_and_human_review_controls",
      "configured": {
        "model_risk_required": false,
        "model_risk_policy_configured": false,
        "policy_bundle_required": false
      },
      "risk_domains": {
        "agent_actions": [
          "tool_authorization",
          "human_approval",
          "guardrail_incidents"
        ],
        "forecasting": [
          "model_evaluation",
          "drift_monitor",
          "lineage_run"
        ],
        "content_generation": [
          "prompt_evaluation",
          "approved_material",
          "policy_review"
        ],
        "all": [
          "tool_authorization",
          "model_evaluation",
          "prompt_evaluation",
          "drift_monitor",
          "guardrail_incidents"
        ]
      },
      "required_controls": [
        "Model, prompt, and agent releases must have risk assessment evidence before autonomous or customer-impacting use.",
        "High-risk tool authorization requires policy bundle coverage, human-review thresholds, drift/guardrail evidence, and rollback controls.",
        "Model-risk findings should feed release gates, feature flags, and incident/runbook review when guardrail incidents appear."
      ]
    },
    "model_risk_summary": {
      "total_assessments": 0,
      "by_decision": {},
      "by_domain": {},
      "latest_assessment_at": null
    },
    "trust_evidence_plan": {
      "version": "2026-04-20.13",
      "mode": "production_customer_trust_evidence_portal_and_share_controls",
      "configured": {
        "trust_evidence_required": false,
        "trust_portal_configured": false,
        "object_storage_configured": false,
        "evidence_seals_required": false
      },
      "required_controls": [
        "Customer-facing trust evidence must be shared through expiring, audited, least-privilege evidence links.",
        "Trust packets should reference DPA, security review, compliance pack, evidence seals, and DLP/export checks before customer sharing.",
        "Every trust evidence share must record audience, framework, evidence types, expiration, actor, tenant, and outbox/audit evidence."
      ]
    },
    "trust_evidence_summary": {
      "total_shares": 0,
      "by_status": {},
      "by_framework": {},
      "latest_share_at": null
    },
    "identity_cutover_plan": {
      "version": "2026-04-21.19",
      "mode": "identity_provider_cutover_and_scim_readiness",
      "configured": {
        "identity_cutover_required": false,
        "oidc_configured": false,
        "trusted_identity_headers": false,
        "api_auth_required": false,
        "mfa_required": false,
        "scim_sync_required": false,
        "scim_base_url_configured": false,
        "session_governance_required": false
      },
      "required_capabilities": [
        "oidc_login",
        "mfa_enforcement",
        "role_claim_mapping",
        "tenant_claim_mapping",
        "session_revocation",
        "scim_provisioning",
        "break_glass_account_review"
      ],
      "required_controls": [
        "Production access must be cut over from simulated local identity to OIDC/SAML or trusted identity headers behind a verified boundary.",
        "Role, tenant, MFA, and session-revocation claims must be rehearsed before enabling customer traffic.",
        "SCIM or directory provisioning must produce reconciliation evidence when enterprise identity sync is enabled.",
        "Break-glass accounts must be reviewed and separately audited before production launch."
      ]
    },
    "identity_cutover_summary": {
      "total_runs": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_run_at": null,
      "latest_blocking_findings": 0
    },
    "tenant_activation_plan": {
      "version": "2026-04-21.19",
      "mode": "tenant_activation_and_go_live_readiness",
      "configured": {
        "tenant_activation_required": false,
        "tenant_isolation_required": false,
        "default_data_region": "us",
        "allowed_data_regions": [
          "us",
          "eu",
          "ca",
          "uk",
          "au"
        ],
        "tenant_entitlements_required": false,
        "trust_evidence_required": false
      },
      "activation_checks": [
        "tenant_record",
        "admin_contact",
        "domain_verification",
        "identity_boundary",
        "data_region",
        "entitlements",
        "billing_contact",
        "support_sla",
        "trust_evidence"
      ],
      "required_controls": [
        "Each customer tenant must have a go-live activation record with region, admin, domain, identity, entitlement, billing, SLA, and trust evidence.",
        "Tenant activation must fail closed when data region or tenant isolation controls are not established.",
        "Production tenant activation must be auditable and tied to outbox events for downstream billing/support provisioning."
      ]
    },
    "tenant_activation_summary": {
      "total_runs": 0,
      "activated_tenants": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_run_at": null
    },
    "evidence_vault_plan": {
      "version": "2026-04-21.19",
      "mode": "immutable_evidence_vault_and_chain_of_custody",
      "configured": {
        "evidence_vault_required": false,
        "evidence_vault_configured": false,
        "evidence_seals_required": false,
        "object_storage_configured": false,
        "retention_days": 2555
      },
      "required_controls": [
        "Sensitive audit, release, privacy, provider, and finance evidence must be sealed and written to immutable storage.",
        "Evidence vault records must preserve source collection, source object, digest, classification, retention, legal-hold, and actor metadata.",
        "Verification must fail closed when a source digest changes or the external vault is required but not configured."
      ]
    },
    "evidence_vault_records": [],
    "evidence_vault_summary": {
      "total_records": 0,
      "by_status": {},
      "by_classification": {},
      "latest_record_at": null
    },
    "provider_oauth_plan": {
      "version": "2026-04-21.19",
      "mode": "provider_oauth_refresh_token_and_scope_health",
      "configured": {
        "provider_oauth_required": false,
        "oauth_client_registry_configured": false,
        "secret_manager_configured": false,
        "provider_contract_tests_required": false,
        "api_token_rotation_days": 90
      },
      "provider_families": [
        "billing",
        "calendar",
        "crm",
        "email",
        "esign",
        "identity",
        "observability",
        "sms",
        "warehouse"
      ],
      "required_controls": [
        "Live provider adapters must use least-privilege OAuth scopes, managed refresh-token references, rotation metadata, and contract-test evidence.",
        "Provider OAuth health checks must identify expiring tokens, missing scopes, plaintext credential risks, and missing client registry evidence.",
        "Production provider promotion must fail closed when OAuth client registration or secret-manager references are missing."
      ]
    },
    "provider_oauth_summary": {
      "total_checks": 0,
      "by_decision": {},
      "by_family": {},
      "latest_decision": null,
      "latest_check_at": null
    },
    "data_migration_wave_plan": {
      "version": "2026-04-21.19",
      "mode": "json_state_to_database_cutover_wave_governance",
      "configured": {
        "data_migration_waves_required": false,
        "database_configured": false,
        "shadow_reads_required": false,
        "dual_write_required": false,
        "database_cutover_required": false,
        "object_store_configured": false
      },
      "default_collections": [
        "tenants",
        "identity",
        "crm",
        "revenue",
        "contracts",
        "invoices",
        "workflow",
        "audit",
        "provider"
      ],
      "required_controls": [
        "Each production migration wave must name source and target stores, scoped collections, validation rates, diff counts, rollback plan, backup evidence, and release decision.",
        "Cutover waves must remain blocked when the database is not configured, shadow reads are incomplete, dual-write mismatches exist, or rollback evidence is missing.",
        "Migration wave records are release evidence, not a replacement for Alembic/PostgreSQL migration execution."
      ]
    },
    "data_migration_waves": [],
    "data_migration_wave_summary": {
      "total_waves": 0,
      "by_status": {},
      "by_decision": {},
      "promoted_waves": 0,
      "latest_status": null,
      "latest_decision": null,
      "latest_validation_pass_rate_pct": null
    },
    "provider_execution_plan": {
      "version": "2026-04-21.19",
      "mode": "provider_adapter_execution_and_live_action_readiness",
      "configured": {
        "provider_execution_required": false,
        "secret_manager_configured": false,
        "provider_oauth_required": false,
        "oauth_client_registry_configured": false,
        "outbox_required": false,
        "queue_configured": false,
        "contract_tests_required": false
      },
      "supported_provider_actions": {
        "identity": [
          "scim_sync",
          "user_lookup",
          "group_reconcile"
        ],
        "email": [
          "send_email",
          "sync_suppression",
          "template_validate"
        ],
        "calendar": [
          "create_event",
          "availability_check",
          "sync_event"
        ],
        "esign": [
          "create_envelope",
          "void_envelope",
          "sync_status"
        ],
        "billing": [
          "create_invoice",
          "sync_payment",
          "reconcile_customer"
        ],
        "crm": [
          "upsert_account",
          "upsert_contact",
          "sync_pipeline"
        ],
        "warehouse": [
          "sync_dataset",
          "validate_contract",
          "refresh_dashboard"
        ],
        "observability": [
          "emit_event",
          "open_incident",
          "sync_slo"
        ],
        "sms": [
          "send_sms",
          "sync_opt_out",
          "verify_number"
        ]
      },
      "required_controls": [
        "Live provider actions must execute through adapter contracts, managed secret references, idempotency keys, and outbox/job delivery instead of synchronous controller calls.",
        "Provider execution must link to OAuth/token-health checks and provider contract-test evidence before live_send/live_execute modes are enabled.",
        "Action payloads are referenced by digest or object reference; sensitive provider payloads must not be stored inline."
      ]
    },
    "provider_action_runs": [],
    "provider_execution_summary": {
      "total_runs": 0,
      "by_status": {},
      "by_family": {},
      "by_decision": {},
      "latest_decision": null,
      "latest_status": null
    },
    "notification_delivery_plan": {
      "version": "2026-04-21.19",
      "mode": "tenant_customer_and_operator_notification_delivery_governance",
      "configured": {
        "notification_delivery_required": false,
        "notification_provider_configured": false,
        "consent_ledger_required": false,
        "privacy_requests_required": false,
        "outbox_required": false
      },
      "channels": [
        "email",
        "sms",
        "in_app",
        "webhook",
        "slack",
        "teams"
      ],
      "templates": [
        {
          "key": "tenant_activation_ready",
          "channel": "email",
          "classification": "customer_operational"
        },
        {
          "key": "maintenance_window_notice",
          "channel": "email",
          "classification": "customer_operational"
        },
        {
          "key": "security_alert",
          "channel": "in_app",
          "classification": "restricted_security"
        },
        {
          "key": "invoice_notice",
          "channel": "email",
          "classification": "restricted_finance"
        },
        {
          "key": "privacy_request_update",
          "channel": "email",
          "classification": "restricted_privacy"
        }
      ],
      "required_controls": [
        "Customer-facing email/SMS notifications must verify consent or operational necessity before dispatch.",
        "Delivery attempts must use managed provider credentials, idempotency, suppression checks, and retry/outbox evidence.",
        "Sensitive notifications must store body content by artifact reference rather than inline payload text."
      ]
    },
    "notification_deliveries": [],
    "notification_delivery_summary": {
      "total_deliveries": 0,
      "by_status": {},
      "by_channel": {},
      "by_decision": {},
      "blocked_deliveries": 0,
      "queued_deliveries": 0
    },
    "webhook_assurance_plan": {
      "version": "2026-04-21.19",
      "mode": "signed_webhook_ingress_and_replay_window_assurance",
      "configured": {
        "webhook_assurance_required": false,
        "webhook_signature_required": false,
        "webhook_secret_configured": false,
        "webhook_max_age_seconds": 300,
        "webhook_replay_required": false
      },
      "supported_provider_families": [
        "billing",
        "calendar",
        "crm",
        "email",
        "esign",
        "identity",
        "observability",
        "sms",
        "warehouse"
      ],
      "required_controls": [
        "Every provider webhook must have signature verification, event-id idempotency, timestamp/replay-window checks, and dead-letter evidence.",
        "Provider-specific secrets must be rotated through managed secret references and never stored as plaintext state.",
        "Duplicate webhook event IDs must be safe-success, not double processing."
      ]
    },
    "webhook_signature_verifications": [],
    "webhook_assurance_summary": {
      "total_verifications": 0,
      "by_decision": {},
      "by_family": {},
      "latest_decision": null,
      "latest_blocking_findings": 0
    },
    "external_audit_plan": {
      "version": "2026-04-21.19",
      "mode": "external_audit_engagement_and_attestation_readiness",
      "configured": {
        "external_audit_required": false,
        "external_audit_register_configured": false,
        "evidence_vault_required": false,
        "evidence_vault_configured": false,
        "compliance_evidence_required": false
      },
      "frameworks": [
        "customer_security_review",
        "gdpr",
        "hipaa_readiness",
        "iso27001",
        "pci_readiness",
        "soc2_type_i",
        "soc2_type_ii"
      ],
      "default_evidence_collections": [
        "audit_events",
        "evidence_vault_records",
        "compliance_evidence_packs",
        "access_review_cycles",
        "vulnerability_scans",
        "provider_contract_test_runs",
        "incident_records"
      ],
      "required_controls": [
        "External audit engagements must identify framework, period, audit firm, evidence collections, control gaps, and evidence-vault references.",
        "Attestation status must be blocked when restricted evidence is not vaulted or compliance evidence packs are missing.",
        "Audit evidence shares must be permissioned, time-bound, and recorded in the immutable evidence/audit trail."
      ]
    },
    "external_audit_engagements": [],
    "external_audit_summary": {
      "total_engagements": 0,
      "by_status": {},
      "by_framework": {},
      "by_decision": {},
      "latest_status": null,
      "latest_decision": null
    },
    "client_application_security_plan": {
      "version": "2026-04-21.19",
      "mode": "oauth_client_browser_origin_redirect_uri_and_secret_rotation_governance",
      "configured": {
        "client_app_governance_required": false,
        "redirect_uri_allowlist_required": false,
        "oauth_pkce_required": false,
        "secret_manager_configured": false,
        "oauth_client_registry_configured": false,
        "allowed_origins_configured": false,
        "client_secret_rotation_days": 90
      },
      "required_controls": [
        "Every browser, mobile, server, partner, and machine client must be registered with owner, scopes, redirect URIs, origins, and credential references.",
        "Browser and mobile clients must use PKCE and exact redirect URI/origin allow-lists before production traffic.",
        "Server and machine clients must use managed secret references with rotation evidence and least-privilege scopes.",
        "Sensitive scopes must be reviewed before client activation and during every release promotion."
      ],
      "sensitive_scopes": [
        "admin",
        "export",
        "finance",
        "provider",
        "security",
        "tenant"
      ],
      "supported_app_types": [
        "browser",
        "machine",
        "mobile",
        "partner",
        "server"
      ]
    },
    "client_applications": [],
    "client_application_summary": {
      "total_clients": 0,
      "by_status": {},
      "by_type": {},
      "stale_secret_count": 0,
      "sensitive_clients": 0,
      "latest_client_at": null
    },
    "data_minimization_plan": {
      "version": "2026-04-21.19",
      "mode": "field_level_minimization_masking_and_collection_limitation",
      "configured": {
        "data_minimization_required": false,
        "field_level_masking_required": false,
        "default_pii_retention_days": 365,
        "dlp_scans_required": false,
        "privacy_subject_rights_required": false
      },
      "required_controls": [
        "Collect only launch-critical personal data fields and tag any extra collection with purpose and retention evidence.",
        "Mask or hash sensitive fields in exports, search indexes, support evidence, audit summaries, and operator-facing diagnostics.",
        "Run data-minimization assessments before enabling new providers, new exports, or customer-facing search features."
      ],
      "pii_key_hints": [
        "actor_id",
        "contact_email",
        "contact_name",
        "display_name",
        "email",
        "ip",
        "name",
        "phone",
        "subject_ref"
      ]
    },
    "data_minimization_assessments": [],
    "data_minimization_summary": {
      "total_assessments": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_finding_count": 0,
      "latest_assessed_at": null
    },
    "support_escalation_plan": {
      "version": "2026-04-21.19",
      "mode": "customer_support_escalation_sla_and_incident_linkage",
      "configured": {
        "support_escalations_required": false,
        "support_ticketing_configured": false,
        "incident_response_required": false,
        "sla_controls_required": false,
        "support_sla_hours": {
          "sev1": 4,
          "sev2": 12,
          "sev3": 48,
          "sev4": 120
        }
      },
      "required_controls": [
        "Customer-facing incidents and support escalations must be linked to SLA, tenant, owner, and status evidence.",
        "Sev1/Sev2 support escalations should link to incident records and alert-routing/pager evidence.",
        "Escalation resolution must record customer impact, remediation, and follow-up commitments for audit and SLA credit review."
      ]
    },
    "support_escalations": [],
    "support_escalation_summary": {
      "total_escalations": 0,
      "open_critical": 0,
      "by_status": {},
      "by_severity": {},
      "latest_escalation_at": null
    },
    "environment_promotion_plan": {
      "version": "2026-04-21.19",
      "mode": "staging_to_production_promotion_parity_and_cutover_evidence",
      "configured": {
        "environment_promotion_required": false,
        "staging_url_configured": false,
        "production_url_configured": false,
        "deployment_change_control_required": false,
        "release_manifest_required": false
      },
      "parity_checks": [
        "release_manifest_verified",
        "migration_manifest_verified",
        "configuration_baseline_evaluated",
        "secrets_present",
        "identity_boundary_configured",
        "database_cutover_rehearsed",
        "backup_drill_completed",
        "synthetic_monitor_passed",
        "rollback_plan_attached"
      ],
      "required_controls": [
        "Every production promotion must prove staging/production parity for release manifest, migrations, secrets, identity, telemetry, backup, and rollback evidence.",
        "Promotion must fail closed when release manifest or migration evidence is missing.",
        "Promotion records should be linked to deployment changes, maintenance windows, and customer communication plans."
      ]
    },
    "environment_promotions": [],
    "environment_promotion_summary": {
      "total_promotions": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_promoted_at": null
    },
    "database_operations_plan": {
      "version": "2026-04-21.19",
      "mode": "production_database_operations_and_cutover_runtime",
      "configured": {
        "database_operations_required": false,
        "database_configured": false,
        "database_replica_configured": false,
        "migration_tool": "manual_sql_manifest",
        "pool_size": 10,
        "pitr_required": false,
        "maintenance_window": "not_configured"
      },
      "required_controls": [
        "Production database access must use tenant-scoped repositories and never direct JSON-state writes.",
        "Migration application, rollback, PITR, connection pooling, replica health, and maintenance-window evidence must be recorded before cutover.",
        "Database operations checks must fail closed for missing primary database, missing PITR evidence, or excessive replication lag in production."
      ]
    },
    "database_operation_checks": [],
    "database_operation_summary": {
      "total_checks": 0,
      "by_decision": {},
      "by_environment": {},
      "latest_decision": null,
      "latest_check_at": null
    },
    "directory_sync_plan": {
      "version": "2026-04-21.19",
      "mode": "scim_directory_sync_and_deprovisioning_evidence",
      "configured": {
        "directory_sync_required": false,
        "scim_sync_required": false,
        "scim_base_configured": false,
        "idp_configured": false,
        "deprovisioning_sla_hours": 24
      },
      "required_controls": [
        "Directory sync must map IdP groups to NexaMarket roles and tenant memberships with audit evidence.",
        "Orphaned memberships and deprovisioning lag must be detected before tenant go-live.",
        "Production directory sync must fail closed when SCIM is required but no SCIM base URL is configured."
      ]
    },
    "directory_sync_runs": [],
    "directory_sync_summary": {
      "total_runs": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_run_at": null,
      "latest_orphaned_memberships": null
    },
    "provider_sandbox_plan": {
      "version": "2026-04-21.19",
      "mode": "provider_sandbox_validation_and_live_adapter_gate",
      "configured": {
        "provider_sandbox_required": false,
        "provider_contract_tests_required": false,
        "oauth_client_registry_configured": false,
        "webhook_secret_configured": false,
        "secret_manager_configured": false
      },
      "provider_families": [
        "billing",
        "calendar",
        "crm",
        "email",
        "esign",
        "identity",
        "observability",
        "sms",
        "warehouse"
      ],
      "required_controls": [
        "Each live provider must pass sandbox OAuth, webhook, retry, rate-limit, and reconciliation validations before production activation.",
        "Provider sandbox validations must record event coverage and must not expose plaintext provider credentials.",
        "Provider promotion should be blocked when sandbox validation, contract test, OAuth, or webhook evidence is missing."
      ]
    },
    "provider_sandbox_validations": [],
    "provider_sandbox_summary": {
      "total_validations": 0,
      "by_decision": {},
      "by_family": {},
      "latest_decision": null,
      "latest_validation_at": null
    },
    "document_custody_plan": {
      "version": "2026-04-21.19",
      "mode": "contract_document_custody_and_worm_evidence",
      "configured": {
        "document_custody_required": false,
        "object_store_configured": false,
        "evidence_vault_configured": false,
        "default_retention_days": 2555
      },
      "required_controls": [
        "Executed contracts and sensitive legal artifacts must have digest, custody class, retention, and verification evidence.",
        "Production custody records should reference external object storage or WORM evidence vault objects instead of inline document bodies.",
        "Legal holds must override expiry and archive/deletion workers."
      ]
    },
    "document_custody_records": [],
    "document_custody_summary": {
      "total_records": 0,
      "by_status": {},
      "by_classification": {},
      "legal_hold_count": 0,
      "latest_record_at": null
    },
    "error_budget_plan": {
      "version": "2026-04-21.19",
      "mode": "slo_error_budget_release_guard",
      "configured": {
        "error_budget_required": false,
        "alert_routing_required": false,
        "default_availability_target_pct": 99.5,
        "freeze_threshold_pct": 0.0,
        "review_threshold_pct": 20.0
      },
      "required_controls": [
        "Release promotion must consider error-budget burn, open incidents, and customer-impacting SLO breaches.",
        "Error-budget reports must tie SLO snapshots to deployment change control and customer communications.",
        "Production changes should freeze when the remaining budget is exhausted or burn rate is unsafe."
      ]
    },
    "error_budget_reports": [],
    "error_budget_summary": {
      "total_reports": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_remaining_pct": null,
      "latest_report_at": null
    },
    "customer_comms_plan": {
      "version": "2026-04-21.19",
      "mode": "customer_notification_and_status_communications_governance",
      "configured": {
        "customer_comms_required": false,
        "status_page_configured": false,
        "incident_pager_configured": false,
        "customer_notification_sla_minutes": 60
      },
      "required_controls": [
        "Customer-facing incident, maintenance, privacy, and SLA communications must be auditable and tied to a source object.",
        "Production communications must use approved templates, appropriate channels, and status-page references for customer-impacting incidents.",
        "Notification SLA evidence must be preserved for enterprise customers and trust reviews."
      ],
      "supported_categories": [
        "general",
        "incident",
        "maintenance",
        "privacy",
        "release",
        "security",
        "sla"
      ],
      "supported_channels": [
        "email",
        "in_app",
        "slack",
        "status_page",
        "teams",
        "webhook"
      ]
    },
    "customer_comms_events": [],
    "customer_comms_summary": {
      "total_events": 0,
      "by_status": {},
      "by_category": {},
      "latest_status": null,
      "latest_event_at": null
    },
    "service_catalog_plan": {
      "version": "2026-04-21.19",
      "mode": "service_ownership_dependency_runbook_and_slo_catalog_governance",
      "configured": {
        "service_catalog_required": false,
        "service_owner_review_days": 90,
        "runbook_automation_required": false,
        "telemetry_pipeline_required": false
      },
      "criticality_tiers": [
        "tier0",
        "tier1",
        "tier2",
        "tier3"
      ],
      "required_controls": [
        "Every production service must have an accountable owner, criticality tier, dependency list, SLO reference, data classification, and runbook reference.",
        "Tier0 and tier1 services require runbook, telemetry, and SLO evidence before production promotion.",
        "Ownership reviews must be refreshed on a fixed cadence and recorded as evidence."
      ]
    },
    "service_catalog_entries": [],
    "service_catalog_summary": {
      "total_services": 0,
      "by_criticality": {},
      "by_status": {},
      "stale_owner_reviews": 0,
      "missing_owner_count": 0,
      "latest_review_at": null
    },
    "circuit_breaker_plan": {
      "version": "2026-04-21.19",
      "mode": "provider_health_retry_budget_circuit_breaker_governance",
      "configured": {
        "integration_circuit_breakers_required": false,
        "redis_configured": false,
        "webhook_replay_required": false,
        "provider_contract_tests_required": false,
        "default_failure_threshold": 5,
        "default_cooldown_seconds": 300
      },
      "provider_families": [
        "billing",
        "calendar",
        "crm",
        "email",
        "esign",
        "identity",
        "notifications",
        "observability",
        "sms",
        "warehouse"
      ],
      "required_controls": [
        "Provider calls must be protected by circuit breakers, retry budgets, idempotency keys, and dead-letter evidence.",
        "Open circuits must create alert/outbox evidence and prevent unsafe synchronous provider calls.",
        "Circuit reset decisions require provider health, replay backlog, and contract-test evidence."
      ]
    },
    "integration_circuit_breakers": [],
    "integration_circuit_breaker_events": [],
    "integration_circuit_breaker_summary": {
      "total_breakers": 0,
      "open_breakers": 0,
      "by_status": {},
      "by_family": {},
      "latest_event_at": null
    },
    "privacy_impact_plan": {
      "version": "2026-04-21.19",
      "mode": "privacy_impact_dpias_processing_purpose_and_high_risk_release_gate",
      "configured": {
        "privacy_impact_required": false,
        "privacy_impact_policy_configured": false,
        "dlp_scans_required": false,
        "data_residency_required": false,
        "privacy_subject_rights_required": false
      },
      "risk_levels": [
        "critical",
        "high",
        "low",
        "medium"
      ],
      "required_controls": [
        "High-risk processing requires DPIA evidence, lawful basis, DLP scan linkage, residency assessment, and mitigation references.",
        "Automated decisioning or agent-assisted actions require privacy-risk review before release promotion.",
        "Privacy impact assessments must preserve subject-rights and retention obligations for every launch-critical data flow."
      ]
    },
    "privacy_impact_assessments": [],
    "privacy_impact_summary": {
      "total_assessments": 0,
      "high_risk_open": 0,
      "by_decision": {},
      "latest_assessment_at": null
    },
    "accessibility_plan": {
      "version": "2026-04-21.19",
      "mode": "wcag_accessibility_keyboard_screen_reader_and_release_gate_assurance",
      "configured": {
        "accessibility_assurance_required": false,
        "accessibility_standard": "WCAG2.2AA",
        "frontend_tests_required": false
      },
      "required_controls": [
        "Launch-critical UI paths require keyboard navigation, visible focus, semantic labels, contrast, and screen-reader checks.",
        "Critical accessibility violations block production promotion until remediated or formally accepted.",
        "Accessibility evidence should be linked to release and customer trust evidence for public-facing deployments."
      ]
    },
    "accessibility_scans": [],
    "accessibility_summary": {
      "total_scans": 0,
      "open_critical_violations": 0,
      "by_decision": {},
      "latest_scan_at": null
    },
    "cost_governance_plan": {
      "version": "2026-04-21.19",
      "mode": "finops_budget_cost_anomaly_and_infrastructure_spend_governance",
      "configured": {
        "cost_governance_required": false,
        "monthly_budget_usd": 0.0,
        "cost_anomaly_threshold_pct": 20.0,
        "database_configured": false,
        "object_store_configured": false
      },
      "required_controls": [
        "Production environments require budget thresholds, owner review, and anomaly evidence for database, worker, object storage, observability, and provider spend.",
        "Cost anomalies must be linked to deployment changes, provider syncs, or incident/resilience events when possible.",
        "Release promotion should review forecast spend and freeze when burn exceeds budget policy."
      ]
    },
    "cost_assessments": [],
    "cost_assessment_summary": {
      "total_assessments": 0,
      "by_decision": {},
      "latest_forecast_spend_usd": 0.0,
      "latest_assessment_at": null
    },
    "hypercare_plan": {
      "version": "2026-04-21.19",
      "mode": "post_launch_hypercare_and_rollback_watch",
      "configured": {
        "hypercare_required": false,
        "post_launch_hypercare_required": false,
        "hypercare_duration_days": 14,
        "support_ticketing_configured": false,
        "incident_pager_configured": false
      },
      "exit_criteria": [
        "no_sev1_or_sev2_incidents",
        "error_budget_green",
        "support_backlog_reviewed",
        "customer_comms_ready",
        "provider_health_green"
      ],
      "required_controls": [
        "Post-launch hypercare must record owner team, target tenants, exit criteria, incident/support posture, and rollback-watch status.",
        "Hypercare must preserve rollback-watch decisions until launch criteria are stable for the configured period.",
        "Critical customer impact during hypercare must create an escalation and incident-response handoff."
      ]
    },
    "hypercare_runs": [],
    "hypercare_reviews": [],
    "hypercare_summary": {
      "total_runs": 0,
      "open_runs": 0,
      "total_reviews": 0,
      "by_status": {},
      "by_decision": {},
      "latest_status": null,
      "latest_decision": null,
      "latest_open_incidents": 0,
      "latest_run_at": null,
      "latest_review_at": null
    },
    "domain_verification_plan": {
      "version": "2026-04-21.19",
      "mode": "tenant_custom_domain_dns_email_authentication_governance",
      "configured": {
        "custom_domain_required": false,
        "dns_provider_configured": false,
        "email_auth_required": false,
        "tls_certificate_provider_configured": false,
        "domain_verification_ttl_hours": 72
      },
      "supported_purposes": [
        "api",
        "dashboard",
        "email",
        "tracking"
      ],
      "required_controls": [
        "Tenant custom domains must prove DNS ownership before production traffic is routed.",
        "Customer email domains must pass SPF, DKIM, and DMARC checks before outbound sending or branded notifications are enabled.",
        "TLS certificate readiness, domain purpose, tenant owner, verification evidence, and recheck history must be auditable."
      ]
    },
    "domain_verifications": [],
    "domain_verification_summary": {
      "total_domains": 0,
      "verified_domains": 0,
      "blocked_domains": 0,
      "by_status": {},
      "by_purpose": {},
      "latest_status": null,
      "latest_checked_at": null
    },
    "warehouse_sync_plan": {
      "version": "2026-04-21.19",
      "mode": "tenant_scoped_warehouse_cdc_and_data_contract_sync_governance",
      "configured": {
        "warehouse_sync_required": false,
        "warehouse_configured": false,
        "cdc_pipeline_required": false,
        "data_contract_enforcement_required": false,
        "max_cdc_lag_seconds": 300
      },
      "supported_datasets": [
        "all",
        "audit",
        "crm",
        "finance",
        "product",
        "provider",
        "revenue",
        "workflow"
      ],
      "required_controls": [
        "Warehouse syncs must be tenant-scoped, watermark based, and auditable before analytics or board packets rely on them.",
        "CDC lag, row-level failures, PII export posture, and data-contract validation must be captured for each production sync.",
        "Production promotion should fail closed when warehouse infrastructure or data-contract evidence is missing."
      ]
    },
    "warehouse_sync_runs": [],
    "warehouse_sync_summary": {
      "total_runs": 0,
      "successful_runs": 0,
      "blocked_runs": 0,
      "by_status": {},
      "by_dataset": {},
      "latest_status": null,
      "latest_cdc_lag_seconds": null,
      "latest_synced_at": null
    },
    "disaster_recovery_plan": {
      "version": "2026-04-21.19",
      "mode": "regional_failover_rto_rpo_and_traffic_cutover_assurance",
      "configured": {
        "dr_failover_required": false,
        "secondary_region_configured": false,
        "secondary_region": "",
        "rto_minutes": 240,
        "rpo_minutes": 60,
        "multi_region_object_store_required": false,
        "object_store_configured": false
      },
      "required_controls": [
        "Production launch must document primary/secondary region assumptions and failover decision authority.",
        "Failover drills must record observed RTO/RPO, traffic-shift verification, rollback verification, and customer-impact notes.",
        "Disaster-recovery evidence must block production promotion when data loss or recovery time exceed customer commitments."
      ]
    },
    "dr_failover_drills": [],
    "disaster_recovery_summary": {
      "total_drills": 0,
      "passed_drills": 0,
      "blocked_drills": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_failover_minutes": null,
      "latest_data_loss_minutes": null
    },
    "finops_plan": {
      "version": "2026-04-21.19",
      "mode": "cloud_cost_budget_tagging_and_anomaly_governance",
      "configured": {
        "finops_required": false,
        "monthly_budget_usd": 0.0,
        "cost_anomaly_threshold_pct": 20.0,
        "cost_tagging_required": false
      },
      "required_controls": [
        "Production infrastructure must have owner/environment/tenant cost tags and budget evidence.",
        "Cost anomalies, idle workers, oversized storage, and unexpected provider usage must be assessed before release promotion.",
        "FinOps findings must be tied to an owner and preserved for operational review."
      ]
    },
    "finops_assessments": [],
    "finops_summary": {
      "total_assessments": 0,
      "blocked_assessments": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_budget_variance_pct": null,
      "latest_forecast_monthly_usd": null,
      "aggregate_forecast_monthly_usd": 0.0
    },
    "policy_exception_plan": {
      "version": "2026-04-21.19",
      "mode": "risk_acceptance_policy_exception_and_expiration_governance",
      "configured": {
        "policy_exceptions_required": false,
        "risk_acceptance_max_days": 30,
        "high_risk_exception_approval_required": true
      },
      "supported_severities": [
        "critical",
        "high",
        "low",
        "medium"
      ],
      "required_controls": [
        "Any production policy exception must include owner, reason, compensating controls, expiry, approval evidence, and closure history.",
        "Critical or high-risk exceptions must not be silently accepted without approval and release-gate visibility.",
        "Expired exceptions must create operational evidence and block promotion when policy-exception controls are required."
      ]
    },
    "policy_exceptions": [],
    "policy_exception_summary": {
      "total_exceptions": 0,
      "open_exceptions": 0,
      "critical_open_exceptions": 0,
      "by_status": {},
      "by_severity": {},
      "latest_status": null
    },
    "launch_readiness_plan": {
      "version": "2026-04-21.19",
      "mode": "production_launch_readiness_and_final_go_live_gate",
      "configured": {
        "launch_readiness_required": false,
        "launch_approval_board_configured": false,
        "production_launch_date": "",
        "required_control_count": 14
      },
      "required_controls": [
        "release_manifest_verified",
        "migration_manifest_verified",
        "database_cutover_rehearsed",
        "identity_cutover_rehearsed",
        "tenant_activation_passed",
        "provider_oauth_checked",
        "provider_sandbox_validated",
        "webhook_assurance_verified",
        "data_quality_gate_passed",
        "dlp_scan_clear",
        "error_budget_ok",
        "customer_comms_ready",
        "rollback_plan_confirmed",
        "support_hypercare_staffed"
      ],
      "release_decisions": [
        "launch_ready",
        "review",
        "blocked"
      ]
    },
    "launch_readiness_runs": [],
    "launch_readiness_summary": {
      "total_runs": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_blocking_findings": 0,
      "latest_run_at": null
    },
    "go_live_plan": {
      "version": "2026-04-21.19",
      "mode": "production_go_live_cutover_command_center",
      "configured": {
        "go_live_control_required": false,
        "launch_war_room_configured": false,
        "rollback_owner": ""
      },
      "default_steps": [
        "launch_readiness_approved",
        "maintenance_window_started",
        "final_backup_verified",
        "database_migration_confirmed",
        "identity_provider_cutover_confirmed",
        "provider_webhooks_observed",
        "customer_comms_sent",
        "hypercare_started"
      ],
      "states": [
        "ready",
        "in_progress",
        "completed",
        "aborted",
        "blocked"
      ]
    },
    "go_live_runs": [],
    "go_live_summary": {
      "total_runs": 0,
      "by_status": {},
      "latest_status": null,
      "latest_run_at": null
    },
    "runtime_parity_plan": {
      "version": "2026-04-21.19",
      "mode": "staging_to_production_runtime_parity_evidence",
      "configured": {
        "runtime_parity_required": false,
        "staging_url_configured": false,
        "production_url_configured": false,
        "parity_dimensions": [
          "config",
          "schema",
          "feature_flags",
          "providers",
          "secrets",
          "network",
          "observability",
          "workers"
        ]
      },
      "required_controls": [
        "Staging and production must share the same migration manifest and compatible feature-flag state before promotion.",
        "Provider, secret, network, telemetry, and worker parity must be reviewed before customer traffic cutover.",
        "Parity drift must create release evidence and block launch when high-risk production-only differences are found."
      ]
    },
    "runtime_parity_checks": [],
    "runtime_parity_summary": {
      "total_checks": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_drift_count": 0,
      "latest_check_at": null
    },
    "api_consumer_plan": {
      "version": "2026-04-21.19",
      "mode": "external_api_consumer_scope_credential_and_allowlist_governance",
      "configured": {
        "api_consumer_governance_required": false,
        "api_consumer_program_configured": false,
        "api_consumer_ip_allowlist_required": false,
        "api_consumer_rotation_days": 90,
        "allowed_scopes": [
          "audit:read",
          "contract:read",
          "crm:read",
          "crm:write",
          "export:read",
          "invoice:read",
          "provider:execute",
          "quote:read",
          "quote:write",
          "state:read",
          "workflow:read",
          "workflow:write"
        ]
      },
      "required_controls": [
        "Every API consumer must have an owner, approved scopes, tenant or partner context, and a managed credential reference.",
        "Public and partner consumers must provide callback/origin evidence and IP allow-lists when required.",
        "Credential rotation, revocation, and scope changes must be auditable and exportable before live API access."
      ]
    },
    "api_consumers": [],
    "api_consumer_summary": {
      "total_consumers": 0,
      "active_consumers": 0,
      "revoked_consumers": 0,
      "by_status": {},
      "by_type": {},
      "latest_created_at": null
    },
    "sso_claims_plan": {
      "version": "2026-04-21.19",
      "mode": "trusted_identity_claim_mapping_and_mfa_assertion_validation",
      "configured": {
        "sso_claim_mapping_required": false,
        "oidc_configured": false,
        "trusted_identity_headers": false,
        "sso_group_mapping_configured": false,
        "tenant_claim_name": "tenant_id",
        "required_claims": [
          "sub",
          "email",
          "tenant_id",
          "roles",
          "mfa_verified"
        ]
      },
      "required_controls": [
        "SSO tokens or trusted headers must assert a stable subject, email, tenant, role/groups, and MFA state.",
        "Group-to-role mapping must be versioned and tested before enabling trusted identity headers in production.",
        "Claim mapping drift must block production launch when tenant or privileged-role claims are missing."
      ]
    },
    "sso_claims_summary": {
      "total_checks": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_blocking_findings": 0
    },
    "abuse_detection_plan": {
      "version": "2026-04-21.19",
      "mode": "tenant_api_export_provider_and_auth_abuse_detection",
      "configured": {
        "abuse_detection_required": false,
        "alert_routing_required": false,
        "log_shipping_required": false,
        "abuse_export_threshold": 1000,
        "abuse_failed_auth_threshold": 10
      },
      "required_controls": [
        "Export spikes, rate-limit pressure, failed identity checks, webhook replay anomalies, and provider action bursts must create security signals.",
        "Critical or high abuse signals must route to alerting before production API consumers are enabled.",
        "Signals must preserve tenant, actor, route, source collection, and remediation evidence for security review."
      ]
    },
    "abuse_detection_signals": [],
    "abuse_detection_summary": {
      "total_scans": 0,
      "total_signals": 0,
      "critical_or_high_signals": 0,
      "by_severity": {},
      "by_decision": {}
    },
    "traffic_management_plan": {
      "version": "2026-04-21.19",
      "mode": "canary_blue_green_traffic_shift_and_health_gate_control",
      "configured": {
        "traffic_management_required": false,
        "traffic_controller_configured": false,
        "canary_max_error_rate_pct": 2.0,
        "supported_strategies": [
          "blue_green",
          "canary",
          "maintenance",
          "rolling",
          "shadow"
        ]
      },
      "required_controls": [
        "Production traffic changes must be represented as explicit canary/blue-green route records before cutover.",
        "Canary advancement must check health, error rate, runtime parity, and rollback owner evidence.",
        "Rollback must set traffic to zero for the candidate release and preserve operator timeline evidence."
      ]
    },
    "traffic_management_summary": {
      "total_routes": 0,
      "active_routes": 0,
      "rolled_back_routes": 0,
      "by_status": {},
      "by_decision": {}
    },
    "rollback_execution_plan": {
      "version": "2026-04-21.19",
      "mode": "production_rollback_execution_and_post_rollback_validation",
      "configured": {
        "rollback_execution_required": false,
        "rollback_owner_configured": false,
        "rollback_time_target_minutes": 60,
        "backup_plan_required": false
      },
      "required_controls": [
        "Rollback runs must capture trigger, affected services, rollback plan reference, owner, validation evidence, and final decision.",
        "Rollback completion must verify traffic reversion, database/schema safety, provider queue status, customer comms, and monitoring recovery.",
        "Post-rollback validation must create release evidence and feed the launch/hypercare decision path."
      ]
    },
    "rollback_execution_summary": {
      "total_runs": 0,
      "open_runs": 0,
      "completed_runs": 0,
      "by_status": {},
      "by_decision": {}
    },
    "data_contract_enforcement_plan": {
      "version": "2026-04-21.19",
      "mode": "schema_contract_runtime_gate_and_release_evidence",
      "configured": {
        "data_contract_enforcement_required": false,
        "database_configured": false,
        "required_contracts": [
          "tenant_id_required",
          "actor_id_required",
          "immutable_audit_event",
          "outbox_event_for_mutation",
          "pii_classification_declared",
          "pagination_required"
        ]
      },
      "required_controls": [
        "Every production resource collection must declare tenant, actor, PII, pagination, audit, and outbox contracts.",
        "Contract failures should block release promotion when data-contract enforcement is required.",
        "Contract evidence must be exportable and tied to migration/release evidence before database cutover."
      ]
    },
    "data_contract_summary": {
      "total_runs": 0,
      "by_decision": {},
      "by_domain": {},
      "latest_run_id": null,
      "latest_decision": null,
      "latest_missing_contract_count": 0
    },
    "egress_gateway_plan": {
      "version": "2026-04-21.19",
      "mode": "provider_egress_gateway_allowlist_and_data_class_review",
      "configured": {
        "egress_gateway_required": false,
        "egress_gateway_configured": false,
        "egress_allowlist_required": false,
        "egress_allowlist_configured": false
      },
      "required_controls": [
        "All live provider and warehouse egress must pass through a controlled gateway or equivalent allow-listed network path.",
        "Restricted data classes require purpose, destination, and provider-family evidence before egress is allowed.",
        "Policy checks should be recorded before enabling provider execution, webhooks, exports, or data warehouse syncs."
      ]
    },
    "egress_gateway_summary": {
      "total_checks": 0,
      "by_decision": {},
      "by_provider": {},
      "latest_check_id": null,
      "latest_decision": null
    },
    "secret_rotation_plan": {
      "version": "2026-04-21.19",
      "mode": "managed_secret_rotation_campaigns_and_credential_age_evidence",
      "configured": {
        "secret_rotation_campaigns_required": false,
        "secret_manager_configured": false,
        "rotation_sla_days": 90
      },
      "required_controls": [
        "Credential rotation must be represented as an auditable campaign with scope, owner, due date, and completion evidence.",
        "Provider, API consumer, webhook, OIDC, and KMS references should rotate through a managed secret store, not plaintext state.",
        "Overdue or blocked campaigns should prevent production promotion when secret-rotation enforcement is required."
      ]
    },
    "secret_rotation_campaigns": [],
    "secret_rotation_summary": {
      "total_campaigns": 0,
      "open_campaigns": 0,
      "completed_campaigns": 0,
      "blocked_campaigns": 0,
      "by_status": {},
      "by_scope": {}
    },
    "payment_risk_plan": {
      "version": "2026-04-21.19",
      "mode": "payment_provider_risk_reconciliation_and_high_value_control",
      "configured": {
        "payment_risk_controls_required": false,
        "billing_reconciliation_required": false,
        "provider_oauth_required": false,
        "high_value_threshold_usd": 100000.0
      },
      "required_controls": [
        "High-value payments, refunds, settlements, and payouts should require risk assessment before provider execution.",
        "Payment-risk evidence should link provider OAuth health, billing reconciliation, invoice/settlement references, and approval evidence.",
        "Blocking risk decisions should prevent silent payment success and create outbox/audit evidence for finance review."
      ]
    },
    "payment_risk_summary": {
      "total_assessments": 0,
      "by_decision": {},
      "by_method": {},
      "latest_assessment_id": null,
      "latest_decision": null
    },
    "oncall_coverage_plan": {
      "version": "2026-04-21.19",
      "mode": "production_oncall_rota_escalation_and_handoff_evidence",
      "configured": {
        "oncall_coverage_required": false,
        "incident_pager_configured": false,
        "minimum_coverage_hours": 24
      },
      "required_controls": [
        "Launch and production operations require named primary and secondary on-call coverage for critical services.",
        "Coverage checks should verify escalation policy, pager/status route, handoff timing, and service ownership before go-live.",
        "Missing coverage should block production promotion for customer-facing control-plane services."
      ]
    },
    "oncall_coverage_summary": {
      "total_checks": 0,
      "by_decision": {},
      "by_service": {},
      "latest_check_id": null,
      "latest_decision": null
    },
    "incident_postmortem_plan": {
      "version": "2026-04-21.19",
      "mode": "incident_postmortem_action_item_and_recurring_learning_control",
      "configured": {
        "incident_postmortems_required": false,
        "postmortem_sla_days": 5,
        "incident_response_required": false
      },
      "required_controls": [
        "Severity-one and severity-two incidents require postmortem evidence with root cause, customer impact, action items, owner, and due dates.",
        "Postmortems should link to alerts, incidents, runbook executions, customer communications, and deployment/rollback evidence.",
        "Open critical action items should appear in readiness and release promotion evidence until closed or risk-accepted."
      ]
    },
    "incident_postmortems": [],
    "incident_postmortem_summary": {
      "total_postmortems": 0,
      "open_postmortems": 0,
      "completed_postmortems": 0,
      "open_action_items": 0,
      "by_status": {},
      "by_severity": {}
    },
    "data_backfill_plan": {
      "version": "2026-04-21.19",
      "mode": "production_data_backfill_and_migration_remediation_governance",
      "configured": {
        "data_backfill_required": false,
        "database_configured": false,
        "backfill_worker_configured": false,
        "max_allowed_diff_count": 0,
        "supported_targets": [
          "tenant_id_backfill",
          "audit_event_actor_backfill",
          "workflow_run_foreign_key_backfill",
          "search_index_backfill",
          "provider_connection_reference_backfill"
        ]
      },
      "required_controls": [
        "Backfills must run as auditable jobs with source snapshot, target collection, expected record count, processed record count, and diff/error evidence.",
        "Production promotion must block when a required backfill has unapproved diffs, failed rows, or no rollback reference.",
        "Tenant identifiers, actor references, workflow foreign keys, provider references, and search indexes must be remediated before database cutover."
      ]
    },
    "data_backfill_summary": {
      "total_runs": 0,
      "completed_runs": 0,
      "blocked_runs": 0,
      "by_status": {},
      "by_decision": {},
      "latest_decision": null,
      "latest_target": null
    },
    "email_deliverability_plan": {
      "version": "2026-04-21.19",
      "mode": "production_email_domain_reputation_bounce_and_suppression_governance",
      "configured": {
        "email_deliverability_required": false,
        "email_provider_configured": false,
        "bounce_threshold_pct": 2.0,
        "complaint_threshold_pct": 0.1
      },
      "required_controls": [
        "Every outbound email domain must have SPF, DKIM, and DMARC evidence before production sending.",
        "Bounce, complaint, and unsubscribe latency thresholds must be evaluated before campaign or notification cutover.",
        "Suppression and consent evidence must be connected before provider-send routes are enabled for live contacts."
      ]
    },
    "email_deliverability_summary": {
      "total_assessments": 0,
      "blocked_assessments": 0,
      "passing_assessments": 0,
      "by_decision": {},
      "latest_domain": null,
      "latest_decision": null
    },
    "contract_obligation_plan": {
      "version": "2026-04-21.19",
      "mode": "post_signature_contract_obligation_owner_due_date_and_evidence_governance",
      "configured": {
        "contract_obligations_required": false,
        "contract_repository_configured": false,
        "default_obligation_sla_days": 30
      },
      "supported_types": [
        "custom_clause",
        "dpa",
        "implementation",
        "renewal_notice",
        "security_review",
        "sla_commitment",
        "usage_report"
      ],
      "required_controls": [
        "Executed contracts must produce owner-assigned obligations for security, privacy, SLA, renewal, and customer-success commitments.",
        "Obligations require due dates, evidence references, completion events, and audit/outbox evidence before being marked complete.",
        "Production finance/customer-success workflows should block silent closeout when critical contract obligations are overdue."
      ]
    },
    "contract_obligations": [],
    "contract_obligation_summary": {
      "total_obligations": 0,
      "open_obligations": 0,
      "completed_obligations": 0,
      "overdue_obligations": 0,
      "by_status": {}
    },
    "customer_health_plan": {
      "version": "2026-04-21.19",
      "mode": "customer_success_health_risk_sla_and_renewal_governance",
      "configured": {
        "customer_health_governance_required": false,
        "customer_success_system_configured": false,
        "health_score_review_threshold": 70,
        "health_score_block_threshold": 45
      },
      "required_controls": [
        "Customer health assessments must combine usage, support, SLA, renewal, contract obligation, and billing signals before renewal or expansion workflows.",
        "At-risk customers need owner, playbook, next-step, and executive-review evidence before automated revenue actions proceed.",
        "SLA breaches and overdue obligations must be surfaced into customer success and release/incident decisions."
      ]
    },
    "customer_health_summary": {
      "total_assessments": 0,
      "at_risk_accounts": 0,
      "by_decision": {},
      "latest_account_id": null,
      "latest_health_score": null
    },
    "knowledge_governance_plan": {
      "version": "2026-04-21.19",
      "mode": "knowledge_base_runbook_customer_help_and_trust_document_governance",
      "configured": {
        "knowledge_governance_required": false,
        "knowledge_base_url_configured": false,
        "default_review_days": 90
      },
      "categories": [
        "api_docs",
        "customer_help",
        "internal_policy",
        "runbook",
        "sales_enablement",
        "security_trust"
      ],
      "required_controls": [
        "Runbooks, customer help, API docs, trust-center articles, and policies must have owner, version, approval, review date, and stale-content evidence.",
        "Articles containing PII, pricing commitments, legal claims, or security claims must carry DLP/legal/security review evidence.",
        "Knowledge reviews should be exportable and connected to incident, support, release, and trust-evidence workflows."
      ]
    },
    "knowledge_reviews": [],
    "knowledge_governance_summary": {
      "total_reviews": 0,
      "approved_reviews": 0,
      "blocked_reviews": 0,
      "pending_reviews": 0,
      "by_status": {},
      "latest_article_ref": null
    },
    "infrastructure_policy_plan": {
      "version": "2026-04-21.19",
      "mode": "infrastructure_as_code_policy_governance",
      "configured": {
        "infrastructure_policy_required": false,
        "iac_repository_configured": false,
        "cloud_account_configured": false,
        "kubernetes_namespace": "",
        "policy_pack_ref": "",
        "required_controls": [
          "network_policy",
          "iam_least_privilege",
          "encryption_at_rest",
          "backup_tags",
          "policy_pack"
        ]
      },
      "required_controls": [
        "Production infrastructure must be versioned as IaC.",
        "Network policy, IAM least privilege, encryption, backup tags, and policy packs must be verified before launch."
      ]
    },
    "infrastructure_policy_summary": {
      "total_checks": 0,
      "blocked_checks": 0,
      "passed_checks": 0,
      "by_decision": {},
      "latest_decision": null
    },
    "release_smoke_test_plan": {
      "version": "2026-04-21.19",
      "mode": "release_smoke_and_revenue_path_validation",
      "configured": {
        "release_smoke_tests_required": false,
        "smoke_test_runner_configured": false,
        "minimum_pass_rate": 100.0,
        "default_steps": [
          "state_load",
          "lead_capture_or_seed_lead",
          "quote_path",
          "contract_path",
          "invoice_path",
          "workflow_path",
          "audit_or_outbox_evidence"
        ]
      },
      "required_controls": [
        "Production promotion must record a smoke journey for state, CRM, quote, contract, invoice, workflow, and audit/outbox evidence."
      ]
    },
    "release_smoke_summary": {
      "total_runs": 0,
      "passed_runs": 0,
      "blocked_runs": 0,
      "by_decision": {},
      "latest_pass_rate": null,
      "latest_decision": null
    },
    "legal_hold_enforcement_plan": {
      "version": "2026-04-21.19",
      "mode": "legal_hold_safe_retention_enforcement",
      "configured": {
        "legal_hold_enforcement_required": false,
        "retention_scans_required": false,
        "archive_lifecycle_required": false,
        "evidence_vault_configured": false
      },
      "required_controls": [
        "Archive/delete actions must be tested against legal holds before execution.",
        "Blocked retention actions must keep object, reason, actor, tenant, and evidence references."
      ]
    },
    "legal_hold_enforcement_summary": {
      "total_runs": 0,
      "blocked_runs": 0,
      "total_blocked_actions": 0,
      "by_decision": {},
      "latest_decision": null
    },
    "revenue_close_validation_plan": {
      "version": "2026-04-21.19",
      "mode": "crm_quote_contract_invoice_workflow_closeout_validation",
      "configured": {
        "revenue_close_validation_required": false,
        "billing_reconciliation_required": false,
        "minimum_closed_won_evidence": 1
      },
      "required_controls": [
        "Validate CRM, quote, contract, invoice, workflow, and audit/outbox links before production closeout automation."
      ]
    },
    "revenue_close_validation_summary": {
      "total_runs": 0,
      "blocked_runs": 0,
      "passed_runs": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_coverage_score": null
    },
    "support_readiness_plan": {
      "version": "2026-04-21.19",
      "mode": "customer_support_and_status_page_launch_readiness",
      "configured": {
        "support_readiness_required": false,
        "support_ticketing_configured": false,
        "knowledge_base_configured": false,
        "status_page_configured": false,
        "required_signals": [
          "support_ticketing",
          "knowledge_base",
          "status_page",
          "customer_comms",
          "oncall",
          "sla_policy"
        ]
      },
      "required_controls": [
        "Customer-facing launch requires support routing, status page, comms, SLA policy, on-call, and knowledge-base readiness."
      ]
    },
    "support_readiness_summary": {
      "total_runs": 0,
      "blocked_runs": 0,
      "passed_runs": 0,
      "by_decision": {},
      "latest_decision": null,
      "latest_ready_signal_count": null
    },
    "schema_registry": [
      {
        "name": "stable_error_envelope",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "error.code",
          "error.message",
          "error.field_errors",
          "correlation_id"
        ]
      },
      {
        "name": "request_audit_event",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "actor_id",
          "actor_role",
          "tenant_id",
          "method",
          "path",
          "status_code",
          "correlation_id",
          "idempotency_key"
        ]
      },
      {
        "name": "openapi_3_1_contract",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "openapi",
          "info.version",
          "paths",
          "components.securitySchemes",
          "components.schemas.ErrorEnvelope"
        ]
      },
      {
        "name": "transactional_outbox_event",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "id",
          "event_type",
          "aggregate_type",
          "aggregate_id",
          "status",
          "attempts",
          "next_attempt_at",
          "payload"
        ]
      },
      {
        "name": "migration_manifest",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "schema_version",
          "application_version",
          "dialect",
          "migrations.file",
          "migrations.sha256"
        ]
      },
      {
        "name": "rate_limit_counter",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "actor_id",
          "tenant_id",
          "method",
          "path",
          "bucket",
          "count"
        ]
      },
      {
        "name": "release_evidence_manifest",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "version",
          "build_digest",
          "files.path",
          "files.sha256",
          "migration_manifest",
          "route_count"
        ]
      },
      {
        "name": "signed_webhook_receipt",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "id",
          "provider",
          "event_id",
          "signature_status",
          "signature_verified",
          "payload_fingerprint",
          "duplicate_count"
        ]
      },
      {
        "name": "browser_csrf_control",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "required",
          "token_configured",
          "header",
          "origin",
          "decision"
        ]
      },
      {
        "name": "paginated_resource_envelope",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "collection",
          "items",
          "page.limit",
          "page.offset",
          "page.total",
          "page.next_offset"
        ]
      },
      {
        "name": "provider_integration_contract",
        "status": "active",
        "version": "2026-04-20",
        "fields": [
          "provider_family",
          "required_capabilities",
          "webhook_events",
          "contract_tests"
        ]
      },
      {
        "name": "tenant_scoped_resource_envelope",
        "status": "active",
        "version": "2026-04-20.4",
        "fields": [
          "tenant_scope.tenant_id",
          "tenant_scope.cross_tenant",
          "items.tenant_id",
          "redacted"
        ]
      },
      {
        "name": "export_job_artifact",
        "status": "active",
        "version": "2026-04-20.4",
        "fields": [
          "id",
          "collection",
          "status",
          "tenant_id",
          "sha256",
          "expires_at",
          "record_count"
        ]
      },
      {
        "name": "recovery_point_manifest",
        "status": "active",
        "version": "2026-04-20.4",
        "fields": [
          "id",
          "tenant_id",
          "state_digest",
          "collections",
          "captured_at",
          "restore_mode"
        ]
      },
      {
        "name": "repository_contract_boundary",
        "status": "active",
        "version": "2026-04-20.5",
        "fields": [
          "domain",
          "repositories",
          "tables",
          "required_predicates",
          "write_pattern",
          "read_pattern"
        ]
      },
      {
        "name": "data_quality_run",
        "status": "active",
        "version": "2026-04-20.5",
        "fields": [
          "id",
          "score",
          "decision",
          "severity_counts",
          "findings",
          "actor_id",
          "tenant_id"
        ]
      },
      {
        "name": "privacy_retention_scan",
        "status": "active",
        "version": "2026-04-20.5",
        "fields": [
          "id",
          "mode",
          "decision",
          "action_count",
          "actions",
          "actor_id",
          "tenant_id"
        ]
      },
      {
        "name": "secret_reference_inventory",
        "status": "active",
        "version": "2026-04-20.5",
        "fields": [
          "credential_ref",
          "connection_id",
          "auth_mode",
          "status",
          "expires_at",
          "external_secret_pointer"
        ]
      },
      {
        "name": "policy_evaluation_receipt",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "id",
          "policy_bundle_version",
          "decision",
          "applied_policies",
          "violations",
          "obligations",
          "context"
        ]
      },
      {
        "name": "route_governance_catalog",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "routes.rule",
          "routes.methods",
          "routes.domain",
          "routes.sensitivity",
          "routes.controls",
          "module_boundaries"
        ]
      },
      {
        "name": "privileged_access_request",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "id",
          "capability",
          "reason",
          "tenant_id",
          "target_tenant_id",
          "status",
          "decision"
        ]
      },
      {
        "name": "break_glass_session",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "id",
          "capability",
          "reason",
          "actor_id",
          "tenant_id",
          "expires_at",
          "status"
        ]
      },
      {
        "name": "provider_contract_test_run",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "id",
          "provider_family",
          "connection_id",
          "status",
          "finding_count",
          "findings"
        ]
      },
      {
        "name": "incident_record",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "id",
          "title",
          "severity",
          "status",
          "affected_domains",
          "timeline",
          "resolution"
        ]
      },
      {
        "name": "slo_snapshot_evidence",
        "status": "active",
        "version": "2026-04-20.6",
        "fields": [
          "id",
          "window",
          "api_availability_pct",
          "workflow_completion_pct",
          "open_incidents",
          "status"
        ]
      },
      {
        "name": "dlp_scan_evidence",
        "status": "active",
        "version": "2026-04-20.7",
        "fields": [
          "id",
          "scope",
          "decision",
          "blocking_finding_count",
          "severity_counts",
          "findings",
          "actor_id",
          "tenant_id"
        ]
      },
      {
        "name": "feature_flag_control",
        "status": "active",
        "version": "2026-04-20.7",
        "fields": [
          "key",
          "enabled",
          "risk",
          "category",
          "owner",
          "updated_at",
          "last_changed_by",
          "reason"
        ]
      },
      {
        "name": "deployment_change_control",
        "status": "active",
        "version": "2026-04-20.7",
        "fields": [
          "id",
          "release_version",
          "target_environment",
          "risk",
          "status",
          "rollback_plan",
          "promotion_evidence"
        ]
      },
      {
        "name": "scheduler_run_evidence",
        "status": "active",
        "version": "2026-04-20.7",
        "fields": [
          "id",
          "mode",
          "selected_tasks",
          "executed_tasks",
          "actions",
          "status",
          "actor_id",
          "tenant_id"
        ]
      },
      {
        "name": "service_account_control",
        "status": "active",
        "version": "2026-04-20.8",
        "fields": [
          "id",
          "name",
          "tenant_id",
          "scopes",
          "credential_ref",
          "token_version",
          "status",
          "last_token_rotation_at"
        ]
      },
      {
        "name": "object_artifact_manifest",
        "status": "active",
        "version": "2026-04-20.8",
        "fields": [
          "id",
          "artifact_type",
          "object_key",
          "content_type",
          "size_bytes",
          "sha256",
          "classification",
          "malware_scan_status",
          "expires_at"
        ]
      },
      {
        "name": "webhook_replay_job",
        "status": "active",
        "version": "2026-04-20.8",
        "fields": [
          "id",
          "provider",
          "event_id",
          "receipt_id",
          "payload_fingerprint",
          "mode",
          "status",
          "reason",
          "requested_by"
        ]
      },
      {
        "name": "synthetic_monitor_run",
        "status": "active",
        "version": "2026-04-20.8",
        "fields": [
          "id",
          "status",
          "mode",
          "probes",
          "probe_results",
          "failed_probe_count",
          "warning_probe_count",
          "tenant_id"
        ]
      },
      {
        "name": "consent_preference_event",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "action",
          "channel",
          "subject_ref",
          "email",
          "lawful_basis",
          "status",
          "actor_id",
          "tenant_id"
        ]
      },
      {
        "name": "billing_reconciliation_run",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "decision",
          "invoice_count",
          "provider_payment_evidence_count",
          "finding_count",
          "severity_counts",
          "findings"
        ]
      },
      {
        "name": "resilience_drill_run",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "scenario",
          "mode",
          "decision",
          "observed_controls",
          "gap_count",
          "actor_id",
          "tenant_id"
        ]
      },
      {
        "name": "data_residency_transfer_event",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "tenant_id",
          "source_region",
          "target_region",
          "data_class",
          "legal_basis",
          "decision",
          "blockers"
        ]
      },
      {
        "name": "api_lifecycle_check",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "suite",
          "target_version",
          "status",
          "route_count",
          "missing_critical_routes",
          "blockers",
          "warnings"
        ]
      },
      {
        "name": "data_residency_assessment",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "tenant_id",
          "target_region",
          "decision",
          "scanned_record_count",
          "severity_counts",
          "findings"
        ]
      },
      {
        "name": "backup_drill_evidence",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "mode",
          "status",
          "recovery_point_id",
          "measured_rto_minutes",
          "measured_rpo_minutes",
          "findings"
        ]
      },
      {
        "name": "supply_chain_scan",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "mode",
          "status",
          "package_count",
          "sbom",
          "finding_count",
          "findings"
        ]
      },
      {
        "name": "compliance_evidence_pack",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "framework",
          "scope",
          "decision",
          "controls",
          "gaps",
          "release_version",
          "actor_id"
        ]
      },
      {
        "name": "kms_key_control",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "alias",
          "purpose",
          "classification",
          "tenant_id",
          "status",
          "key_ref",
          "key_version",
          "last_rotated_at"
        ]
      },
      {
        "name": "vulnerability_scan_evidence",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "scope",
          "mode",
          "decision",
          "blocking_finding_count",
          "severity_counts",
          "findings"
        ]
      },
      {
        "name": "configuration_baseline_evidence",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "profile",
          "required_control_keys",
          "runtime_snapshot_hash",
          "last_decision",
          "last_drift_count"
        ]
      },
      {
        "name": "evidence_seal_attestation",
        "status": "active",
        "version": "2026-04-20.10",
        "fields": [
          "id",
          "source",
          "purpose",
          "payload_hash",
          "signature",
          "verification_status",
          "verifications"
        ]
      },
      {
        "name": "telemetry_snapshot_evidence",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "status",
          "signal_count",
          "configured",
          "blockers",
          "warnings",
          "tenant_id"
        ]
      },
      {
        "name": "alert_routing_event",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "title",
          "severity",
          "source",
          "signal",
          "entity_ref",
          "status",
          "tenant_id",
          "timeline"
        ]
      },
      {
        "name": "data_lineage_run",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "scope",
          "mode",
          "decision",
          "scanned_counts",
          "finding_count",
          "findings",
          "tenant_id"
        ]
      },
      {
        "name": "capacity_assessment_evidence",
        "status": "active",
        "version": "2026-04-20.11",
        "fields": [
          "id",
          "mode",
          "decision",
          "expected_rps",
          "observed_p95_ms",
          "worker_count",
          "outbox_backlog",
          "findings"
        ]
      },
      {
        "name": "session_risk_assessment",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "session_id",
          "actor_id",
          "tenant_id",
          "risk_score",
          "decision",
          "signals",
          "created_at"
        ]
      },
      {
        "name": "search_index_run",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "scope",
          "mode",
          "decision",
          "document_count",
          "source_counts",
          "findings",
          "tenant_id"
        ]
      },
      {
        "name": "queue_autoscaling_assessment",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "queue_depths",
          "total_backlog",
          "current_workers",
          "recommended_workers",
          "findings"
        ]
      },
      {
        "name": "migration_rollback_rehearsal",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "target_migration_id",
          "manifest_version",
          "recovery_point_count",
          "backup_drill_count",
          "findings"
        ]
      },
      {
        "name": "database_cutover_rehearsal",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "target_version",
          "schema_version",
          "migration_count",
          "shadow_read_pass_rate_pct",
          "dual_write_mismatch_count",
          "rollback_rehearsed"
        ]
      },
      {
        "name": "schema_drift_check",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "schema_version",
          "target_schema_version",
          "migration_count",
          "release_manifest_version",
          "findings"
        ]
      },
      {
        "name": "query_performance_assessment",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "collection",
          "observed_p95_ms",
          "query_p95_target_ms",
          "slow_query_count",
          "missing_index_count"
        ]
      },
      {
        "name": "archive_lifecycle_run",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "candidate_count",
          "eligible_count",
          "blocked_by_legal_hold_count",
          "action_count",
          "actions"
        ]
      },
      {
        "name": "queue_sla_scan",
        "status": "active",
        "version": "2026-04-20.12",
        "fields": [
          "id",
          "mode",
          "decision",
          "total_backlog",
          "pending_outbox_count",
          "dead_letter_count",
          "stale_lease_count",
          "findings"
        ]
      },
      {
        "name": "privacy_subject_request",
        "status": "active",
        "version": "2026-04-20.13",
        "fields": [
          "id",
          "request_type",
          "status",
          "subject_ref",
          "email_hash_ref",
          "verification_status",
          "matched_record_count",
          "due_at",
          "tenant_id"
        ]
      },
      {
        "name": "tenant_entitlement_assessment",
        "status": "active",
        "version": "2026-04-20.13",
        "fields": [
          "id",
          "mode",
          "decision",
          "tenant_ids",
          "plan",
          "limits",
          "usage_totals",
          "finding_count",
          "findings"
        ]
      },
      {
        "name": "usage_metering_event",
        "status": "active",
        "version": "2026-04-20.13",
        "fields": [
          "id",
          "tenant_id",
          "meter",
          "quantity",
          "source",
          "object_ref",
          "actor_id",
          "created_at"
        ]
      },
      {
        "name": "network_posture_snapshot",
        "status": "active",
        "version": "2026-04-20.13",
        "fields": [
          "id",
          "mode",
          "decision",
          "observed_ingress_controls",
          "observed_egress_domains",
          "mtls_enabled",
          "waf_enabled",
          "findings"
        ]
      },
      {
        "name": "maintenance_window",
        "status": "active",
        "version": "2026-04-20.13",
        "fields": [
          "id",
          "title",
          "scope",
          "status",
          "freeze_level",
          "start_at",
          "end_at",
          "change_id",
          "notification_ref",
          "timeline"
        ]
      },
      {
        "name": "identity_cutover_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider",
          "decision",
          "configured",
          "tested_capabilities",
          "missing_capabilities",
          "findings",
          "tenant_id"
        ]
      },
      {
        "name": "tenant_activation_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "tenant_id",
          "tenant_name",
          "data_region",
          "plan",
          "completed_checks",
          "missing_checks",
          "decision",
          "status"
        ]
      },
      {
        "name": "evidence_vault_record",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "evidence_type",
          "source_collection",
          "source_id",
          "classification",
          "payload_digest",
          "vault_ref",
          "verification_status"
        ]
      },
      {
        "name": "provider_oauth_check",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider_family",
          "connection_id",
          "decision",
          "scopes",
          "credential_ref",
          "token_expires_in_days",
          "findings"
        ]
      },
      {
        "name": "data_migration_wave",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "name",
          "source_store",
          "target_store",
          "collections",
          "status",
          "decision",
          "validation_pass_rate_pct",
          "diff_count",
          "findings"
        ]
      },
      {
        "name": "provider_action_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider_family",
          "connection_id",
          "action_type",
          "mode",
          "status",
          "decision",
          "idempotency_key",
          "findings"
        ]
      },
      {
        "name": "notification_delivery",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "channel",
          "template_key",
          "audience",
          "status",
          "decision",
          "consent_status",
          "suppressed",
          "findings"
        ]
      },
      {
        "name": "webhook_signature_verification",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider_family",
          "event_id",
          "signature_valid",
          "timestamp_skew_seconds",
          "duplicate_event",
          "decision",
          "findings"
        ]
      },
      {
        "name": "external_audit_engagement",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "framework",
          "audit_firm",
          "period_start",
          "period_end",
          "status",
          "decision",
          "evidence_collections",
          "attestation_ref"
        ]
      },
      {
        "name": "database_operation_check",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "target_environment",
          "decision",
          "observed_connections",
          "replication_lag_seconds",
          "pitr_verified",
          "findings"
        ]
      },
      {
        "name": "directory_sync_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider",
          "decision",
          "synced_users",
          "synced_groups",
          "deprovisioned_users",
          "orphaned_memberships",
          "findings"
        ]
      },
      {
        "name": "provider_sandbox_validation",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider_family",
          "provider_name",
          "connection_id",
          "tested_events",
          "sandbox_result",
          "decision",
          "findings"
        ]
      },
      {
        "name": "document_custody_record",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "object_type",
          "object_id",
          "artifact_ref",
          "sha256",
          "classification",
          "retention_days",
          "legal_hold",
          "verification_status"
        ]
      },
      {
        "name": "error_budget_report",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "service",
          "window",
          "availability_target_pct",
          "observed_availability_pct",
          "error_budget_remaining_pct",
          "burn_rate",
          "decision"
        ]
      },
      {
        "name": "customer_comms_event",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "category",
          "channel",
          "audience",
          "title",
          "source_type",
          "source_id",
          "status",
          "timeline"
        ]
      },
      {
        "name": "client_application",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "name",
          "app_type",
          "owner_team",
          "status",
          "redirect_uris",
          "allowed_origins",
          "scopes",
          "secret_ref",
          "pkce_enforced"
        ]
      },
      {
        "name": "data_minimization_assessment",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "scope",
          "purpose",
          "decision",
          "finding_count",
          "blocking_finding_count",
          "findings",
          "recommended_retention_days"
        ]
      },
      {
        "name": "support_escalation",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "title",
          "severity",
          "status",
          "customer_ref",
          "owner",
          "linked_incident_id",
          "sla_due_at",
          "decision",
          "timeline"
        ]
      },
      {
        "name": "environment_promotion",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "source_environment",
          "target_environment",
          "decision",
          "completed_checks",
          "missing_checks",
          "change_id",
          "rollback_plan_ref"
        ]
      },
      {
        "name": "service_catalog_entry",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "service_name",
          "domain",
          "owner_team",
          "criticality",
          "dependencies",
          "runbook_ref",
          "slo_ref",
          "status"
        ]
      },
      {
        "name": "integration_circuit_breaker",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider_family",
          "connection_id",
          "status",
          "failure_count",
          "failure_threshold",
          "cooldown_seconds",
          "decision"
        ]
      },
      {
        "name": "privacy_impact_assessment",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "system_name",
          "processing_purpose",
          "data_categories",
          "legal_basis",
          "risk_level",
          "decision",
          "status"
        ]
      },
      {
        "name": "accessibility_scan",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "target",
          "standard",
          "critical_violations",
          "high_violations",
          "keyboard_passed",
          "screen_reader_passed",
          "decision"
        ]
      },
      {
        "name": "cost_assessment",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "period",
          "observed_spend_usd",
          "forecast_spend_usd",
          "budget_usd",
          "top_drivers",
          "decision"
        ]
      },
      {
        "name": "hypercare_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "target_tenants",
          "owner_team",
          "status",
          "planned_ends_at",
          "completed_exit_criteria",
          "missing_exit_criteria",
          "decision"
        ]
      },
      {
        "name": "launch_readiness_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "launch_window",
          "decision",
          "completed_controls",
          "missing_controls",
          "findings"
        ]
      },
      {
        "name": "go_live_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "launch_readiness_run_id",
          "rollback_plan_ref",
          "status",
          "steps",
          "timeline"
        ]
      },
      {
        "name": "runtime_parity_check",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "source_environment",
          "target_environment",
          "decision",
          "dimension_results",
          "drift_count",
          "findings"
        ]
      },
      {
        "name": "hypercare_review",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "period",
          "decision",
          "open_incidents",
          "open_support_escalations",
          "p95_latency_ms",
          "error_budget_remaining_pct"
        ]
      },
      {
        "name": "domain_verification",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "domain",
          "tenant_id",
          "purpose",
          "status",
          "decision",
          "required_records",
          "observed_records",
          "findings"
        ]
      },
      {
        "name": "warehouse_sync_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "dataset",
          "mode",
          "status",
          "decision",
          "row_count",
          "failed_row_count",
          "cdc_lag_seconds",
          "watermark"
        ]
      },
      {
        "name": "dr_failover_drill",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "mode",
          "primary_region",
          "secondary_region",
          "observed_failover_minutes",
          "observed_data_loss_minutes",
          "decision"
        ]
      },
      {
        "name": "finops_assessment",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "service_area",
          "monthly_spend_usd",
          "forecast_monthly_usd",
          "budget_monthly_usd",
          "budget_variance_pct",
          "decision"
        ]
      },
      {
        "name": "policy_exception",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "exception_type",
          "object_ref",
          "severity",
          "status",
          "expires_in_days",
          "approval_ref",
          "compensating_controls"
        ]
      },
      {
        "name": "api_consumer",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "name",
          "consumer_type",
          "owner",
          "tenant_id",
          "status",
          "decision",
          "scopes",
          "credential_ref",
          "next_rotation_due_at"
        ]
      },
      {
        "name": "sso_claim_check",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "provider",
          "decision",
          "required_claims",
          "observed_claims",
          "tenant_claim_name",
          "findings"
        ]
      },
      {
        "name": "abuse_detection_scan",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "scope",
          "mode",
          "decision",
          "signal_count",
          "findings"
        ]
      },
      {
        "name": "traffic_route",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "service",
          "release_version",
          "strategy",
          "traffic_percent",
          "health_status",
          "error_rate_pct",
          "status",
          "decision"
        ]
      },
      {
        "name": "rollback_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "trigger",
          "rollback_plan_ref",
          "affected_services",
          "status",
          "decision",
          "validation_passed"
        ]
      },
      {
        "name": "data_backfill_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "target",
          "mode",
          "expected_records",
          "processed_records",
          "error_count",
          "diff_count",
          "decision",
          "rollback_ref"
        ]
      },
      {
        "name": "email_deliverability_assessment",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "domain",
          "provider",
          "observed_records",
          "bounce_rate_pct",
          "complaint_rate_pct",
          "suppression_connected",
          "decision"
        ]
      },
      {
        "name": "contract_obligation",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "contract_id",
          "account_id",
          "obligation_type",
          "owner",
          "due_at",
          "status",
          "evidence_ref"
        ]
      },
      {
        "name": "customer_health_assessment",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "account_id",
          "success_owner",
          "health_score",
          "open_sla_breaches",
          "overdue_obligations",
          "renewal_days",
          "decision"
        ]
      },
      {
        "name": "knowledge_review",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "article_ref",
          "category",
          "owner",
          "version",
          "status",
          "next_review_due_at",
          "evidence_ref"
        ]
      },
      {
        "name": "infrastructure_policy_check",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "environment",
          "cloud_provider",
          "terraform_workspace",
          "kubernetes_namespace",
          "observed_controls",
          "decision",
          "findings"
        ]
      },
      {
        "name": "release_smoke_test_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "release_version",
          "environment",
          "journey",
          "step_results",
          "pass_rate",
          "failed_steps",
          "decision"
        ]
      },
      {
        "name": "legal_hold_enforcement_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "mode",
          "candidate_action_count",
          "blocked_action_count",
          "blocked_actions",
          "evidence_ref",
          "decision"
        ]
      },
      {
        "name": "revenue_close_validation",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "mode",
          "record_counts",
          "coverage_score",
          "findings",
          "decision"
        ]
      },
      {
        "name": "support_readiness_run",
        "status": "active",
        "version": "2026-04-21.19",
        "fields": [
          "id",
          "environment",
          "signals",
          "missing_signals",
          "ready_signal_count",
          "decision"
        ]
      },
      {
        "name": "repository_transaction_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "domain",
          "repository",
          "operation",
          "changed_record_count",
          "tenant_filter_violation_count",
          "audit_event_id",
          "outbox_event_id",
          "decision"
        ]
      },
      {
        "name": "worker_lease_cycle",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_name",
          "worker_id",
          "job_type",
          "lease_count",
          "completed_count",
          "stale_lease_count",
          "dlq_count",
          "heartbeat_age_seconds",
          "decision"
        ]
      },
      {
        "name": "provider_adapter_execution",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_family",
          "action",
          "mode",
          "credential_ref",
          "idempotency_key",
          "contract_test_decision",
          "egress_policy_decision",
          "decision"
        ]
      },
      {
        "name": "ui_surface_contract",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "surface_key",
          "role",
          "api_paths",
          "unresolved_permission_gap_count",
          "accessibility_violation_count",
          "full_state_fetch_count",
          "decision"
        ]
      },
      {
        "name": "cutover_readiness_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "blockers",
          "warnings",
          "decision"
        ]
      },
      {
        "name": "postgres_repository_runtime_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "domain",
          "repository",
          "collection",
          "operation",
          "mode",
          "contract_pass_pct",
          "tenant_violation_count",
          "decision"
        ]
      },
      {
        "name": "authz_decision_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "route",
          "method",
          "capability",
          "role",
          "expected_decision",
          "observed_decision",
          "bypass_count",
          "decision"
        ]
      },
      {
        "name": "durable_worker_queue_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_name",
          "runtime",
          "worker_count",
          "pending_job_count",
          "queue_lag_seconds",
          "dlq_count",
          "decision"
        ]
      },
      {
        "name": "provider_webhook_runtime_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_family",
          "provider_name",
          "event_type",
          "mode",
          "signature_valid",
          "replay_detected",
          "decision"
        ]
      },
      {
        "name": "ui_api_regression_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "surface_key",
          "role",
          "failed_test_count",
          "schema_mismatch_count",
          "permission_gap_count",
          "decision"
        ]
      },
      {
        "name": "launch_binding_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "gate_score",
          "decision",
          "blockers",
          "warnings"
        ]
      },
      {
        "name": "dependency_topology_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "environment",
          "service_count",
          "ready_pct",
          "missing_owner_count",
          "unverified_dependency_count",
          "cycle_count",
          "decision"
        ]
      },
      {
        "name": "repository_rls_proof",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "domain",
          "repository",
          "table_name",
          "policy_names",
          "negative_test_count",
          "rows_examined",
          "decision"
        ]
      },
      {
        "name": "worker_failover_rehearsal",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_name",
          "primary_worker_id",
          "standby_worker_id",
          "jobs_in_flight",
          "jobs_recovered",
          "lost_jobs",
          "failover_seconds",
          "decision"
        ]
      },
      {
        "name": "provider_webhook_binding",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_family",
          "provider_name",
          "webhook_endpoint",
          "signature_secret_ref",
          "timestamp_skew_seconds",
          "outbox_event_created",
          "decision"
        ]
      },
      {
        "name": "production_launch_acceptance_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "blockers",
          "warnings",
          "decision"
        ]
      },
      {
        "name": "repository_live_cutover",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "wave_name",
          "domain",
          "cutover_mode",
          "validation_pass_rate_pct",
          "mismatch_count",
          "decision"
        ]
      },
      {
        "name": "authorization_enforcement_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "scope",
          "route_count",
          "coverage_pct",
          "negative_test_count",
          "bypass_count",
          "decision"
        ]
      },
      {
        "name": "worker_job_batch",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_name",
          "worker_pool",
          "job_type",
          "completion_rate_pct",
          "dlq_count",
          "decision"
        ]
      },
      {
        "name": "provider_webhook_cutover",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_family",
          "provider_name",
          "cutover_stage",
          "signature_pass_rate_pct",
          "dlq_count",
          "decision"
        ]
      },
      {
        "name": "frontend_navigation_contract",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "surface_key",
          "role",
          "navigation_paths",
          "api_paths",
          "full_state_fetch_count",
          "decision"
        ]
      },
      {
        "name": "runtime_cutover_acceptance_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "database_repository_binding",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "domain",
          "adapter_name",
          "target_schema_version",
          "contract_pass_pct",
          "p95_query_ms",
          "decision"
        ]
      },
      {
        "name": "auth_middleware_enforcement",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "route_count",
          "protected_route_coverage_pct",
          "bypass_route_count",
          "decision"
        ]
      },
      {
        "name": "worker_daemon_operation",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_name",
          "worker_pool",
          "process_count",
          "heartbeat_age_seconds",
          "dlq_count",
          "decision"
        ]
      },
      {
        "name": "provider_connector_operation",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_family",
          "connector_name",
          "mode",
          "contract_test_pass_pct",
          "decision"
        ]
      },
      {
        "name": "observability_trace_binding",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "service_name",
          "environment",
          "trace_coverage_pct",
          "missing_context_count",
          "decision"
        ]
      },
      {
        "name": "infrastructure_execution_acceptance_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "repository_connection_pool_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "pool_size",
          "p95_acquire_ms",
          "failed_health_check_count",
          "rls_session_context_set",
          "decision"
        ]
      },
      {
        "name": "identity_token_runtime_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "token_validation_count",
          "failed_validation_count",
          "clock_skew_seconds",
          "required_claims",
          "decision"
        ]
      },
      {
        "name": "worker_orchestration_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_names",
          "active_worker_count",
          "max_queue_lag_seconds",
          "stale_lease_count",
          "dlq_count",
          "decision"
        ]
      },
      {
        "name": "provider_connector_health_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_family",
          "connector_name",
          "contract_test_pass_pct",
          "error_rate_pct",
          "webhook_ack_latency_ms",
          "decision"
        ]
      },
      {
        "name": "evidence_pipeline_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "event_count",
          "delivery_success_pct",
          "max_delivery_lag_seconds",
          "hash_gap_count",
          "watermark_failure_count",
          "decision"
        ]
      },
      {
        "name": "live_runtime_acceptance_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "tenant_data_boundary_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "collections",
          "coverage_pct",
          "boundary_violation_count",
          "unscoped_query_count",
          "redaction_gap_count",
          "decision"
        ]
      },
      {
        "name": "repository_snapshot_consistency_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "collections",
          "consistency_pass_pct",
          "mismatch_count",
          "replica_lag_ms",
          "snapshot_age_seconds",
          "decision"
        ]
      },
      {
        "name": "worker_backpressure_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "queue_names",
          "queue_depth",
          "max_queue_age_seconds",
          "dlq_count",
          "consumer_utilization_pct",
          "decision"
        ]
      },
      {
        "name": "provider_failback_run",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "provider_families",
          "connectors",
          "failover_seconds",
          "failback_seconds",
          "lost_event_count",
          "decision"
        ]
      },
      {
        "name": "observability_slo_burn_check",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "services",
          "burn_rate_1h",
          "burn_rate_6h",
          "error_budget_remaining_pct",
          "open_critical_alerts",
          "decision"
        ]
      },
      {
        "name": "runtime_operations_acceptance_pack",
        "status": "active",
        "version": "2026-04-21.28",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "tenant_migration_cutover",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "tenant_ids",
          "collections",
          "validation_pass_rate_pct",
          "mismatch_count",
          "open_blocker_count",
          "rollback_minutes",
          "decision"
        ]
      },
      {
        "name": "edge_gateway_check",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "domains",
          "gateway_routes",
          "route_count",
          "protected_route_pct",
          "unprotected_route_count",
          "rate_limit_bypass_count",
          "decision"
        ]
      },
      {
        "name": "billing_subscription_cutover",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "provider_families",
          "invoice_count",
          "subscription_count",
          "catalog_sync_pct",
          "reconciliation_mismatch_count",
          "duplicate_invoice_count",
          "decision"
        ]
      },
      {
        "name": "provider_rate_limit_budget",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "provider_families",
          "calls_per_minute",
          "provider_429_count",
          "retry_budget_remaining_pct",
          "circuit_breaker_trip_count",
          "decision"
        ]
      },
      {
        "name": "compliance_attestation",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "frameworks",
          "control_count",
          "failed_control_count",
          "critical_gap_count",
          "control_coverage_pct",
          "decision"
        ]
      },
      {
        "name": "hypercare_command_run",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "staffed_roles",
          "active_wave_count",
          "open_critical_ticket_count",
          "pager_gap_count",
          "sli_dashboard_coverage_pct",
          "decision"
        ]
      },
      {
        "name": "go_live_acceptance_pack",
        "status": "active",
        "version": "2026-04-21.30",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_market_program_control",
        "status": "active",
        "version": "2026-04-22.33",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_market_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.33",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_leadership_proof_control",
        "status": "active",
        "version": "2026-04-22.33",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_leadership_proof_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.33",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_productization_runtime_control",
        "status": "active",
        "version": "2026-04-22.34",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_productization_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.34",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_operating_system_runtime_control",
        "status": "active",
        "version": "2026-04-22.36",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_operating_system_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.36",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_future_simulation_runtime_control",
        "status": "active",
        "version": "2026-04-22.36",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_future_simulation_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.36",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_commercialization_runtime_control",
        "status": "active",
        "version": "2026-04-22.37",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_commercialization_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.37",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_growth_scale_runtime_control",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_growth_scale_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_enterprise_scale_runtime_control",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_enterprise_scale_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_network_effects_runtime_control",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_network_effects_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_global_scale_runtime_control",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_global_scale_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.39",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_autonomous_market_mesh_runtime_control",
        "status": "active",
        "version": "2026-04-22.40",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_verified_market_network_runtime_control",
        "status": "active",
        "version": "2026-04-22.41",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at"
        ]
      },
      {
        "name": "no1_autonomous_mesh_acceptance_pack",
        "status": "active",
        "version": "2026-04-22.40",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_external_review_execution_control",
        "status": "active",
        "version": "2026-04-24.55",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "reviewer_count",
          "signed_approval_count"
        ]
      },
      {
        "name": "no1_external_review_execution_acceptance_pack",
        "status": "active",
        "version": "2026-04-24.55",
        "fields": [
          "id",
          "release_version",
          "environment",
          "claim_label",
          "required_gates",
          "dependencies",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_artifact_integrity_control",
        "status": "active",
        "version": "2026-04-24.56",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "size_delta_pct",
          "release_manifest_file_count"
        ]
      },
      {
        "name": "no1_artifact_integrity_acceptance_pack",
        "status": "active",
        "version": "2026-04-24.56",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_review_artifact_export_control",
        "status": "active",
        "version": "2026-04-24.57",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "evidence_coverage_pct"
        ]
      },
      {
        "name": "no1_review_artifact_export_acceptance_pack",
        "status": "active",
        "version": "2026-04-24.57",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "dependencies",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_formal_delivery_control",
        "status": "active",
        "version": "2026-04-24.58",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "artifact_paths"
        ]
      },
      {
        "name": "no1_formal_delivery_acceptance_pack",
        "status": "active",
        "version": "2026-04-24.58",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "dependencies",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_builderai_checkpoint_control",
        "status": "active",
        "version": "2026-04-24.59",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "source_program"
        ]
      },
      {
        "name": "no1_builderai_checkpoint_acceptance_pack",
        "status": "active",
        "version": "2026-04-24.59",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "dependencies",
          "gate_results",
          "gate_score",
          "decision",
          "authority_boundary"
        ]
      },
      {
        "name": "no1_runtime_execution_control",
        "status": "active",
        "version": "2026-04-25.60",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "payload"
        ]
      },
      {
        "name": "no1_runtime_execution_acceptance_pack",
        "status": "active",
        "version": "2026-04-25.60",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "dependencies",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_dependency_environment_control",
        "status": "active",
        "version": "2026-04-25.61",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "payload"
        ]
      },
      {
        "name": "no1_dependency_environment_acceptance_pack",
        "status": "active",
        "version": "2026-04-25.61",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_production_process_control",
        "status": "active",
        "version": "2026-04-25.63",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "payload"
        ]
      },
      {
        "name": "no1_production_process_acceptance_pack",
        "status": "active",
        "version": "2026-04-25.63",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_live_infrastructure_control",
        "status": "active",
        "version": "2026-04-26.64",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "receipt_domains",
          "payload"
        ]
      },
      {
        "name": "no1_live_infrastructure_acceptance_pack",
        "status": "active",
        "version": "2026-04-26.64",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_final_execution_control",
        "status": "active",
        "version": "2026-04-25.63",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "evidence_domains",
          "payload"
        ]
      },
      {
        "name": "no1_final_execution_acceptance_pack",
        "status": "active",
        "version": "2026-04-25.63",
        "fields": [
          "id",
          "release_version",
          "environment",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision"
        ]
      },
      {
        "name": "no1_receipt_file_generation_control",
        "status": "active",
        "version": "2026-04-26.66",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "receipt_domains",
          "file_manifest",
          "payload"
        ]
      },
      {
        "name": "no1_receipt_file_generation_acceptance_pack",
        "status": "active",
        "version": "2026-04-26.66",
        "fields": [
          "id",
          "release_version",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision",
          "blockers"
        ]
      },
      {
        "name": "no1_post_mutation_validation_control",
        "status": "active",
        "version": "2026-04-28.77",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "post_route_count",
          "missing_verified_receipt_count"
        ]
      },
      {
        "name": "no1_post_mutation_validation_acceptance_pack",
        "status": "active",
        "version": "2026-04-28.77",
        "fields": [
          "id",
          "release_version",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision",
          "missing_verified_receipt_count"
        ]
      },
      {
        "name": "no1_broader_mutation_budget_control",
        "status": "active",
        "version": "2026-04-28.78",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "post_route_count",
          "missing_verified_receipt_count"
        ]
      },
      {
        "name": "no1_broader_mutation_budget_acceptance_pack",
        "status": "active",
        "version": "2026-04-28.78",
        "fields": [
          "id",
          "release_version",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision",
          "missing_verified_receipt_count"
        ]
      },
      {
        "name": "no1_production_http_execution_control",
        "status": "active",
        "version": "2026-04-28.79",
        "fields": [
          "id",
          "control",
          "tenant_id",
          "actor_id",
          "score",
          "decision",
          "status",
          "created_at",
          "post_route_count",
          "missing_verified_receipt_count"
        ]
      },
      {
        "name": "no1_production_http_execution_acceptance_pack",
        "status": "active",
        "version": "2026-04-28.79",
        "fields": [
          "id",
          "release_version",
          "required_gates",
          "gate_results",
          "gate_score",
          "decision",
          "missing_verified_receipt_count"
        ]
      }
    ]
  },
  "no1_v735_claim_publication_approval_acceptance_packs": [
    {
      "id": "v735_claim_publication_approval_source_control_seed",
      "decision": "v735_claim_publication_approval_ready_claims_frozen",
      "claim_freeze_active": true,
      "public_no1_claim_allowed": false,
      "blueprint_100_public_claim_allowed": false,
      "missing_verified_receipt_count": 56,
      "verified_live_receipts": 0,
      "note": "Placeholder only. External claims remain frozen until verified live receipts and approvals exist."
    }
  ],
  "identity": {
    "provider": "Nexa Identity",
    "sso_enabled": true,
    "mfa_policy": "required",
    "users": [
      {
        "id": "user_owner_primary",
        "name": "placeholder-operator",
        "email": "placeholderoperator@nexabuilder.local",
        "role_template": "partner_seller",
        "role_label": "Partner seller",
        "linked_owner": "placeholder-operator",
        "status": "active",
        "sso_enabled": true,
        "mfa_required": true,
        "mfa_verified": true,
        "sync_status": "synced",
        "systems": {
          "builderai": {
            "role": "Partner Seller",
            "access": "active"
          },
          "nexamarket": {
            "role": "Revenue Operator",
            "access": "active"
          },
          "nexacrm": {
            "role": "Account Executive",
            "access": "active"
          }
        },
        "notes": "Owns sourced opportunities, governed outreach, and seller-code activity.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "last_synced_at": "2026-07-09T19:05:10",
        "material_training": [],
        "privacy_actions": []
      },
      {
        "id": "user_manager_demo",
        "name": "Avery Stone",
        "email": "avery.stone@nexabuilder.local",
        "role_template": "manager",
        "role_label": "Manager",
        "linked_owner": "Avery Stone",
        "status": "active",
        "sso_enabled": true,
        "mfa_required": true,
        "mfa_verified": true,
        "sync_status": "synced",
        "systems": {
          "builderai": {
            "role": "Manager Review",
            "access": "active"
          },
          "nexamarket": {
            "role": "Manager Approval",
            "access": "active"
          },
          "nexacrm": {
            "role": "Pipeline Manager",
            "access": "active"
          }
        },
        "notes": "Reviews forecasts, approvals, coaching signals, and escalations.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "last_synced_at": "2026-07-09T19:05:10",
        "material_training": [],
        "privacy_actions": []
      },
      {
        "id": "user_finance_demo",
        "name": "Priya Shah",
        "email": "priya.shah@nexabuilder.local",
        "role_template": "finance_admin",
        "role_label": "Finance admin",
        "linked_owner": "Priya Shah",
        "status": "active",
        "sso_enabled": true,
        "mfa_required": true,
        "mfa_verified": true,
        "sync_status": "synced",
        "systems": {
          "builderai": {
            "role": "Finance Admin",
            "access": "active"
          },
          "nexamarket": {
            "role": "Finance Visibility",
            "access": "active"
          },
          "nexacrm": {
            "role": "Billing Reviewer",
            "access": "active"
          }
        },
        "notes": "Owns invoicing, reconciliation, clawbacks, and payout readiness.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "last_synced_at": "2026-07-09T19:05:10",
        "material_training": [],
        "privacy_actions": []
      },
      {
        "id": "user_legal_demo",
        "name": "Elena Brooks",
        "email": "elena.brooks@nexabuilder.local",
        "role_template": "legal_reviewer",
        "role_label": "Legal reviewer",
        "linked_owner": "Elena Brooks",
        "status": "active",
        "sso_enabled": true,
        "mfa_required": true,
        "mfa_verified": true,
        "sync_status": "synced",
        "systems": {
          "builderai": {
            "role": "Audit Viewer",
            "access": "active"
          },
          "nexamarket": {
            "role": "Compliance Reviewer",
            "access": "active"
          },
          "nexacrm": {
            "role": "Contract Reviewer",
            "access": "active"
          }
        },
        "notes": "Approves non-standard terms, contract language, and sensitive share rules.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "last_synced_at": "2026-07-09T19:05:10",
        "material_training": [],
        "privacy_actions": []
      },
      {
        "id": "user_cs_demo",
        "name": "Marcus Hill",
        "email": "marcus.hill@nexabuilder.local",
        "role_template": "customer_success",
        "role_label": "Customer success",
        "linked_owner": "Marcus Hill",
        "status": "active",
        "sso_enabled": true,
        "mfa_required": true,
        "mfa_verified": true,
        "sync_status": "synced",
        "systems": {
          "builderai": {
            "role": "Read Only",
            "access": "active"
          },
          "nexamarket": {
            "role": "Handoff Visibility",
            "access": "active"
          },
          "nexacrm": {
            "role": "Customer Success",
            "access": "active"
          }
        },
        "notes": "Owns onboarding, kickoff, milestone visibility, and renewal prep.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "last_synced_at": "2026-07-09T19:05:10",
        "material_training": [],
        "privacy_actions": []
      },
      {
        "id": "user_analyst_demo",
        "name": "Jamie Chen",
        "email": "jamie.chen@nexabuilder.local",
        "role_template": "analyst",
        "role_label": "Analyst",
        "linked_owner": "Jamie Chen",
        "status": "active",
        "sso_enabled": true,
        "mfa_required": true,
        "mfa_verified": false,
        "sync_status": "synced",
        "systems": {
          "builderai": {
            "role": "Read Only",
            "access": "active"
          },
          "nexamarket": {
            "role": "Read Only",
            "access": "active"
          },
          "nexacrm": {
            "role": "Read Only",
            "access": "active"
          }
        },
        "notes": "Read-only inspection of shared CRM records without approval, outreach, or finance authority.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "last_synced_at": "2026-07-09T19:05:10",
        "material_training": [],
        "privacy_actions": []
      }
    ],
    "directory": [
      {
        "id": "user_owner_primary",
        "name": "placeholder-operator",
        "email": "placeholderoperator@nexabuilder.local",
        "role": "Partner seller",
        "status": "active",
        "sso_provider": "Nexa Identity",
        "mfa_enrolled": true,
        "apps": [
          "builderai (Partner Seller)",
          "nexamarket (Revenue Operator)",
          "nexacrm (Account Executive)"
        ],
        "seller_code": "NM-PLACEHOLDEROPERATOR-PRIMARY"
      },
      {
        "id": "user_manager_demo",
        "name": "Avery Stone",
        "email": "avery.stone@nexabuilder.local",
        "role": "Manager",
        "status": "active",
        "sso_provider": "Nexa Identity",
        "mfa_enrolled": true,
        "apps": [
          "builderai (Manager Review)",
          "nexamarket (Manager Approval)",
          "nexacrm (Pipeline Manager)"
        ],
        "seller_code": "NM-AVERY-STONE-PRIMARY"
      },
      {
        "id": "user_finance_demo",
        "name": "Priya Shah",
        "email": "priya.shah@nexabuilder.local",
        "role": "Finance admin",
        "status": "active",
        "sso_provider": "Nexa Identity",
        "mfa_enrolled": true,
        "apps": [
          "builderai (Finance Admin)",
          "nexamarket (Finance Visibility)",
          "nexacrm (Billing Reviewer)"
        ],
        "seller_code": "NM-PRIYA-SHAH-PRIMARY"
      },
      {
        "id": "user_legal_demo",
        "name": "Elena Brooks",
        "email": "elena.brooks@nexabuilder.local",
        "role": "Legal reviewer",
        "status": "active",
        "sso_provider": "Nexa Identity",
        "mfa_enrolled": true,
        "apps": [
          "builderai (Audit Viewer)",
          "nexamarket (Compliance Reviewer)",
          "nexacrm (Contract Reviewer)"
        ],
        "seller_code": "NM-ELENA-BROOKS-PRIMARY"
      },
      {
        "id": "user_cs_demo",
        "name": "Marcus Hill",
        "email": "marcus.hill@nexabuilder.local",
        "role": "Customer success",
        "status": "active",
        "sso_provider": "Nexa Identity",
        "mfa_enrolled": true,
        "apps": [
          "builderai (Read Only)",
          "nexamarket (Handoff Visibility)",
          "nexacrm (Customer Success)"
        ],
        "seller_code": "NM-MARCUS-HILL-PRIMARY"
      },
      {
        "id": "user_analyst_demo",
        "name": "Jamie Chen",
        "email": "jamie.chen@nexabuilder.local",
        "role": "Analyst",
        "status": "active",
        "sso_provider": "Nexa Identity",
        "mfa_enrolled": true,
        "apps": [
          "builderai (Read Only)",
          "nexamarket (Read Only)",
          "nexacrm (Read Only)"
        ],
        "seller_code": "NM-JAMIE-CHEN-PRIMARY"
      }
    ],
    "current_user_id": "user_manager_demo",
    "session": {
      "user_id": "user_manager_demo",
      "mfa_verified": true,
      "last_auth_at": "2026-07-09T19:05:10"
    },
    "session_policy": {
      "provider": "Nexa Identity",
      "session_hours": 8,
      "scim": "planned",
      "visible_capabilities": [
        "agent_guardrails",
        "agent_handoff",
        "agent_ops",
        "agent_policy",
        "agent_profile",
        "agent_runtime",
        "ai_governance",
        "analytics_ops",
        "anomaly_alerts",
        "approvals",
        "audit_export",
        "backup_vault",
        "board_packets",
        "capacity_management",
        "collections",
        "commercial_ops",
        "compensation",
        "connectors",
        "contracts",
        "cpq",
        "crm",
        "crm_bridge",
        "customer_export",
        "customer_ops",
        "customer_success",
        "dashboard_refreshes",
        "data_contracts",
        "data_quality",
        "deal_rooms",
        "drift_monitoring",
        "enterprise_export",
        "event_bus_resilience",
        "event_delivery",
        "feature_store",
        "finance",
        "forecast_lab",
        "go_live",
        "go_live_export",
        "growth_attribution",
        "growth_campaigns",
        "growth_experiments",
        "growth_export",
        "growth_ops",
        "growth_scoring",
        "incident_routing",
        "intelligence_export",
        "intelligence_ops",
        "job_queue",
        "kill_switch",
        "launch",
        "launch_export",
        "legal_hold_release",
        "lineage_graph",
        "materials",
        "meetings",
        "model_deployment",
        "model_ops",
        "observability",
        "onboarding",
        "ops_export",
        "orchestration",
        "outbound",
        "partner_cosell",
        "partner_export",
        "partner_governance",
        "partner_marketplace",
        "partner_mdf",
        "partner_ops",
        "partner_payouts",
        "playbooks",
        "privacy",
        "procurement",
        "prompt_registry",
        "providers",
        "recovery_drill",
        "release_ops",
        "renewals",
        "retention",
        "revenue_intelligence",
        "revenue_ops",
        "runtime_deployment",
        "runtime_operations",
        "runtime_tracing",
        "security",
        "semantic_metrics",
        "settlement",
        "signature_provider",
        "slo_monitoring",
        "state_lock",
        "subscription_billing",
        "subscription_export",
        "support_sync",
        "tax_ops",
        "telemetry_ops",
        "tenants",
        "tool_proxy",
        "tool_sandbox",
        "tool_telemetry",
        "training_pipeline",
        "trust_center",
        "uat",
        "warehouse_sync",
        "webhook_verification",
        "worker_pool",
        "workflow_blueprint",
        "workflow_run"
      ],
      "mfa_required_for": [
        "agent_release",
        "agent_schedule",
        "agentops_export",
        "ai_governance",
        "analytics_export",
        "audit_export",
        "backup_vault",
        "collections",
        "compensation",
        "connectors",
        "contracts",
        "cpq",
        "credential_rotation",
        "crm_bridge",
        "customer_export",
        "customer_ops",
        "data_quality",
        "enterprise_export",
        "event_bus_resilience",
        "event_delivery",
        "go_live",
        "go_live_export",
        "growth_export",
        "incident_route",
        "intelligence_export",
        "kill_switch",
        "launch",
        "launch_export",
        "legal_hold_release",
        "model_deployment",
        "modelops_export",
        "observability",
        "observability_export",
        "ops_export",
        "orchestration",
        "orchestration_export",
        "partner_export",
        "partner_payouts",
        "procurement",
        "providers",
        "recovery_drill",
        "release_ops",
        "retention",
        "revenue_ops",
        "runtime_deployment",
        "runtime_export",
        "security",
        "settlement",
        "signature_provider",
        "subscription_billing",
        "subscription_export",
        "tax_ops",
        "tenants",
        "tool_proxy",
        "trust_center",
        "uat",
        "webhook_verification"
      ],
      "can_send_outbound": true,
      "can_schedule_meetings": true,
      "can_approve": true,
      "can_offboard": true,
      "can_manage_connectors": true,
      "finance_export": true,
      "can_manage_materials": true,
      "can_manage_privacy": true,
      "can_manage_forecast": true,
      "can_manage_deal_rooms": true,
      "can_manage_cpq": true,
      "can_manage_contracts": true,
      "can_manage_providers": true,
      "can_manage_procurement": true,
      "can_manage_revenue_ops": true,
      "can_manage_customer_success": true,
      "can_manage_security": true,
      "can_rotate_credentials": true,
      "can_manage_event_delivery": true,
      "can_manage_retention": true,
      "audit_export": true,
      "can_manage_release": true,
      "can_manage_observability": true,
      "can_run_quality": true,
      "ops_export": true,
      "can_manage_launch": true,
      "launch_export": true,
      "can_manage_crm_bridge": true,
      "can_verify_webhooks": true,
      "can_release_legal_holds": true,
      "can_run_recovery_drills": true,
      "can_manage_provider_certification": true,
      "can_manage_signature_provider": true,
      "can_manage_settlement": true,
      "can_manage_tax_ops": true,
      "can_manage_event_bus_resilience": true,
      "can_manage_backup_vault": true,
      "can_run_uat": true,
      "go_live_export": true,
      "can_manage_tenants": true,
      "can_manage_trust_center": true,
      "can_manage_ai_governance": true,
      "enterprise_export": true,
      "can_manage_customer_ops": true,
      "customer_export": true,
      "can_manage_subscription_billing": true,
      "can_manage_telemetry_ops": true,
      "can_manage_collections": true,
      "can_manage_support_sync": true,
      "subscription_export": true,
      "can_manage_partner_ops": true,
      "can_manage_partner_governance": true,
      "can_manage_mdf": true,
      "can_manage_partner_payouts": true,
      "partner_export": true,
      "can_manage_growth_ops": true,
      "can_manage_growth_experiments": true,
      "can_manage_growth_routing": true,
      "growth_export": true,
      "can_manage_intelligence_ops": true,
      "can_resolve_intelligence_alerts": true,
      "intelligence_export": true,
      "can_manage_analytics_ops": true,
      "can_train_forecasts": true,
      "can_resolve_data_contracts": true,
      "analytics_export": true,
      "can_manage_modelops": true,
      "can_run_drift_monitors": true,
      "can_approve_model_deployments": true,
      "modelops_export": true,
      "can_manage_agentops": true,
      "can_run_agent_workflows": true,
      "can_approve_agent_releases": true,
      "agentops_export": true,
      "can_toggle_kill_switches": true,
      "can_resolve_observability_incidents": true,
      "observability_export": true,
      "can_manage_runtime": true,
      "can_dispatch_runtime_jobs": true,
      "can_promote_runtime_deployments": true,
      "runtime_export": true,
      "can_manage_orchestration": true,
      "can_run_orchestration": true,
      "can_resolve_orchestration": true,
      "orchestration_export": true
    },
    "role_templates": [
      {
        "id": "partner_seller",
        "label": "Partner seller",
        "description": "Owns sourced opportunities, governed outreach, and seller-code activity."
      },
      {
        "id": "manager",
        "label": "Manager",
        "description": "Reviews forecasts, approvals, coaching signals, and escalations."
      },
      {
        "id": "finance_admin",
        "label": "Finance admin",
        "description": "Owns invoicing, reconciliation, clawbacks, and payout readiness."
      },
      {
        "id": "legal_reviewer",
        "label": "Legal reviewer",
        "description": "Approves non-standard terms, contract language, and sensitive share rules."
      },
      {
        "id": "customer_success",
        "label": "Customer success",
        "description": "Owns onboarding, kickoff, milestone visibility, and renewal prep."
      },
      {
        "id": "analyst",
        "label": "Analyst",
        "description": "Read-only inspection of shared CRM records without approval, outreach, or finance authority."
      }
    ],
    "role_sync_log": [],
    "deactivation_log": [],
    "summary": {
      "active_users": 6,
      "mfa_verified": 5,
      "deactivated_users": 0,
      "role_sync_events": 0
    }
  },
  "platform_sync": {
    "api_gateway": {
      "name": "Nexa Revenue Gateway",
      "status": "simulated",
      "contract_version": "revenue-sync.v1",
      "last_reconcile_at": null
    },
    "canonical_owners": [
      {
        "object_type": "account",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "commission",
        "owner_system": "NexaBuilderAI"
      },
      {
        "object_type": "contact",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "contract",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "deal",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "deal_room",
        "owner_system": "NexaMarket"
      },
      {
        "object_type": "document",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "invoice",
        "owner_system": "Finance Rail"
      },
      {
        "object_type": "lead",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "material",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "meeting",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "offboarding",
        "owner_system": "NexaBuilderAI"
      },
      {
        "object_type": "payout_snapshot",
        "owner_system": "NexaBuilderAI"
      },
      {
        "object_type": "privacy_request",
        "owner_system": "Shared Platform"
      },
      {
        "object_type": "quote",
        "owner_system": "NexaCRM"
      },
      {
        "object_type": "seller_code",
        "owner_system": "NexaBuilderAI"
      },
      {
        "object_type": "user",
        "owner_system": "Shared Identity"
      }
    ],
    "object_registry": [
      {
        "id": "registry_agentops_policy_agent_policy_revenue_assistant",
        "object_type": "agentops_policy",
        "object_id": "agent_policy_revenue_assistant",
        "canonical_id": "CAN-AGEN-POLICY_REVENUE_ASSISTANT",
        "title": "Revenue Assistant Policy",
        "status": "approved",
        "owner_system": "AgentOps Policy Engine",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "outbound_send"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_agentops_policy_agent_policy_revops_analyst",
        "object_type": "agentops_policy",
        "object_id": "agent_policy_revops_analyst",
        "canonical_id": "CAN-AGEN-POLICY_REVOPS_ANALYST",
        "title": "RevOps Analyst Policy",
        "status": "approved",
        "owner_system": "AgentOps Policy Engine",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "billing_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_agentops_prompt_version_prompt_revenue_assistant_v1",
        "object_type": "agentops_prompt_version",
        "object_id": "prompt_revenue_assistant_v1",
        "canonical_id": "CAN-AGEN-REVENUE_ASSISTANT_V1",
        "title": "revenue_assistant_followup",
        "status": "evaluated",
        "owner_system": "AgentOps Prompt Registry",
        "company_name": "",
        "linked_ids": [
          "agent_policy_revenue_assistant"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_agentops_prompt_version_prompt_revops_explainer_v1",
        "object_type": "agentops_prompt_version",
        "object_id": "prompt_revops_explainer_v1",
        "canonical_id": "CAN-AGEN-REVOPS_EXPLAINER_V1",
        "title": "revops_executive_explainer",
        "status": "evaluated",
        "owner_system": "AgentOps Prompt Registry",
        "company_name": "",
        "linked_ids": [
          "agent_policy_revops_analyst"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_ai_model_model_nexa_orchestrator_local",
        "object_type": "ai_model",
        "object_id": "model_nexa_orchestrator_local",
        "canonical_id": "CAN-AI_M-NEXA_ORCHESTRATOR_LOCAL",
        "title": "Nexa Orchestrator Local Policy Agent",
        "status": "approved_for_demo",
        "owner_system": "AI Governance",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_ai_model_model_outbound_compliance_guard",
        "object_type": "ai_model",
        "object_id": "model_outbound_compliance_guard",
        "canonical_id": "CAN-AI_M-OUTBOUND_COMPLIANCE_GUARD",
        "title": "Outbound Compliance Guard",
        "status": "approved_for_demo",
        "owner_system": "AI Governance",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_dashboard_refresh_dashboard_refresh_ffc92770ea",
        "object_type": "analytics_dashboard_refresh",
        "object_id": "dashboard_refresh_ffc92770ea",
        "canonical_id": "CAN-ANAL-REFRESH_FFC92770EA",
        "title": "Executive Revenue BI Dashboard",
        "status": "published_simulated",
        "owner_system": "BI Refresh Scheduler",
        "company_name": "",
        "linked_ids": [
          "snapshot_749adf2d44"
        ],
        "last_updated": "2026-07-12T01:35:50"
      },
      {
        "id": "registry_analytics_data_contract_contract_crm_deals",
        "object_type": "analytics_data_contract",
        "object_id": "contract_crm_deals",
        "canonical_id": "CAN-ANAL-CRM_DEALS",
        "title": "CRM deals contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_data_contract_contract_growth_attribution",
        "object_type": "analytics_data_contract",
        "object_id": "contract_growth_attribution",
        "canonical_id": "CAN-ANAL-GROWTH_ATTRIBUTION",
        "title": "Growth attribution contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_data_contract_contract_invoices",
        "object_type": "analytics_data_contract",
        "object_id": "contract_invoices",
        "canonical_id": "CAN-ANAL-INVOICES",
        "title": "Invoice revenue contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_data_contract_contract_subscription_usage",
        "object_type": "analytics_data_contract",
        "object_id": "contract_subscription_usage",
        "canonical_id": "CAN-ANAL-SUBSCRIPTION_USAGE",
        "title": "Subscription telemetry contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_forecast_model_forecast_model_revenue_baseline",
        "object_type": "analytics_forecast_model",
        "object_id": "forecast_model_revenue_baseline",
        "canonical_id": "CAN-ANAL-MODEL_REVENUE_BASELINE",
        "title": "Revenue Baseline Forecast",
        "status": "trained_simulated",
        "owner_system": "Forecast Lab",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_open_pipeline",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_open_pipeline",
        "canonical_id": "CAN-ANAL-OPEN_PIPELINE",
        "title": "Open Pipeline",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_operational_risk_count",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_operational_risk_count",
        "canonical_id": "CAN-ANAL-OPERATIONAL_RISK_COUNT",
        "title": "Operational Risk Count",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_subscription_mrr",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_subscription_mrr",
        "canonical_id": "CAN-ANAL-SUBSCRIPTION_MRR",
        "title": "Subscription MRR",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_weighted_forecast",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_weighted_forecast",
        "canonical_id": "CAN-ANAL-WEIGHTED_FORECAST",
        "title": "Weighted Forecast",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_warehouse_connection_wh_local_revenue_lake",
        "object_type": "analytics_warehouse_connection",
        "object_id": "wh_local_revenue_lake",
        "canonical_id": "CAN-ANAL-LOCAL_REVENUE_LAKE",
        "title": "Nexa Revenue Lakehouse",
        "status": "connected_simulated",
        "owner_system": "Analytics Warehouse Gateway",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_billing_provider_connection_bill_conn_chargebee_stub",
        "object_type": "billing_provider_connection",
        "object_id": "bill_conn_chargebee_stub",
        "canonical_id": "CAN-BILL-CONN_CHARGEBEE_STUB",
        "title": "Chargebee Billing Stub",
        "status": "ready",
        "owner_system": "Subscription Billing Gateway",
        "company_name": "",
        "linked_ids": [
          "site_demo_nexamarket"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_billing_provider_connection_bill_conn_stripe_stub",
        "object_type": "billing_provider_connection",
        "object_id": "bill_conn_stripe_stub",
        "canonical_id": "CAN-BILL-CONN_STRIPE_STUB",
        "title": "Stripe Billing Stub",
        "status": "connected_simulated",
        "owner_system": "Subscription Billing Gateway",
        "company_name": "",
        "linked_ids": [
          "acct_demo_nexamarket"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_catalog_change_catalog_change_b089a47cc9",
        "object_type": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "canonical_id": "CAN-CATA-CHANGE_B089A47CC9",
        "title": "Add product NexaMarket Workflow Automation Pack",
        "status": "pending_approval",
        "owner_system": "NexaMarket CPQ",
        "company_name": "",
        "linked_ids": [
          "prod_37d27276ac",
          "approval_9bcdd9c074"
        ],
        "last_updated": "2026-07-17T19:33:52"
      },
      {
        "id": "registry_deal_placeholder_deal_source_control_seed",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "canonical_id": "CAN-DEAL-DEAL_SOURCE_CONTROL_SEED",
        "title": "Source-control seed placeholder",
        "status": "placeholder",
        "owner_system": "NexaCRM",
        "company_name": "",
        "linked_ids": [
          "NM-OWNER-PRIMARY"
        ],
        "last_updated": "2026-07-09T20:39:02"
      },
      {
        "id": "registry_environment_env_production",
        "object_type": "environment",
        "object_id": "env_production",
        "canonical_id": "CAN-ENVI-PRODUCTION",
        "title": "Production",
        "status": "blocked",
        "owner_system": "Release Control",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_environment_env_sandbox",
        "object_type": "environment",
        "object_id": "env_sandbox",
        "canonical_id": "CAN-ENVI-SANDBOX",
        "title": "Sandbox",
        "status": "attention",
        "owner_system": "Release Control",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_environment_env_staging",
        "object_type": "environment",
        "object_id": "env_staging",
        "canonical_id": "CAN-ENVI-STAGING",
        "title": "Staging",
        "status": "attention",
        "owner_system": "Release Control",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_event_subscription_sub_dd6819138c",
        "object_type": "event_subscription",
        "object_id": "sub_dd6819138c",
        "canonical_id": "CAN-EVEN-DD6819138C",
        "title": "Customer webhook replay target",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T20:41:01"
      },
      {
        "id": "registry_event_subscription_sub_finance_invoice",
        "object_type": "event_subscription",
        "object_id": "sub_finance_invoice",
        "canonical_id": "CAN-EVEN-FINANCE_INVOICE",
        "title": "Finance invoice handoff",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_event_subscription_sub_nexacrm_all",
        "object_type": "event_subscription",
        "object_id": "sub_nexacrm_all",
        "canonical_id": "CAN-EVEN-NEXACRM_ALL",
        "title": "NexaCRM canonical sync",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_event_subscription_sub_security_audit",
        "object_type": "event_subscription",
        "object_id": "sub_security_audit",
        "canonical_id": "CAN-EVEN-SECURITY_AUDIT",
        "title": "Security audit ledger",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_growth_audience_segment_segment_enterprise_healthcare",
        "object_type": "growth_audience_segment",
        "object_id": "segment_enterprise_healthcare",
        "canonical_id": "CAN-GROW-ENTERPRISE_HEALTHCARE",
        "title": "Enterprise healthcare operators",
        "status": "active",
        "owner_system": "Growth Audience Builder",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_identity_provider_idp_customer_saml_stub",
        "object_type": "identity_provider",
        "object_id": "idp_customer_saml_stub",
        "canonical_id": "CAN-IDEN-CUSTOMER_SAML_STUB",
        "title": "Customer SAML Stub",
        "status": "simulated",
        "owner_system": "Shared Identity",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_identity_provider_idp_nexa_identity_oidc",
        "object_type": "identity_provider",
        "object_id": "idp_nexa_identity_oidc",
        "canonical_id": "CAN-IDEN-NEXA_IDENTITY_OIDC",
        "title": "Nexa Identity OIDC",
        "status": "connected",
        "owner_system": "Shared Identity",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_intelligence_metric_snapshot_snapshot_749adf2d44",
        "object_type": "intelligence_metric_snapshot",
        "object_id": "snapshot_749adf2d44",
        "canonical_id": "CAN-INTE-749ADF2D44",
        "title": "Metric snapshot 2026-07",
        "status": "at_risk",
        "owner_system": "Revenue Intelligence Lake",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-12T01:35:50"
      },
      {
        "id": "registry_intelligence_playbook_playbook_operational_risk",
        "object_type": "intelligence_playbook",
        "object_id": "playbook_operational_risk",
        "canonical_id": "CAN-INTE-OPERATIONAL_RISK",
        "title": "Operational risk cleanup",
        "status": "active",
        "owner_system": "Revenue Playbook Orchestrator",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_intelligence_playbook_playbook_pipeline_coverage",
        "object_type": "intelligence_playbook",
        "object_id": "playbook_pipeline_coverage",
        "canonical_id": "CAN-INTE-PIPELINE_COVERAGE",
        "title": "Pipeline coverage recovery",
        "status": "active",
        "owner_system": "Revenue Playbook Orchestrator",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_audience_summary_v11",
        "object_type": "material",
        "object_id": "mat_audience_summary_v11",
        "canonical_id": "CAN-MATE-AUDIENCE_SUMMARY_V11",
        "title": "Audience Summary",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "audience_summary",
        "linked_ids": [
          "audiencesummary:audience-summary:summary"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_budget_guardrail_v10",
        "object_type": "material",
        "object_id": "mat_budget_guardrail_v10",
        "canonical_id": "CAN-MATE-BUDGET_GUARDRAIL_V10",
        "title": "Budget Guardrails",
        "status": "approval_only",
        "owner_system": "NexaCRM",
        "company_name": "budget",
        "linked_ids": [
          "budget:budget-guardrails:policy"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_pitch_deck_v60",
        "object_type": "material",
        "object_id": "mat_pitch_deck_v60",
        "canonical_id": "CAN-MATE-PITCH_DECK_V60",
        "title": "Corporate Pitch Deck",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "pitch_deck",
        "linked_ids": [
          "pitchdeck:corporate-pitch-deck:deck"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_creative_brief_v11",
        "object_type": "material",
        "object_id": "mat_creative_brief_v11",
        "canonical_id": "CAN-MATE-CREATIVE_BRIEF_V11",
        "title": "Creative Brief",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "creative_brief",
        "linked_ids": [
          "creativebrief:creative-brief:brief"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_financial_model_v14",
        "object_type": "material",
        "object_id": "mat_financial_model_v14",
        "canonical_id": "CAN-MATE-FINANCIAL_MODEL_V14",
        "title": "Detailed Financial Model",
        "status": "approval_only",
        "owner_system": "NexaCRM",
        "company_name": "financial_model",
        "linked_ids": [
          "financialmodel:detailed-financial-model:workbook"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_brief_v10",
        "object_type": "material",
        "object_id": "mat_brief_v10",
        "canonical_id": "CAN-MATE-BRIEF_V10",
        "title": "General Solution Brief",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "brief",
        "linked_ids": [
          "brief:general-solution-brief:brief"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_pitch_teaser_v32",
        "object_type": "material",
        "object_id": "mat_pitch_teaser_v32",
        "canonical_id": "CAN-MATE-PITCH_TEASER_V32",
        "title": "Investor Teaser",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "pitch_teaser",
        "linked_ids": [
          "pitchteaser:investor-teaser:deck"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_security_packet_v21",
        "object_type": "material",
        "object_id": "mat_security_packet_v21",
        "canonical_id": "CAN-MATE-SECURITY_PACKET_V21",
        "title": "Security Packet",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "sensitive",
        "linked_ids": [
          "sensitive:security-packet:data-room"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_modelops_drift_monitor_drift_monitor_revenue_forecast",
        "object_type": "modelops_drift_monitor",
        "object_id": "drift_monitor_revenue_forecast",
        "canonical_id": "CAN-MODE-MONITOR_REVENUE_FORECAST",
        "title": "Revenue Forecast Drift Monitor",
        "status": "active",
        "owner_system": "ModelOps Drift Monitor",
        "company_name": "",
        "linked_ids": [
          "forecast_model_revenue_baseline"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_modelops_feature_set_feature_set_revenue_forecast",
        "object_type": "modelops_feature_set",
        "object_id": "feature_set_revenue_forecast",
        "canonical_id": "CAN-MODE-SET_REVENUE_FORECAST",
        "title": "Revenue Forecast Feature Set",
        "status": "approved",
        "owner_system": "ModelOps Feature Store",
        "company_name": "",
        "linked_ids": [
          "contract_crm_deals",
          "contract_growth_attribution",
          "contract_subscription_usage",
          "forecast_model_revenue_baseline"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_partner_partner_builder_systems",
        "object_type": "partner",
        "object_id": "partner_builder_systems",
        "canonical_id": "CAN-PART-BUILDER_SYSTEMS",
        "title": "Builder Systems Collective",
        "status": "onboarding_review",
        "owner_system": "Partner Portal",
        "company_name": "Builder Systems Collective",
        "linked_ids": [
          "buildersystems.example"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_partner_partner_nexa_growth_advisors",
        "object_type": "partner",
        "object_id": "partner_nexa_growth_advisors",
        "canonical_id": "CAN-PART-NEXA_GROWTH_ADVISORS",
        "title": "Nexa Growth Advisors",
        "status": "active",
        "owner_system": "Partner Portal",
        "company_name": "Nexa Growth Advisors",
        "linked_ids": [
          "nexagrowth.example"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_price_book_pb_growth_2026",
        "object_type": "price_book",
        "object_id": "pb_growth_2026",
        "canonical_id": "CAN-PRIC-GROWTH_2026",
        "title": "Growth Partner Price Book",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_price_book_pb_standard_2026",
        "object_type": "price_book",
        "object_id": "pb_standard_2026",
        "canonical_id": "CAN-PRIC-STANDARD_2026",
        "title": "Standard 2026 Commercial Price Book",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_privacy_request_privacy_demo_export",
        "object_type": "privacy_request",
        "object_id": "privacy_demo_export",
        "canonical_id": "CAN-PRIV-DEMO_EXPORT",
        "title": "Demo audit export request",
        "status": "resolved",
        "owner_system": "Shared Platform",
        "company_name": "Demo audit export request",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_product_prod_enterprise_core",
        "object_type": "product",
        "object_id": "prod_enterprise_core",
        "canonical_id": "CAN-PROD-ENTERPRISE_CORE",
        "title": "NexaMarket Enterprise Core",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "Subscription",
        "linked_ids": [
          "pb_standard_2026"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_product_prod_partner_enablement",
        "object_type": "product",
        "object_id": "prod_partner_enablement",
        "canonical_id": "CAN-PROD-PARTNER_ENABLEMENT",
        "title": "Partner Enablement Pack",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "Services",
        "linked_ids": [
          "pb_standard_2026"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_product_prod_pipeline_plus",
        "object_type": "product",
        "object_id": "prod_pipeline_plus",
        "canonical_id": "CAN-PROD-PIPELINE_PLUS",
        "title": "Pipeline Intelligence Plus",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "Add-On",
        "linked_ids": [
          "pb_standard_2026"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_esign_stub",
        "object_type": "provider_connection",
        "object_id": "provider_esign_stub",
        "canonical_id": "CAN-PROV-ESIGN_STUB",
        "title": "E-Sign Provider Stub",
        "status": "attention",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_82ff488291"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_finance_stub",
        "object_type": "provider_connection",
        "object_id": "provider_finance_stub",
        "canonical_id": "CAN-PROV-FINANCE_STUB",
        "title": "Finance Rail Stub",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_d90de779fe"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_calendar_google",
        "object_type": "provider_connection",
        "object_id": "provider_calendar_google",
        "canonical_id": "CAN-PROV-CALENDAR_GOOGLE",
        "title": "Google Calendar",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_16151d24d4"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_email_google",
        "object_type": "provider_connection",
        "object_id": "provider_email_google",
        "canonical_id": "CAN-PROV-EMAIL_GOOGLE",
        "title": "Google Workspace Email",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_053ec8149c"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_crm_stub",
        "object_type": "provider_connection",
        "object_id": "provider_crm_stub",
        "canonical_id": "CAN-PROV-CRM_STUB",
        "title": "NexaCRM Sync Endpoint",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_2e1cb68c2b"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_sync_job_sync_job_86d831e132",
        "object_type": "provider_sync_job",
        "object_id": "sync_job_86d831e132",
        "canonical_id": "CAN-PROV-JOB_86D831E132",
        "title": "Google Calendar sync",
        "status": "completed",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "provider_calendar_google"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_backup_coverage",
        "object_type": "sla_monitor",
        "object_id": "sla_backup_coverage",
        "canonical_id": "CAN-SLA_-BACKUP_COVERAGE",
        "title": "Backup coverage",
        "status": "breach",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_finance_reconciliation",
        "object_type": "sla_monitor",
        "object_id": "sla_finance_reconciliation",
        "canonical_id": "CAN-SLA_-FINANCE_RECONCILIATION",
        "title": "Finance reconciliation queue",
        "status": "healthy",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_identity_access",
        "object_type": "sla_monitor",
        "object_id": "sla_identity_access",
        "canonical_id": "CAN-SLA_-IDENTITY_ACCESS",
        "title": "Identity and access posture",
        "status": "breach",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_provider_delivery",
        "object_type": "sla_monitor",
        "object_id": "sla_provider_delivery",
        "canonical_id": "CAN-SLA_-PROVIDER_DELIVERY",
        "title": "Provider event delivery",
        "status": "healthy",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_trust_artifact_trust_ai_governance_statement",
        "object_type": "trust_artifact",
        "object_id": "trust_ai_governance_statement",
        "canonical_id": "CAN-TRUS-AI_GOVERNANCE_STATEMENT",
        "title": "AI governance statement",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_dpa_template",
        "object_type": "trust_artifact",
        "object_id": "trust_dpa_template",
        "canonical_id": "CAN-TRUS-DPA_TEMPLATE",
        "title": "DPA template",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_security_whitepaper",
        "object_type": "trust_artifact",
        "object_id": "trust_security_whitepaper",
        "canonical_id": "CAN-TRUS-SECURITY_WHITEPAPER",
        "title": "Security architecture whitepaper",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_soc2_placeholder",
        "object_type": "trust_artifact",
        "object_id": "trust_soc2_placeholder",
        "canonical_id": "CAN-TRUS-SOC2_PLACEHOLDER",
        "title": "SOC 2 readiness summary",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_subprocessor_inventory",
        "object_type": "trust_artifact",
        "object_id": "trust_subprocessor_inventory",
        "canonical_id": "CAN-TRUS-SUBPROCESSOR_INVENTORY",
        "title": "Subprocessor inventory",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_incident_route_route_agent_runtime_high",
        "object_type": "observability_incident_route",
        "object_id": "route_agent_runtime_high",
        "canonical_id": "CAN-OBSE-AGENT_RUNTIME_HIGH",
        "title": "Agent runtime high-severity route",
        "status": "active",
        "owner_system": "Incident Router",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_incident_route_route_provider_failure",
        "object_type": "observability_incident_route",
        "object_id": "route_provider_failure",
        "canonical_id": "CAN-OBSE-PROVIDER_FAILURE",
        "title": "Provider gateway incident route",
        "status": "active",
        "owner_system": "Incident Router",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_incident_route_route_finance_controls",
        "object_type": "observability_incident_route",
        "object_id": "route_finance_controls",
        "canonical_id": "CAN-OBSE-FINANCE_CONTROLS",
        "title": "Finance controls incident route",
        "status": "active",
        "owner_system": "Incident Router",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_agent_runtime_global",
        "object_type": "observability_kill_switch",
        "object_id": "kill_agent_runtime_global",
        "canonical_id": "CAN-OBSE-AGENT_RUNTIME_GLOBAL",
        "title": "Agent runtime global kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "agent_runtime",
          "agent_workflows",
          "tool_execution"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_outbound_send",
        "object_type": "observability_kill_switch",
        "object_id": "kill_outbound_send",
        "canonical_id": "CAN-OBSE-OUTBOUND_SEND",
        "title": "Outbound send kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "outbound_send",
          "messaging",
          "campaign_launch"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_provider_live_mode",
        "object_type": "observability_kill_switch",
        "object_id": "kill_provider_live_mode",
        "canonical_id": "CAN-OBSE-PROVIDER_LIVE_MODE",
        "title": "Provider live-mode kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "provider_sync",
          "webhook_intake",
          "live_connectors"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_finance_settlement",
        "object_type": "observability_kill_switch",
        "object_id": "kill_finance_settlement",
        "canonical_id": "CAN-OBSE-FINANCE_SETTLEMENT",
        "title": "Finance settlement kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "settlement_capture",
          "payout_payment",
          "credit_memo_apply"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_agent_runtime_prod",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_agent_runtime_prod",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME_PROD",
        "title": "Agent Runtime Production Pool",
        "status": "active",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "agent_runtime",
          "multi_agent_orchestration"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_provider_sync",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_provider_sync",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC",
        "title": "Provider Sync Worker Pool",
        "status": "active",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "provider_sync"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_finance_controls",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_finance_controls",
        "canonical_id": "CAN-RUNT-FINANCE_CONTROLS",
        "title": "Finance Control Worker Pool",
        "status": "active",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "finance_settlement"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_modelops_training",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Worker Pool",
        "status": "standby",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "modelops_training"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_job_queue_queue_agent_runtime",
        "object_type": "runtime_job_queue",
        "object_id": "queue_agent_runtime",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME",
        "title": "Agent Runtime Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "agent_runtime"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_provider_sync",
        "object_type": "runtime_job_queue",
        "object_id": "queue_provider_sync",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC",
        "title": "Provider Sync Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "provider_sync"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_finance_settlement",
        "object_type": "runtime_job_queue",
        "object_id": "queue_finance_settlement",
        "canonical_id": "CAN-RUNT-FINANCE_SETTLEMENT",
        "title": "Finance Settlement Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "finance_settlement"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_modelops_training",
        "object_type": "runtime_job_queue",
        "object_id": "queue_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "modelops_training"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_multi_agent_orchestration",
        "object_type": "runtime_job_queue",
        "object_id": "queue_multi_agent_orchestration",
        "canonical_id": "CAN-RUNT-MULTI_AGENT_ORCHESTRATION",
        "title": "Multi-Agent Orchestration Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "multi_agent_orchestration"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_crm_tool_v1",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_crm_tool_v1",
        "canonical_id": "CAN-RUNT-CRM_TOOL_V1",
        "title": "CRM Tool Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_nexacrm_sync_endpoint",
          "sandbox_agent_default"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_outbound_guarded",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_outbound_guarded",
        "canonical_id": "CAN-RUNT-OUTBOUND_GUARDED",
        "title": "Governed Outbound Tool Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_provider_email",
          "sandbox_agent_default"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_finance_read",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_finance_read",
        "canonical_id": "CAN-RUNT-FINANCE_READ",
        "title": "Finance Read Tool Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_provider_finance_rail",
          "sandbox_finance_strict"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_modelops_training",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_modelops_training_pipeline",
          "sandbox_modelops_training"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_agent_default",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_agent_default",
        "canonical_id": "CAN-RUNT-AGENT_DEFAULT",
        "title": "Default Agent Runtime Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "quote_prepare",
          "billing_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_finance_strict",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_finance_strict",
        "canonical_id": "CAN-RUNT-FINANCE_STRICT",
        "title": "Strict Finance Control Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_provider_sync",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_provider_sync",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC",
        "title": "Provider Sync Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "provider_sync",
          "webhook_verify",
          "event_replay"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_modelops_training",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "warehouse_read",
          "feature_materialize",
          "model_evaluate",
          "lineage_scan"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_deployment_deploy_agent_runtime_v56",
        "object_type": "runtime_deployment",
        "object_id": "deploy_agent_runtime_v56",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME_V56",
        "title": "Agent Runtime v5.6",
        "status": "active",
        "owner_system": "Runtime Deployment Controller",
        "company_name": "",
        "linked_ids": [
          "pool_agent_runtime_prod"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_deployment_deploy_tool_proxy_v1",
        "object_type": "runtime_deployment",
        "object_id": "deploy_tool_proxy_v1",
        "canonical_id": "CAN-RUNT-TOOL_PROXY_V1",
        "title": "Tool Proxy Gateway v1",
        "status": "active",
        "owner_system": "Runtime Deployment Controller",
        "company_name": "",
        "linked_ids": [
          "pool_provider_sync"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_revenue_coordinator",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_revenue_coordinator",
        "canonical_id": "CAN-ORCH-AGENT_REVENUE_COORDINATOR",
        "title": "Revenue Coordinator Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "quote_prepare",
          "contract_prepare"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_crm_operator",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_crm_operator",
        "canonical_id": "CAN-ORCH-AGENT_CRM_OPERATOR",
        "title": "CRM Operator Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_deal_desk",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_deal_desk",
        "canonical_id": "CAN-ORCH-AGENT_DEAL_DESK",
        "title": "Deal Desk Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "quote_prepare",
          "contract_prepare",
          "crm_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_finance_controller",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_finance_controller",
        "canonical_id": "CAN-ORCH-AGENT_FINANCE_CONTROLLER",
        "title": "Finance Controller Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_success_manager",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_success_manager",
        "canonical_id": "CAN-ORCH-AGENT_SUCCESS_MANAGER",
        "title": "Customer Success Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "meeting_schedule",
          "billing_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_runtime_supervisor",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_runtime_supervisor",
        "canonical_id": "CAN-ORCH-AGENT_RUNTIME_SUPERVISOR",
        "title": "Runtime Supervisor Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "provider_sync",
          "event_replay",
          "lineage_scan"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_blueprint_orch_bp_lead_to_cash_saga",
        "object_type": "orchestration_blueprint",
        "object_id": "orch_bp_lead_to_cash_saga",
        "canonical_id": "CAN-ORCH-BP_LEAD_TO_CASH_SAGA",
        "title": "Lead-to-cash durable saga",
        "status": "active",
        "owner_system": "Durable Workflow Engine",
        "company_name": "",
        "linked_ids": [
          "orch_agent_revenue_coordinator",
          "orch_agent_crm_operator",
          "orch_agent_deal_desk",
          "orch_agent_finance_controller",
          "orch_agent_success_manager"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_blueprint_orch_bp_renewal_risk_save",
        "object_type": "orchestration_blueprint",
        "object_id": "orch_bp_renewal_risk_save",
        "canonical_id": "CAN-ORCH-BP_RENEWAL_RISK_SAVE",
        "title": "Renewal risk-save orchestration",
        "status": "active",
        "owner_system": "Durable Workflow Engine",
        "company_name": "",
        "linked_ids": [
          "orch_agent_revenue_coordinator",
          "orch_agent_success_manager",
          "orch_agent_finance_controller"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_blueprint_orch_bp_runtime_incident_saga",
        "object_type": "orchestration_blueprint",
        "object_id": "orch_bp_runtime_incident_saga",
        "canonical_id": "CAN-ORCH-BP_RUNTIME_INCIDENT_SAGA",
        "title": "Runtime incident recovery saga",
        "status": "active",
        "owner_system": "Durable Workflow Engine",
        "company_name": "",
        "linked_ids": [
          "orch_agent_runtime_supervisor",
          "orch_agent_revenue_coordinator"
        ],
        "last_updated": "2026-07-09T19:05:10"
      }
    ],
    "conflicts": [
      {
        "id": "conflict_event_gateway_backlog",
        "title": "Event gateway backlog is growing",
        "object_type": "event_bus",
        "entity_kind": "event_bus",
        "object_id": "event_07edcc8a7a",
        "severity": "warning",
        "detail": "12 events still need reconciliation through the API gateway.",
        "recommended_action": "Run reconcile or retry the event gateway.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_stale_catalog_catalog_change_b089a47cc9",
        "title": "Stale catalog change: NexaMarket Workflow Automation Pack",
        "object_type": "catalog_change",
        "entity_kind": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "severity": "warning",
        "detail": "A catalog change has been waiting past its intake day.",
        "recommended_action": "Approve, reject, or update effective-date readiness.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_provider_provider_esign_stub",
        "title": "Provider needs attention: E-Sign Provider Stub",
        "object_type": "provider_connection",
        "entity_kind": "provider_connection",
        "object_id": "provider_esign_stub",
        "severity": "warning",
        "detail": "Credential, webhook, or sync posture requires review.",
        "recommended_action": "Test the connection, rotate credentials, or run manual sync.",
        "status": "resolved",
        "resolved_at": null
      },
      {
        "id": "conflict_idp_cert_idp_customer_saml_stub",
        "title": "Identity provider certificate expires soon: Customer SAML Stub",
        "object_type": "identity_provider",
        "entity_kind": "identity_provider",
        "object_id": "idp_customer_saml_stub",
        "severity": "warning",
        "detail": "SSO certificate metadata is nearing expiry.",
        "recommended_action": "Upload new metadata or rotate signing certificate before production launch.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_partner_partner_builder_systems",
        "title": "Partner needs onboarding review: Builder Systems Collective",
        "object_type": "partner",
        "entity_kind": "partner",
        "object_id": "partner_builder_systems",
        "severity": "medium",
        "detail": "Partner is not fully approved/certified for governed marketplace or co-sell use.",
        "recommended_action": "Complete certification, compliance review, and marketplace eligibility checks.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_growth_segment_segment_enterprise_healthcare",
        "title": "Audience segment has no eligible contacts: Enterprise healthcare operators",
        "object_type": "growth_audience_segment",
        "entity_kind": "growth_audience_segment",
        "object_id": "segment_enterprise_healthcare",
        "severity": "warning",
        "detail": "Segment cannot power governed campaigns until CRM/consent coverage is available.",
        "recommended_action": "Refresh criteria, consent, or contact coverage before campaign launch.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_analytics_no_warehouse_sync",
        "title": "Analytics warehouse has not been synced",
        "object_type": "analytics_warehouse_sync_job",
        "entity_kind": "analytics_warehouse_sync_job",
        "object_id": null,
        "severity": "warning",
        "detail": "Executive BI and forecasting evidence are stronger after at least one warehouse sync job.",
        "recommended_action": "Run an analytics warehouse sync before board or launch review.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_analytics_no_forecast_run",
        "title": "No governed forecast run exists",
        "object_type": "analytics_forecast_run",
        "entity_kind": "analytics_forecast_run",
        "object_id": null,
        "severity": "warning",
        "detail": "Forecast-lab output is required for model-governed executive planning evidence.",
        "recommended_action": "Run a governed forecast using the baseline forecast model.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_modelops_no_training_dataset",
        "title": "No governed training dataset exists",
        "object_type": "modelops_training_dataset",
        "entity_kind": "modelops_training_dataset",
        "object_id": null,
        "severity": "warning",
        "detail": "Forecast models need a governed training dataset for production-readiness evidence.",
        "recommended_action": "Build a ModelOps training dataset from the approved revenue feature set.",
        "status": "resolved",
        "resolved_at": null
      },
      {
        "id": "conflict_modelops_no_drift_run",
        "title": "No drift monitor run exists",
        "object_type": "modelops_drift_run",
        "entity_kind": "modelops_drift_run",
        "object_id": null,
        "severity": "warning",
        "detail": "Forecast drift should be checked before board or production-readiness review.",
        "recommended_action": "Run the revenue forecast drift monitor.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_agentops_no_prompt_eval",
        "title": "No AgentOps prompt evaluation exists",
        "object_type": "agentops_prompt_evaluation",
        "entity_kind": "agentops_prompt_evaluation",
        "object_id": null,
        "severity": "warning",
        "detail": "Prompt versions need evaluation evidence before production workflow use.",
        "recommended_action": "Run a prompt evaluation and queue release approval for deployment.",
        "status": "open",
        "resolved_at": null
      }
    ],
    "resolved_conflict_ids": [
      "conflict_modelops_no_training_dataset",
      "conflict_provider_provider_esign_stub"
    ],
    "resolution_log": [
      {
        "id": "resolution_ba2b775de2",
        "conflict_id": "conflict_provider_provider_esign_stub",
        "resolved_at": "2026-07-12T01:22:17"
      },
      {
        "id": "resolution_84838a0d79",
        "conflict_id": "conflict_modelops_no_training_dataset",
        "resolved_at": "2026-07-09T20:45:01"
      }
    ],
    "sync_log": [],
    "summary": {
      "object_count": 102,
      "conflict_count": 9,
      "pending_events": 12,
      "processed_events": 0,
      "last_reconcile_at": null
    }
  },
  "documents": [],
  "meetings": [],
  "partner_sync": {
    "seller_codes": [],
    "commission_records": [],
    "offboarding_cases": [],
    "final_payout_snapshots": [],
    "summary": {
      "active_codes": 0,
      "earned_payout_value": 0,
      "pending_payout_value": 0,
      "clawback_value": 0,
      "tail_cases": 0
    }
  },
  "documents_summary": {
    "count": 0,
    "latest_final": 0
  },
  "meetings_summary": {
    "scheduled": 0,
    "completed": 0,
    "no_show": 0
  },
  "approval_fabric": {
    "summary": {
      "pending": 1,
      "manual_escalations": 0,
      "overdue": 1,
      "resolved": 0
    },
    "queue": [
      {
        "id": "approval_9bcdd9c074",
        "title": "Catalog governance review: NexaMarket Workflow Automation Pack",
        "company_name": "Product catalog",
        "risk": "medium",
        "status": "pending",
        "assigned_role": "Revenue Ops",
        "due_at": "2026-07-19",
        "sla_status": "overdue",
        "escalation_level": 0
      }
    ]
  },
  "sync_center": {
    "summary": {
      "objects_tracked": 102,
      "open_conflicts": 9,
      "resolved_conflicts": 2,
      "event_backlog": 12
    },
    "object_registry": [
      {
        "id": "sync_agentops_policy",
        "object_kind": "agentops_policy",
        "object_type": "agentops_policy",
        "object_id": "sync_agentops_policy",
        "count": 2,
        "system_owner": "AgentOps Policy Engine",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_agentops_prompt_version",
        "object_kind": "agentops_prompt_version",
        "object_type": "agentops_prompt_version",
        "object_id": "sync_agentops_prompt_version",
        "count": 2,
        "system_owner": "AgentOps Prompt Registry",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_ai_model",
        "object_kind": "ai_model",
        "object_type": "ai_model",
        "object_id": "sync_ai_model",
        "count": 2,
        "system_owner": "AI Governance",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_analytics_dashboard_refresh",
        "object_kind": "analytics_dashboard_refresh",
        "object_type": "analytics_dashboard_refresh",
        "object_id": "sync_analytics_dashboard_refresh",
        "count": 1,
        "system_owner": "BI Refresh Scheduler",
        "last_updated": "2026-07-12T01:35:50",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_analytics_data_contract",
        "object_kind": "analytics_data_contract",
        "object_type": "analytics_data_contract",
        "object_id": "sync_analytics_data_contract",
        "count": 4,
        "system_owner": "Data Contract Monitor",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_analytics_forecast_model",
        "object_kind": "analytics_forecast_model",
        "object_type": "analytics_forecast_model",
        "object_id": "sync_analytics_forecast_model",
        "count": 1,
        "system_owner": "Forecast Lab",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_analytics_metric_definition",
        "object_kind": "analytics_metric_definition",
        "object_type": "analytics_metric_definition",
        "object_id": "sync_analytics_metric_definition",
        "count": 4,
        "system_owner": "Metric Semantic Layer",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_analytics_warehouse_connection",
        "object_kind": "analytics_warehouse_connection",
        "object_type": "analytics_warehouse_connection",
        "object_id": "sync_analytics_warehouse_connection",
        "count": 1,
        "system_owner": "Analytics Warehouse Gateway",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_billing_provider_connection",
        "object_kind": "billing_provider_connection",
        "object_type": "billing_provider_connection",
        "object_id": "sync_billing_provider_connection",
        "count": 2,
        "system_owner": "Subscription Billing Gateway",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_catalog_change",
        "object_kind": "catalog_change",
        "object_type": "catalog_change",
        "object_id": "sync_catalog_change",
        "count": 1,
        "system_owner": "NexaMarket CPQ",
        "last_updated": "2026-07-17T19:33:52",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_deal",
        "object_kind": "deal",
        "object_type": "deal",
        "object_id": "sync_deal",
        "count": 1,
        "system_owner": "NexaCRM",
        "last_updated": "2026-07-09T20:39:02",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_environment",
        "object_kind": "environment",
        "object_type": "environment",
        "object_id": "sync_environment",
        "count": 3,
        "system_owner": "Release Control",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_event_subscription",
        "object_kind": "event_subscription",
        "object_type": "event_subscription",
        "object_id": "sync_event_subscription",
        "count": 4,
        "system_owner": "Event Delivery",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_growth_audience_segment",
        "object_kind": "growth_audience_segment",
        "object_type": "growth_audience_segment",
        "object_id": "sync_growth_audience_segment",
        "count": 1,
        "system_owner": "Growth Audience Builder",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_identity_provider",
        "object_kind": "identity_provider",
        "object_type": "identity_provider",
        "object_id": "sync_identity_provider",
        "count": 2,
        "system_owner": "Shared Identity",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_intelligence_metric_snapshot",
        "object_kind": "intelligence_metric_snapshot",
        "object_type": "intelligence_metric_snapshot",
        "object_id": "sync_intelligence_metric_snapshot",
        "count": 1,
        "system_owner": "Revenue Intelligence Lake",
        "last_updated": "2026-07-12T01:35:50",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_intelligence_playbook",
        "object_kind": "intelligence_playbook",
        "object_type": "intelligence_playbook",
        "object_id": "sync_intelligence_playbook",
        "count": 2,
        "system_owner": "Revenue Playbook Orchestrator",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_material",
        "object_kind": "material",
        "object_type": "material",
        "object_id": "sync_material",
        "count": 8,
        "system_owner": "NexaCRM",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_modelops_drift_monitor",
        "object_kind": "modelops_drift_monitor",
        "object_type": "modelops_drift_monitor",
        "object_id": "sync_modelops_drift_monitor",
        "count": 1,
        "system_owner": "ModelOps Drift Monitor",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_modelops_feature_set",
        "object_kind": "modelops_feature_set",
        "object_type": "modelops_feature_set",
        "object_id": "sync_modelops_feature_set",
        "count": 1,
        "system_owner": "ModelOps Feature Store",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_observability_incident_route",
        "object_kind": "observability_incident_route",
        "object_type": "observability_incident_route",
        "object_id": "sync_observability_incident_route",
        "count": 3,
        "system_owner": "Incident Router",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_observability_kill_switch",
        "object_kind": "observability_kill_switch",
        "object_type": "observability_kill_switch",
        "object_id": "sync_observability_kill_switch",
        "count": 4,
        "system_owner": "Production Kill-Switch Control",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_orchestration_agent",
        "object_kind": "orchestration_agent",
        "object_type": "orchestration_agent",
        "object_id": "sync_orchestration_agent",
        "count": 6,
        "system_owner": "Multi-Agent Registry",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_orchestration_blueprint",
        "object_kind": "orchestration_blueprint",
        "object_type": "orchestration_blueprint",
        "object_id": "sync_orchestration_blueprint",
        "count": 3,
        "system_owner": "Durable Workflow Engine",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_partner",
        "object_kind": "partner",
        "object_type": "partner",
        "object_id": "sync_partner",
        "count": 2,
        "system_owner": "Partner Portal",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_price_book",
        "object_kind": "price_book",
        "object_type": "price_book",
        "object_id": "sync_price_book",
        "count": 2,
        "system_owner": "NexaMarket CPQ",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_privacy_request",
        "object_kind": "privacy_request",
        "object_type": "privacy_request",
        "object_id": "sync_privacy_request",
        "count": 1,
        "system_owner": "Shared Platform",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_product",
        "object_kind": "product",
        "object_type": "product",
        "object_id": "sync_product",
        "count": 3,
        "system_owner": "NexaMarket CPQ",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_provider_connection",
        "object_kind": "provider_connection",
        "object_type": "provider_connection",
        "object_id": "sync_provider_connection",
        "count": 5,
        "system_owner": "Provider Gateway",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_provider_sync_job",
        "object_kind": "provider_sync_job",
        "object_type": "provider_sync_job",
        "object_id": "sync_provider_sync_job",
        "count": 1,
        "system_owner": "Provider Gateway",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_runtime_deployment",
        "object_kind": "runtime_deployment",
        "object_type": "runtime_deployment",
        "object_id": "sync_runtime_deployment",
        "count": 2,
        "system_owner": "Runtime Deployment Controller",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_runtime_job_queue",
        "object_kind": "runtime_job_queue",
        "object_type": "runtime_job_queue",
        "object_id": "sync_runtime_job_queue",
        "count": 5,
        "system_owner": "Runtime Job Queue",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_runtime_sandbox_policy",
        "object_kind": "runtime_sandbox_policy",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sync_runtime_sandbox_policy",
        "count": 4,
        "system_owner": "Runtime Sandbox Policy Engine",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_runtime_tool_proxy",
        "object_kind": "runtime_tool_proxy",
        "object_type": "runtime_tool_proxy",
        "object_id": "sync_runtime_tool_proxy",
        "count": 4,
        "system_owner": "Tool Proxy Gateway",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_runtime_worker_pool",
        "object_kind": "runtime_worker_pool",
        "object_type": "runtime_worker_pool",
        "object_id": "sync_runtime_worker_pool",
        "count": 4,
        "system_owner": "Runtime Worker Orchestrator",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_sla_monitor",
        "object_kind": "sla_monitor",
        "object_type": "sla_monitor",
        "object_id": "sync_sla_monitor",
        "count": 4,
        "system_owner": "Observability",
        "last_updated": "2026-07-27T15:37:40",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "sync_trust_artifact",
        "object_kind": "trust_artifact",
        "object_type": "trust_artifact",
        "object_id": "sync_trust_artifact",
        "count": 5,
        "system_owner": "Trust Center",
        "last_updated": "2026-07-09T19:05:10",
        "coverage": "Canonical IDs, ownership, and linked-record integrity."
      },
      {
        "id": "registry_agentops_policy_agent_policy_revenue_assistant",
        "object_type": "agentops_policy",
        "object_id": "agent_policy_revenue_assistant",
        "canonical_id": "CAN-AGEN-POLICY_REVENUE_ASSISTANT",
        "title": "Revenue Assistant Policy",
        "status": "approved",
        "owner_system": "AgentOps Policy Engine",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "outbound_send"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_agentops_policy_agent_policy_revops_analyst",
        "object_type": "agentops_policy",
        "object_id": "agent_policy_revops_analyst",
        "canonical_id": "CAN-AGEN-POLICY_REVOPS_ANALYST",
        "title": "RevOps Analyst Policy",
        "status": "approved",
        "owner_system": "AgentOps Policy Engine",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "billing_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_agentops_prompt_version_prompt_revenue_assistant_v1",
        "object_type": "agentops_prompt_version",
        "object_id": "prompt_revenue_assistant_v1",
        "canonical_id": "CAN-AGEN-REVENUE_ASSISTANT_V1",
        "title": "revenue_assistant_followup",
        "status": "evaluated",
        "owner_system": "AgentOps Prompt Registry",
        "company_name": "",
        "linked_ids": [
          "agent_policy_revenue_assistant"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_agentops_prompt_version_prompt_revops_explainer_v1",
        "object_type": "agentops_prompt_version",
        "object_id": "prompt_revops_explainer_v1",
        "canonical_id": "CAN-AGEN-REVOPS_EXPLAINER_V1",
        "title": "revops_executive_explainer",
        "status": "evaluated",
        "owner_system": "AgentOps Prompt Registry",
        "company_name": "",
        "linked_ids": [
          "agent_policy_revops_analyst"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_ai_model_model_nexa_orchestrator_local",
        "object_type": "ai_model",
        "object_id": "model_nexa_orchestrator_local",
        "canonical_id": "CAN-AI_M-NEXA_ORCHESTRATOR_LOCAL",
        "title": "Nexa Orchestrator Local Policy Agent",
        "status": "approved_for_demo",
        "owner_system": "AI Governance",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_ai_model_model_outbound_compliance_guard",
        "object_type": "ai_model",
        "object_id": "model_outbound_compliance_guard",
        "canonical_id": "CAN-AI_M-OUTBOUND_COMPLIANCE_GUARD",
        "title": "Outbound Compliance Guard",
        "status": "approved_for_demo",
        "owner_system": "AI Governance",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_dashboard_refresh_dashboard_refresh_ffc92770ea",
        "object_type": "analytics_dashboard_refresh",
        "object_id": "dashboard_refresh_ffc92770ea",
        "canonical_id": "CAN-ANAL-REFRESH_FFC92770EA",
        "title": "Executive Revenue BI Dashboard",
        "status": "published_simulated",
        "owner_system": "BI Refresh Scheduler",
        "company_name": "",
        "linked_ids": [
          "snapshot_749adf2d44"
        ],
        "last_updated": "2026-07-12T01:35:50"
      },
      {
        "id": "registry_analytics_data_contract_contract_crm_deals",
        "object_type": "analytics_data_contract",
        "object_id": "contract_crm_deals",
        "canonical_id": "CAN-ANAL-CRM_DEALS",
        "title": "CRM deals contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_data_contract_contract_growth_attribution",
        "object_type": "analytics_data_contract",
        "object_id": "contract_growth_attribution",
        "canonical_id": "CAN-ANAL-GROWTH_ATTRIBUTION",
        "title": "Growth attribution contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_data_contract_contract_invoices",
        "object_type": "analytics_data_contract",
        "object_id": "contract_invoices",
        "canonical_id": "CAN-ANAL-INVOICES",
        "title": "Invoice revenue contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_data_contract_contract_subscription_usage",
        "object_type": "analytics_data_contract",
        "object_id": "contract_subscription_usage",
        "canonical_id": "CAN-ANAL-SUBSCRIPTION_USAGE",
        "title": "Subscription telemetry contract",
        "status": "active",
        "owner_system": "Data Contract Monitor",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_analytics_forecast_model_forecast_model_revenue_baseline",
        "object_type": "analytics_forecast_model",
        "object_id": "forecast_model_revenue_baseline",
        "canonical_id": "CAN-ANAL-MODEL_REVENUE_BASELINE",
        "title": "Revenue Baseline Forecast",
        "status": "trained_simulated",
        "owner_system": "Forecast Lab",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_open_pipeline",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_open_pipeline",
        "canonical_id": "CAN-ANAL-OPEN_PIPELINE",
        "title": "Open Pipeline",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_operational_risk_count",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_operational_risk_count",
        "canonical_id": "CAN-ANAL-OPERATIONAL_RISK_COUNT",
        "title": "Operational Risk Count",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_subscription_mrr",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_subscription_mrr",
        "canonical_id": "CAN-ANAL-SUBSCRIPTION_MRR",
        "title": "Subscription MRR",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_metric_definition_metric_weighted_forecast",
        "object_type": "analytics_metric_definition",
        "object_id": "metric_weighted_forecast",
        "canonical_id": "CAN-ANAL-WEIGHTED_FORECAST",
        "title": "Weighted Forecast",
        "status": "approved",
        "owner_system": "Metric Semantic Layer",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_analytics_warehouse_connection_wh_local_revenue_lake",
        "object_type": "analytics_warehouse_connection",
        "object_id": "wh_local_revenue_lake",
        "canonical_id": "CAN-ANAL-LOCAL_REVENUE_LAKE",
        "title": "Nexa Revenue Lakehouse",
        "status": "connected_simulated",
        "owner_system": "Analytics Warehouse Gateway",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_billing_provider_connection_bill_conn_chargebee_stub",
        "object_type": "billing_provider_connection",
        "object_id": "bill_conn_chargebee_stub",
        "canonical_id": "CAN-BILL-CONN_CHARGEBEE_STUB",
        "title": "Chargebee Billing Stub",
        "status": "ready",
        "owner_system": "Subscription Billing Gateway",
        "company_name": "",
        "linked_ids": [
          "site_demo_nexamarket"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_billing_provider_connection_bill_conn_stripe_stub",
        "object_type": "billing_provider_connection",
        "object_id": "bill_conn_stripe_stub",
        "canonical_id": "CAN-BILL-CONN_STRIPE_STUB",
        "title": "Stripe Billing Stub",
        "status": "connected_simulated",
        "owner_system": "Subscription Billing Gateway",
        "company_name": "",
        "linked_ids": [
          "acct_demo_nexamarket"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_catalog_change_catalog_change_b089a47cc9",
        "object_type": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "canonical_id": "CAN-CATA-CHANGE_B089A47CC9",
        "title": "Add product NexaMarket Workflow Automation Pack",
        "status": "pending_approval",
        "owner_system": "NexaMarket CPQ",
        "company_name": "",
        "linked_ids": [
          "prod_37d27276ac",
          "approval_9bcdd9c074"
        ],
        "last_updated": "2026-07-17T19:33:52"
      },
      {
        "id": "registry_deal_placeholder_deal_source_control_seed",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "canonical_id": "CAN-DEAL-DEAL_SOURCE_CONTROL_SEED",
        "title": "Source-control seed placeholder",
        "status": "placeholder",
        "owner_system": "NexaCRM",
        "company_name": "",
        "linked_ids": [
          "NM-OWNER-PRIMARY"
        ],
        "last_updated": "2026-07-09T20:39:02"
      },
      {
        "id": "registry_environment_env_production",
        "object_type": "environment",
        "object_id": "env_production",
        "canonical_id": "CAN-ENVI-PRODUCTION",
        "title": "Production",
        "status": "blocked",
        "owner_system": "Release Control",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_environment_env_sandbox",
        "object_type": "environment",
        "object_id": "env_sandbox",
        "canonical_id": "CAN-ENVI-SANDBOX",
        "title": "Sandbox",
        "status": "attention",
        "owner_system": "Release Control",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_environment_env_staging",
        "object_type": "environment",
        "object_id": "env_staging",
        "canonical_id": "CAN-ENVI-STAGING",
        "title": "Staging",
        "status": "attention",
        "owner_system": "Release Control",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_event_subscription_sub_dd6819138c",
        "object_type": "event_subscription",
        "object_id": "sub_dd6819138c",
        "canonical_id": "CAN-EVEN-DD6819138C",
        "title": "Customer webhook replay target",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T20:41:01"
      },
      {
        "id": "registry_event_subscription_sub_finance_invoice",
        "object_type": "event_subscription",
        "object_id": "sub_finance_invoice",
        "canonical_id": "CAN-EVEN-FINANCE_INVOICE",
        "title": "Finance invoice handoff",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_event_subscription_sub_nexacrm_all",
        "object_type": "event_subscription",
        "object_id": "sub_nexacrm_all",
        "canonical_id": "CAN-EVEN-NEXACRM_ALL",
        "title": "NexaCRM canonical sync",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_event_subscription_sub_security_audit",
        "object_type": "event_subscription",
        "object_id": "sub_security_audit",
        "canonical_id": "CAN-EVEN-SECURITY_AUDIT",
        "title": "Security audit ledger",
        "status": "active",
        "owner_system": "Event Delivery",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_growth_audience_segment_segment_enterprise_healthcare",
        "object_type": "growth_audience_segment",
        "object_id": "segment_enterprise_healthcare",
        "canonical_id": "CAN-GROW-ENTERPRISE_HEALTHCARE",
        "title": "Enterprise healthcare operators",
        "status": "active",
        "owner_system": "Growth Audience Builder",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_identity_provider_idp_customer_saml_stub",
        "object_type": "identity_provider",
        "object_id": "idp_customer_saml_stub",
        "canonical_id": "CAN-IDEN-CUSTOMER_SAML_STUB",
        "title": "Customer SAML Stub",
        "status": "simulated",
        "owner_system": "Shared Identity",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_identity_provider_idp_nexa_identity_oidc",
        "object_type": "identity_provider",
        "object_id": "idp_nexa_identity_oidc",
        "canonical_id": "CAN-IDEN-NEXA_IDENTITY_OIDC",
        "title": "Nexa Identity OIDC",
        "status": "connected",
        "owner_system": "Shared Identity",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_intelligence_metric_snapshot_snapshot_749adf2d44",
        "object_type": "intelligence_metric_snapshot",
        "object_id": "snapshot_749adf2d44",
        "canonical_id": "CAN-INTE-749ADF2D44",
        "title": "Metric snapshot 2026-07",
        "status": "at_risk",
        "owner_system": "Revenue Intelligence Lake",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-12T01:35:50"
      },
      {
        "id": "registry_intelligence_playbook_playbook_operational_risk",
        "object_type": "intelligence_playbook",
        "object_id": "playbook_operational_risk",
        "canonical_id": "CAN-INTE-OPERATIONAL_RISK",
        "title": "Operational risk cleanup",
        "status": "active",
        "owner_system": "Revenue Playbook Orchestrator",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_intelligence_playbook_playbook_pipeline_coverage",
        "object_type": "intelligence_playbook",
        "object_id": "playbook_pipeline_coverage",
        "canonical_id": "CAN-INTE-PIPELINE_COVERAGE",
        "title": "Pipeline coverage recovery",
        "status": "active",
        "owner_system": "Revenue Playbook Orchestrator",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_audience_summary_v11",
        "object_type": "material",
        "object_id": "mat_audience_summary_v11",
        "canonical_id": "CAN-MATE-AUDIENCE_SUMMARY_V11",
        "title": "Audience Summary",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "audience_summary",
        "linked_ids": [
          "audiencesummary:audience-summary:summary"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_budget_guardrail_v10",
        "object_type": "material",
        "object_id": "mat_budget_guardrail_v10",
        "canonical_id": "CAN-MATE-BUDGET_GUARDRAIL_V10",
        "title": "Budget Guardrails",
        "status": "approval_only",
        "owner_system": "NexaCRM",
        "company_name": "budget",
        "linked_ids": [
          "budget:budget-guardrails:policy"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_pitch_deck_v60",
        "object_type": "material",
        "object_id": "mat_pitch_deck_v60",
        "canonical_id": "CAN-MATE-PITCH_DECK_V60",
        "title": "Corporate Pitch Deck",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "pitch_deck",
        "linked_ids": [
          "pitchdeck:corporate-pitch-deck:deck"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_creative_brief_v11",
        "object_type": "material",
        "object_id": "mat_creative_brief_v11",
        "canonical_id": "CAN-MATE-CREATIVE_BRIEF_V11",
        "title": "Creative Brief",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "creative_brief",
        "linked_ids": [
          "creativebrief:creative-brief:brief"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_financial_model_v14",
        "object_type": "material",
        "object_id": "mat_financial_model_v14",
        "canonical_id": "CAN-MATE-FINANCIAL_MODEL_V14",
        "title": "Detailed Financial Model",
        "status": "approval_only",
        "owner_system": "NexaCRM",
        "company_name": "financial_model",
        "linked_ids": [
          "financialmodel:detailed-financial-model:workbook"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_brief_v10",
        "object_type": "material",
        "object_id": "mat_brief_v10",
        "canonical_id": "CAN-MATE-BRIEF_V10",
        "title": "General Solution Brief",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "brief",
        "linked_ids": [
          "brief:general-solution-brief:brief"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_pitch_teaser_v32",
        "object_type": "material",
        "object_id": "mat_pitch_teaser_v32",
        "canonical_id": "CAN-MATE-PITCH_TEASER_V32",
        "title": "Investor Teaser",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "pitch_teaser",
        "linked_ids": [
          "pitchteaser:investor-teaser:deck"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_material_mat_security_packet_v21",
        "object_type": "material",
        "object_id": "mat_security_packet_v21",
        "canonical_id": "CAN-MATE-SECURITY_PACKET_V21",
        "title": "Security Packet",
        "status": "approved",
        "owner_system": "NexaCRM",
        "company_name": "sensitive",
        "linked_ids": [
          "sensitive:security-packet:data-room"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_modelops_drift_monitor_drift_monitor_revenue_forecast",
        "object_type": "modelops_drift_monitor",
        "object_id": "drift_monitor_revenue_forecast",
        "canonical_id": "CAN-MODE-MONITOR_REVENUE_FORECAST",
        "title": "Revenue Forecast Drift Monitor",
        "status": "active",
        "owner_system": "ModelOps Drift Monitor",
        "company_name": "",
        "linked_ids": [
          "forecast_model_revenue_baseline"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_modelops_feature_set_feature_set_revenue_forecast",
        "object_type": "modelops_feature_set",
        "object_id": "feature_set_revenue_forecast",
        "canonical_id": "CAN-MODE-SET_REVENUE_FORECAST",
        "title": "Revenue Forecast Feature Set",
        "status": "approved",
        "owner_system": "ModelOps Feature Store",
        "company_name": "",
        "linked_ids": [
          "contract_crm_deals",
          "contract_growth_attribution",
          "contract_subscription_usage",
          "forecast_model_revenue_baseline"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_partner_partner_builder_systems",
        "object_type": "partner",
        "object_id": "partner_builder_systems",
        "canonical_id": "CAN-PART-BUILDER_SYSTEMS",
        "title": "Builder Systems Collective",
        "status": "onboarding_review",
        "owner_system": "Partner Portal",
        "company_name": "Builder Systems Collective",
        "linked_ids": [
          "buildersystems.example"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_partner_partner_nexa_growth_advisors",
        "object_type": "partner",
        "object_id": "partner_nexa_growth_advisors",
        "canonical_id": "CAN-PART-NEXA_GROWTH_ADVISORS",
        "title": "Nexa Growth Advisors",
        "status": "active",
        "owner_system": "Partner Portal",
        "company_name": "Nexa Growth Advisors",
        "linked_ids": [
          "nexagrowth.example"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_price_book_pb_growth_2026",
        "object_type": "price_book",
        "object_id": "pb_growth_2026",
        "canonical_id": "CAN-PRIC-GROWTH_2026",
        "title": "Growth Partner Price Book",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_price_book_pb_standard_2026",
        "object_type": "price_book",
        "object_id": "pb_standard_2026",
        "canonical_id": "CAN-PRIC-STANDARD_2026",
        "title": "Standard 2026 Commercial Price Book",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_privacy_request_privacy_demo_export",
        "object_type": "privacy_request",
        "object_id": "privacy_demo_export",
        "canonical_id": "CAN-PRIV-DEMO_EXPORT",
        "title": "Demo audit export request",
        "status": "resolved",
        "owner_system": "Shared Platform",
        "company_name": "Demo audit export request",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_product_prod_enterprise_core",
        "object_type": "product",
        "object_id": "prod_enterprise_core",
        "canonical_id": "CAN-PROD-ENTERPRISE_CORE",
        "title": "NexaMarket Enterprise Core",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "Subscription",
        "linked_ids": [
          "pb_standard_2026"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_product_prod_partner_enablement",
        "object_type": "product",
        "object_id": "prod_partner_enablement",
        "canonical_id": "CAN-PROD-PARTNER_ENABLEMENT",
        "title": "Partner Enablement Pack",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "Services",
        "linked_ids": [
          "pb_standard_2026"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_product_prod_pipeline_plus",
        "object_type": "product",
        "object_id": "prod_pipeline_plus",
        "canonical_id": "CAN-PROD-PIPELINE_PLUS",
        "title": "Pipeline Intelligence Plus",
        "status": "active",
        "owner_system": "NexaMarket CPQ",
        "company_name": "Add-On",
        "linked_ids": [
          "pb_standard_2026"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_esign_stub",
        "object_type": "provider_connection",
        "object_id": "provider_esign_stub",
        "canonical_id": "CAN-PROV-ESIGN_STUB",
        "title": "E-Sign Provider Stub",
        "status": "attention",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_82ff488291"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_finance_stub",
        "object_type": "provider_connection",
        "object_id": "provider_finance_stub",
        "canonical_id": "CAN-PROV-FINANCE_STUB",
        "title": "Finance Rail Stub",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_d90de779fe"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_calendar_google",
        "object_type": "provider_connection",
        "object_id": "provider_calendar_google",
        "canonical_id": "CAN-PROV-CALENDAR_GOOGLE",
        "title": "Google Calendar",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_16151d24d4"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_email_google",
        "object_type": "provider_connection",
        "object_id": "provider_email_google",
        "canonical_id": "CAN-PROV-EMAIL_GOOGLE",
        "title": "Google Workspace Email",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_053ec8149c"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_connection_provider_crm_stub",
        "object_type": "provider_connection",
        "object_id": "provider_crm_stub",
        "canonical_id": "CAN-PROV-CRM_STUB",
        "title": "NexaCRM Sync Endpoint",
        "status": "connected",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "credential_2e1cb68c2b"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_provider_sync_job_sync_job_86d831e132",
        "object_type": "provider_sync_job",
        "object_id": "sync_job_86d831e132",
        "canonical_id": "CAN-PROV-JOB_86D831E132",
        "title": "Google Calendar sync",
        "status": "completed",
        "owner_system": "Provider Gateway",
        "company_name": "",
        "linked_ids": [
          "provider_calendar_google"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_backup_coverage",
        "object_type": "sla_monitor",
        "object_id": "sla_backup_coverage",
        "canonical_id": "CAN-SLA_-BACKUP_COVERAGE",
        "title": "Backup coverage",
        "status": "breach",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_finance_reconciliation",
        "object_type": "sla_monitor",
        "object_id": "sla_finance_reconciliation",
        "canonical_id": "CAN-SLA_-FINANCE_RECONCILIATION",
        "title": "Finance reconciliation queue",
        "status": "healthy",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_identity_access",
        "object_type": "sla_monitor",
        "object_id": "sla_identity_access",
        "canonical_id": "CAN-SLA_-IDENTITY_ACCESS",
        "title": "Identity and access posture",
        "status": "breach",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_sla_monitor_sla_provider_delivery",
        "object_type": "sla_monitor",
        "object_id": "sla_provider_delivery",
        "canonical_id": "CAN-SLA_-PROVIDER_DELIVERY",
        "title": "Provider event delivery",
        "status": "healthy",
        "owner_system": "Observability",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_trust_artifact_trust_ai_governance_statement",
        "object_type": "trust_artifact",
        "object_id": "trust_ai_governance_statement",
        "canonical_id": "CAN-TRUS-AI_GOVERNANCE_STATEMENT",
        "title": "AI governance statement",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_dpa_template",
        "object_type": "trust_artifact",
        "object_id": "trust_dpa_template",
        "canonical_id": "CAN-TRUS-DPA_TEMPLATE",
        "title": "DPA template",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_security_whitepaper",
        "object_type": "trust_artifact",
        "object_id": "trust_security_whitepaper",
        "canonical_id": "CAN-TRUS-SECURITY_WHITEPAPER",
        "title": "Security architecture whitepaper",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_soc2_placeholder",
        "object_type": "trust_artifact",
        "object_id": "trust_soc2_placeholder",
        "canonical_id": "CAN-TRUS-SOC2_PLACEHOLDER",
        "title": "SOC 2 readiness summary",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_trust_artifact_trust_subprocessor_inventory",
        "object_type": "trust_artifact",
        "object_id": "trust_subprocessor_inventory",
        "canonical_id": "CAN-TRUS-SUBPROCESSOR_INVENTORY",
        "title": "Subprocessor inventory",
        "status": "published",
        "owner_system": "Trust Center",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_incident_route_route_agent_runtime_high",
        "object_type": "observability_incident_route",
        "object_id": "route_agent_runtime_high",
        "canonical_id": "CAN-OBSE-AGENT_RUNTIME_HIGH",
        "title": "Agent runtime high-severity route",
        "status": "active",
        "owner_system": "Incident Router",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_incident_route_route_provider_failure",
        "object_type": "observability_incident_route",
        "object_id": "route_provider_failure",
        "canonical_id": "CAN-OBSE-PROVIDER_FAILURE",
        "title": "Provider gateway incident route",
        "status": "active",
        "owner_system": "Incident Router",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_incident_route_route_finance_controls",
        "object_type": "observability_incident_route",
        "object_id": "route_finance_controls",
        "canonical_id": "CAN-OBSE-FINANCE_CONTROLS",
        "title": "Finance controls incident route",
        "status": "active",
        "owner_system": "Incident Router",
        "company_name": "",
        "linked_ids": [],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_agent_runtime_global",
        "object_type": "observability_kill_switch",
        "object_id": "kill_agent_runtime_global",
        "canonical_id": "CAN-OBSE-AGENT_RUNTIME_GLOBAL",
        "title": "Agent runtime global kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "agent_runtime",
          "agent_workflows",
          "tool_execution"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_outbound_send",
        "object_type": "observability_kill_switch",
        "object_id": "kill_outbound_send",
        "canonical_id": "CAN-OBSE-OUTBOUND_SEND",
        "title": "Outbound send kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "outbound_send",
          "messaging",
          "campaign_launch"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_provider_live_mode",
        "object_type": "observability_kill_switch",
        "object_id": "kill_provider_live_mode",
        "canonical_id": "CAN-OBSE-PROVIDER_LIVE_MODE",
        "title": "Provider live-mode kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "provider_sync",
          "webhook_intake",
          "live_connectors"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_observability_kill_switch_kill_finance_settlement",
        "object_type": "observability_kill_switch",
        "object_id": "kill_finance_settlement",
        "canonical_id": "CAN-OBSE-FINANCE_SETTLEMENT",
        "title": "Finance settlement kill switch",
        "status": "inactive",
        "owner_system": "Production Kill-Switch Control",
        "company_name": "",
        "linked_ids": [
          "settlement_capture",
          "payout_payment",
          "credit_memo_apply"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_agent_runtime_prod",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_agent_runtime_prod",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME_PROD",
        "title": "Agent Runtime Production Pool",
        "status": "active",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "agent_runtime",
          "multi_agent_orchestration"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_provider_sync",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_provider_sync",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC",
        "title": "Provider Sync Worker Pool",
        "status": "active",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "provider_sync"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_finance_controls",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_finance_controls",
        "canonical_id": "CAN-RUNT-FINANCE_CONTROLS",
        "title": "Finance Control Worker Pool",
        "status": "active",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "finance_settlement"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_worker_pool_pool_modelops_training",
        "object_type": "runtime_worker_pool",
        "object_id": "pool_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Worker Pool",
        "status": "standby",
        "owner_system": "Runtime Worker Orchestrator",
        "company_name": "",
        "linked_ids": [
          "modelops_training"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_job_queue_queue_agent_runtime",
        "object_type": "runtime_job_queue",
        "object_id": "queue_agent_runtime",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME",
        "title": "Agent Runtime Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "agent_runtime"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_provider_sync",
        "object_type": "runtime_job_queue",
        "object_id": "queue_provider_sync",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC",
        "title": "Provider Sync Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "provider_sync"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_finance_settlement",
        "object_type": "runtime_job_queue",
        "object_id": "queue_finance_settlement",
        "canonical_id": "CAN-RUNT-FINANCE_SETTLEMENT",
        "title": "Finance Settlement Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "finance_settlement"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_modelops_training",
        "object_type": "runtime_job_queue",
        "object_id": "queue_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "modelops_training"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_job_queue_queue_multi_agent_orchestration",
        "object_type": "runtime_job_queue",
        "object_id": "queue_multi_agent_orchestration",
        "canonical_id": "CAN-RUNT-MULTI_AGENT_ORCHESTRATION",
        "title": "Multi-Agent Orchestration Jobs",
        "status": "active",
        "owner_system": "Runtime Job Queue",
        "company_name": "",
        "linked_ids": [
          "multi_agent_orchestration"
        ],
        "last_updated": "2026-07-27T15:37:40"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_crm_tool_v1",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_crm_tool_v1",
        "canonical_id": "CAN-RUNT-CRM_TOOL_V1",
        "title": "CRM Tool Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_nexacrm_sync_endpoint",
          "sandbox_agent_default"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_outbound_guarded",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_outbound_guarded",
        "canonical_id": "CAN-RUNT-OUTBOUND_GUARDED",
        "title": "Governed Outbound Tool Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_provider_email",
          "sandbox_agent_default"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_finance_read",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_finance_read",
        "canonical_id": "CAN-RUNT-FINANCE_READ",
        "title": "Finance Read Tool Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_provider_finance_rail",
          "sandbox_finance_strict"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_tool_proxy_proxy_modelops_training",
        "object_type": "runtime_tool_proxy",
        "object_id": "proxy_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Proxy",
        "status": "active",
        "owner_system": "Tool Proxy Gateway",
        "company_name": "",
        "linked_ids": [
          "conn_modelops_training_pipeline",
          "sandbox_modelops_training"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_agent_default",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_agent_default",
        "canonical_id": "CAN-RUNT-AGENT_DEFAULT",
        "title": "Default Agent Runtime Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "quote_prepare",
          "billing_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_finance_strict",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_finance_strict",
        "canonical_id": "CAN-RUNT-FINANCE_STRICT",
        "title": "Strict Finance Control Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_provider_sync",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_provider_sync",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC",
        "title": "Provider Sync Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "provider_sync",
          "webhook_verify",
          "event_replay"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_sandbox_policy_sandbox_modelops_training",
        "object_type": "runtime_sandbox_policy",
        "object_id": "sandbox_modelops_training",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING",
        "title": "ModelOps Training Sandbox",
        "status": "active",
        "owner_system": "Runtime Sandbox Policy Engine",
        "company_name": "",
        "linked_ids": [
          "warehouse_read",
          "feature_materialize",
          "model_evaluate",
          "lineage_scan"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_deployment_deploy_agent_runtime_v56",
        "object_type": "runtime_deployment",
        "object_id": "deploy_agent_runtime_v56",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME_V56",
        "title": "Agent Runtime v5.6",
        "status": "active",
        "owner_system": "Runtime Deployment Controller",
        "company_name": "",
        "linked_ids": [
          "pool_agent_runtime_prod"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_runtime_deployment_deploy_tool_proxy_v1",
        "object_type": "runtime_deployment",
        "object_id": "deploy_tool_proxy_v1",
        "canonical_id": "CAN-RUNT-TOOL_PROXY_V1",
        "title": "Tool Proxy Gateway v1",
        "status": "active",
        "owner_system": "Runtime Deployment Controller",
        "company_name": "",
        "linked_ids": [
          "pool_provider_sync"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_revenue_coordinator",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_revenue_coordinator",
        "canonical_id": "CAN-ORCH-AGENT_REVENUE_COORDINATOR",
        "title": "Revenue Coordinator Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "quote_prepare",
          "contract_prepare"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_crm_operator",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_crm_operator",
        "canonical_id": "CAN-ORCH-AGENT_CRM_OPERATOR",
        "title": "CRM Operator Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "crm_write"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_deal_desk",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_deal_desk",
        "canonical_id": "CAN-ORCH-AGENT_DEAL_DESK",
        "title": "Deal Desk Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "quote_prepare",
          "contract_prepare",
          "crm_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_finance_controller",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_finance_controller",
        "canonical_id": "CAN-ORCH-AGENT_FINANCE_CONTROLLER",
        "title": "Finance Controller Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_success_manager",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_success_manager",
        "canonical_id": "CAN-ORCH-AGENT_SUCCESS_MANAGER",
        "title": "Customer Success Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "crm_read",
          "meeting_schedule",
          "billing_read"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_agent_orch_agent_runtime_supervisor",
        "object_type": "orchestration_agent",
        "object_id": "orch_agent_runtime_supervisor",
        "canonical_id": "CAN-ORCH-AGENT_RUNTIME_SUPERVISOR",
        "title": "Runtime Supervisor Agent",
        "status": "active",
        "owner_system": "Multi-Agent Registry",
        "company_name": "",
        "linked_ids": [
          "provider_sync",
          "event_replay",
          "lineage_scan"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_blueprint_orch_bp_lead_to_cash_saga",
        "object_type": "orchestration_blueprint",
        "object_id": "orch_bp_lead_to_cash_saga",
        "canonical_id": "CAN-ORCH-BP_LEAD_TO_CASH_SAGA",
        "title": "Lead-to-cash durable saga",
        "status": "active",
        "owner_system": "Durable Workflow Engine",
        "company_name": "",
        "linked_ids": [
          "orch_agent_revenue_coordinator",
          "orch_agent_crm_operator",
          "orch_agent_deal_desk",
          "orch_agent_finance_controller",
          "orch_agent_success_manager"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_blueprint_orch_bp_renewal_risk_save",
        "object_type": "orchestration_blueprint",
        "object_id": "orch_bp_renewal_risk_save",
        "canonical_id": "CAN-ORCH-BP_RENEWAL_RISK_SAVE",
        "title": "Renewal risk-save orchestration",
        "status": "active",
        "owner_system": "Durable Workflow Engine",
        "company_name": "",
        "linked_ids": [
          "orch_agent_revenue_coordinator",
          "orch_agent_success_manager",
          "orch_agent_finance_controller"
        ],
        "last_updated": "2026-07-09T19:05:10"
      },
      {
        "id": "registry_orchestration_blueprint_orch_bp_runtime_incident_saga",
        "object_type": "orchestration_blueprint",
        "object_id": "orch_bp_runtime_incident_saga",
        "canonical_id": "CAN-ORCH-BP_RUNTIME_INCIDENT_SAGA",
        "title": "Runtime incident recovery saga",
        "status": "active",
        "owner_system": "Durable Workflow Engine",
        "company_name": "",
        "linked_ids": [
          "orch_agent_runtime_supervisor",
          "orch_agent_revenue_coordinator"
        ],
        "last_updated": "2026-07-09T19:05:10"
      }
    ],
    "conflicts": [
      {
        "id": "conflict_event_gateway_backlog",
        "title": "Event gateway backlog is growing",
        "object_type": "event_bus",
        "entity_kind": "event_bus",
        "object_id": "event_07edcc8a7a",
        "severity": "warning",
        "detail": "12 events still need reconciliation through the API gateway.",
        "recommended_action": "Run reconcile or retry the event gateway.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_stale_catalog_catalog_change_b089a47cc9",
        "title": "Stale catalog change: NexaMarket Workflow Automation Pack",
        "object_type": "catalog_change",
        "entity_kind": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "severity": "warning",
        "detail": "A catalog change has been waiting past its intake day.",
        "recommended_action": "Approve, reject, or update effective-date readiness.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_provider_provider_esign_stub",
        "title": "Provider needs attention: E-Sign Provider Stub",
        "object_type": "provider_connection",
        "entity_kind": "provider_connection",
        "object_id": "provider_esign_stub",
        "severity": "warning",
        "detail": "Credential, webhook, or sync posture requires review.",
        "recommended_action": "Test the connection, rotate credentials, or run manual sync.",
        "status": "resolved",
        "resolved_at": null
      },
      {
        "id": "conflict_idp_cert_idp_customer_saml_stub",
        "title": "Identity provider certificate expires soon: Customer SAML Stub",
        "object_type": "identity_provider",
        "entity_kind": "identity_provider",
        "object_id": "idp_customer_saml_stub",
        "severity": "warning",
        "detail": "SSO certificate metadata is nearing expiry.",
        "recommended_action": "Upload new metadata or rotate signing certificate before production launch.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_partner_partner_builder_systems",
        "title": "Partner needs onboarding review: Builder Systems Collective",
        "object_type": "partner",
        "entity_kind": "partner",
        "object_id": "partner_builder_systems",
        "severity": "medium",
        "detail": "Partner is not fully approved/certified for governed marketplace or co-sell use.",
        "recommended_action": "Complete certification, compliance review, and marketplace eligibility checks.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_growth_segment_segment_enterprise_healthcare",
        "title": "Audience segment has no eligible contacts: Enterprise healthcare operators",
        "object_type": "growth_audience_segment",
        "entity_kind": "growth_audience_segment",
        "object_id": "segment_enterprise_healthcare",
        "severity": "warning",
        "detail": "Segment cannot power governed campaigns until CRM/consent coverage is available.",
        "recommended_action": "Refresh criteria, consent, or contact coverage before campaign launch.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_analytics_no_warehouse_sync",
        "title": "Analytics warehouse has not been synced",
        "object_type": "analytics_warehouse_sync_job",
        "entity_kind": "analytics_warehouse_sync_job",
        "object_id": null,
        "severity": "warning",
        "detail": "Executive BI and forecasting evidence are stronger after at least one warehouse sync job.",
        "recommended_action": "Run an analytics warehouse sync before board or launch review.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_analytics_no_forecast_run",
        "title": "No governed forecast run exists",
        "object_type": "analytics_forecast_run",
        "entity_kind": "analytics_forecast_run",
        "object_id": null,
        "severity": "warning",
        "detail": "Forecast-lab output is required for model-governed executive planning evidence.",
        "recommended_action": "Run a governed forecast using the baseline forecast model.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_modelops_no_training_dataset",
        "title": "No governed training dataset exists",
        "object_type": "modelops_training_dataset",
        "entity_kind": "modelops_training_dataset",
        "object_id": null,
        "severity": "warning",
        "detail": "Forecast models need a governed training dataset for production-readiness evidence.",
        "recommended_action": "Build a ModelOps training dataset from the approved revenue feature set.",
        "status": "resolved",
        "resolved_at": null
      },
      {
        "id": "conflict_modelops_no_drift_run",
        "title": "No drift monitor run exists",
        "object_type": "modelops_drift_run",
        "entity_kind": "modelops_drift_run",
        "object_id": null,
        "severity": "warning",
        "detail": "Forecast drift should be checked before board or production-readiness review.",
        "recommended_action": "Run the revenue forecast drift monitor.",
        "status": "open",
        "resolved_at": null
      },
      {
        "id": "conflict_agentops_no_prompt_eval",
        "title": "No AgentOps prompt evaluation exists",
        "object_type": "agentops_prompt_evaluation",
        "entity_kind": "agentops_prompt_evaluation",
        "object_id": null,
        "severity": "warning",
        "detail": "Prompt versions need evaluation evidence before production workflow use.",
        "recommended_action": "Run a prompt evaluation and queue release approval for deployment.",
        "status": "open",
        "resolved_at": null
      }
    ]
  },
  "cpq": {
    "price_books": [
      {
        "id": "pb_standard_2026",
        "name": "Standard 2026 Commercial Price Book",
        "currency": "USD",
        "status": "active",
        "effective_from": "2026-01-01",
        "effective_to": "2026-12-31",
        "floor_margin_pct": 35,
        "default_payment_terms": "Net 15",
        "approval_bands": [
          {
            "name": "Seller auto-approve",
            "max_discount_pct": 10,
            "approver_role": "partner_seller"
          },
          {
            "name": "Manager review",
            "max_discount_pct": 20,
            "approver_role": "manager"
          },
          {
            "name": "Deal desk review",
            "max_discount_pct": 35,
            "approver_role": "finance_admin"
          },
          {
            "name": "Executive exception",
            "max_discount_pct": 100,
            "approver_role": "manager"
          }
        ],
        "canonical_id": "CAN-PRIC-STANDARD_2026"
      },
      {
        "id": "pb_growth_2026",
        "name": "Growth Partner Price Book",
        "currency": "USD",
        "status": "active",
        "effective_from": "2026-01-01",
        "effective_to": "2026-09-30",
        "floor_margin_pct": 30,
        "default_payment_terms": "Net 30",
        "approval_bands": [
          {
            "name": "Partner seller auto-approve",
            "max_discount_pct": 8,
            "approver_role": "partner_seller"
          },
          {
            "name": "Manager review",
            "max_discount_pct": 18,
            "approver_role": "manager"
          },
          {
            "name": "Finance exception",
            "max_discount_pct": 30,
            "approver_role": "finance_admin"
          },
          {
            "name": "Executive exception",
            "max_discount_pct": 100,
            "approver_role": "manager"
          }
        ],
        "canonical_id": "CAN-PRIC-GROWTH_2026"
      }
    ],
    "rules": [
      {
        "id": "rule_core_required",
        "name": "Core subscription required",
        "severity": "blocker",
        "description": "Every governed bundle must include NexaMarket Enterprise Core."
      },
      {
        "id": "rule_price_book_active",
        "name": "Active price book required",
        "severity": "blocker",
        "description": "Quotes must use an active price book within its effective window."
      },
      {
        "id": "rule_margin_floor",
        "name": "Margin floor review",
        "severity": "approval",
        "description": "Quotes below the active price-book margin floor require finance review."
      },
      {
        "id": "rule_services_once",
        "name": "Services quantity review",
        "severity": "warning",
        "description": "Enablement services above one unit should be reviewed for delivery capacity."
      }
    ],
    "quote_configs": [],
    "catalog_changes": [
      {
        "id": "catalog_change_b089a47cc9",
        "action": "new_product",
        "title": "Add product NexaMarket Workflow Automation Pack",
        "product_id": "prod_37d27276ac",
        "product_name": "NexaMarket Workflow Automation Pack",
        "status": "pending_approval",
        "risk": "medium",
        "reason": "Catalog governance update for next packaging phase.",
        "payload": {
          "product_id": "prod_37d27276ac",
          "sku": "NM-WORKFLOW-AUTO",
          "name": "NexaMarket Workflow Automation Pack",
          "family": "Add-On",
          "billing_period": "Annual",
          "list_price": 6200.0,
          "unit_cost": 2500.0,
          "max_auto_discount_pct": 10.0,
          "price_book_id": "pb_standard_2026",
          "effective_date": "2026-07-17",
          "active": true
        },
        "created_at": "2026-07-17T19:33:52",
        "approved_at": null,
        "applied_at": null,
        "approval_id": "approval_9bcdd9c074",
        "canonical_id": "CAN-CATA-CHANGE_B089A47CC9"
      }
    ],
    "validation_log": [],
    "summary": {
      "active_products": 3,
      "active_price_books": 2,
      "pending_catalog_changes": 1,
      "quote_configs": 0,
      "quotes_needing_review": 0,
      "average_margin_pct": 0.0
    }
  },
  "contract_ops": {
    "templates": [
      {
        "id": "tmpl_msa_order_form_2026",
        "name": "MSA + Order Form",
        "version": "2026.1",
        "status": "approved",
        "requires_legal_for_non_standard": true,
        "default_payment_terms": "Net 15",
        "governing_law": "Delaware",
        "clause_keys": [
          "limitation_of_liability",
          "data_processing",
          "payment_terms",
          "renewal_notice"
        ]
      },
      {
        "id": "tmpl_sow_services_2026",
        "name": "Services SOW",
        "version": "2026.1",
        "status": "approved",
        "requires_legal_for_non_standard": true,
        "default_payment_terms": "Net 15",
        "governing_law": "Delaware",
        "clause_keys": [
          "acceptance",
          "change_order",
          "delivery_dependencies"
        ]
      }
    ],
    "clause_library": [
      {
        "key": "limitation_of_liability",
        "title": "Limitation of Liability",
        "version": "3.0",
        "risk": "high",
        "status": "approved",
        "locked": true,
        "approval_required_for_change": true
      },
      {
        "key": "data_processing",
        "title": "Data Processing Addendum",
        "version": "2.2",
        "risk": "high",
        "status": "approved",
        "locked": true,
        "approval_required_for_change": true
      },
      {
        "key": "payment_terms",
        "title": "Payment Terms",
        "version": "1.7",
        "risk": "medium",
        "status": "approved",
        "locked": false,
        "approval_required_for_change": true
      },
      {
        "key": "renewal_notice",
        "title": "Renewal Notice",
        "version": "1.1",
        "risk": "medium",
        "status": "approved",
        "locked": false,
        "approval_required_for_change": false
      },
      {
        "key": "acceptance",
        "title": "Acceptance Criteria",
        "version": "1.4",
        "risk": "medium",
        "status": "approved",
        "locked": false,
        "approval_required_for_change": false
      },
      {
        "key": "change_order",
        "title": "Change Order Control",
        "version": "1.3",
        "risk": "medium",
        "status": "approved",
        "locked": false,
        "approval_required_for_change": true
      },
      {
        "key": "delivery_dependencies",
        "title": "Delivery Dependencies",
        "version": "1.2",
        "risk": "low",
        "status": "approved",
        "locked": false,
        "approval_required_for_change": false
      }
    ],
    "signature_matrix": [
      {
        "tier": "standard",
        "label": "Standard commercial packet",
        "max_amount": 25000,
        "authorized_titles": [
          "Chief Revenue Officer",
          "CRO",
          "VP Sales",
          "Vice President",
          "CEO",
          "Chief Executive Officer"
        ],
        "requires_legal": false
      },
      {
        "tier": "executive",
        "label": "Executive signature packet",
        "max_amount": 75000,
        "authorized_titles": [
          "Chief Revenue Officer",
          "CRO",
          "CEO",
          "Chief Executive Officer",
          "COO",
          "Chief Operating Officer",
          "General Counsel"
        ],
        "requires_legal": true
      },
      {
        "tier": "board",
        "label": "Board / owner exception packet",
        "max_amount": 999999999,
        "authorized_titles": [
          "CEO",
          "Chief Executive Officer",
          "General Counsel"
        ],
        "requires_legal": true
      }
    ],
    "redline_queue": [],
    "signature_packets": [],
    "authority_audit": [],
    "summary": {
      "pending_redlines": 0,
      "approved_clause_versions": 7,
      "signature_packets": 0,
      "signature_packets_ready": 0,
      "authority_exceptions": 0,
      "contracts_pending_signature": 0
    }
  },
  "provider_ops": {
    "connections": [
      {
        "id": "provider_email_google",
        "name": "Google Workspace Email",
        "provider": "Google Workspace",
        "kind": "email",
        "environment": "sandbox",
        "auth_mode": "oauth2",
        "credential_status": "configured_stub",
        "status": "connected",
        "scopes": [
          "mail.send",
          "mail.readonly"
        ],
        "webhooks_enabled": true,
        "last_test_at": null,
        "last_sync_at": null,
        "sync_cursor": null,
        "retry_queue": 0,
        "alerts": 0,
        "owner_system": "Outbound Hub",
        "credential_ref": "credential_053ec8149c",
        "canonical_id": "CAN-PROV-EMAIL_GOOGLE"
      },
      {
        "id": "provider_calendar_google",
        "name": "Google Calendar",
        "provider": "Google Workspace",
        "kind": "calendar",
        "environment": "sandbox",
        "auth_mode": "oauth2",
        "credential_status": "configured_stub",
        "status": "connected",
        "scopes": [
          "calendar.events"
        ],
        "webhooks_enabled": true,
        "last_test_at": "2026-07-09T20:40:12",
        "last_sync_at": "2026-07-09T20:40:15",
        "sync_cursor": "meeting:2026-07-09T20:40:15",
        "retry_queue": 0,
        "alerts": 0,
        "owner_system": "Calendar Hub",
        "credential_ref": "credential_16151d24d4",
        "canonical_id": "CAN-PROV-CALENDAR_GOOGLE",
        "last_error": ""
      },
      {
        "id": "provider_esign_stub",
        "name": "E-Sign Provider Stub",
        "provider": "DocuSign-compatible",
        "kind": "esign",
        "environment": "sandbox",
        "auth_mode": "api_key",
        "credential_status": "needs_rotation",
        "status": "attention",
        "scopes": [
          "envelopes.send",
          "envelopes.read"
        ],
        "webhooks_enabled": false,
        "last_test_at": null,
        "last_sync_at": null,
        "sync_cursor": null,
        "retry_queue": 1,
        "alerts": 1,
        "owner_system": "Contract Ops",
        "credential_ref": "credential_82ff488291",
        "canonical_id": "CAN-PROV-ESIGN_STUB"
      },
      {
        "id": "provider_finance_stub",
        "name": "Finance Rail Stub",
        "provider": "QuickBooks-compatible",
        "kind": "finance",
        "environment": "sandbox",
        "auth_mode": "oauth2",
        "credential_status": "configured_stub",
        "status": "connected",
        "scopes": [
          "invoices.write",
          "payments.read"
        ],
        "webhooks_enabled": true,
        "last_test_at": null,
        "last_sync_at": null,
        "sync_cursor": null,
        "retry_queue": 0,
        "alerts": 0,
        "owner_system": "Finance Rail",
        "credential_ref": "credential_d90de779fe",
        "canonical_id": "CAN-PROV-FINANCE_STUB"
      },
      {
        "id": "provider_crm_stub",
        "name": "NexaCRM Sync Endpoint",
        "provider": "NexaCRM",
        "kind": "crm",
        "environment": "sandbox",
        "auth_mode": "signed_webhook",
        "credential_status": "configured_stub",
        "status": "connected",
        "scopes": [
          "records.read",
          "records.write",
          "timeline.write"
        ],
        "webhooks_enabled": true,
        "last_test_at": null,
        "last_sync_at": null,
        "sync_cursor": null,
        "retry_queue": 0,
        "alerts": 0,
        "owner_system": "Platform Sync",
        "credential_ref": "credential_2e1cb68c2b",
        "canonical_id": "CAN-PROV-CRM_STUB"
      }
    ],
    "credential_vault": [
      {
        "id": "credential_2e1cb68c2b",
        "connection_id": "provider_crm_stub",
        "created_at": "2026-07-09T19:05:10",
        "rotation_count": 0,
        "connection_name": "NexaCRM Sync Endpoint",
        "auth_mode": "signed_webhook",
        "masked_secret": "\u2022\u2022\u2022\u2022stub",
        "status": "configured_stub",
        "rotated_at": "2026-07-09T19:05:10",
        "expires_at": "2026-10-07",
        "owner": "Avery Stone"
      },
      {
        "id": "credential_d90de779fe",
        "connection_id": "provider_finance_stub",
        "created_at": "2026-07-09T19:05:10",
        "rotation_count": 0,
        "connection_name": "Finance Rail Stub",
        "auth_mode": "oauth2",
        "masked_secret": "\u2022\u2022\u2022\u2022stub",
        "status": "configured_stub",
        "rotated_at": "2026-07-09T19:05:10",
        "expires_at": "2026-10-07",
        "owner": "Avery Stone"
      },
      {
        "id": "credential_82ff488291",
        "connection_id": "provider_esign_stub",
        "created_at": "2026-07-09T19:05:10",
        "rotation_count": 0,
        "connection_name": "E-Sign Provider Stub",
        "auth_mode": "api_key",
        "masked_secret": "\u2022\u2022\u2022\u2022stub",
        "status": "configured_stub",
        "rotated_at": "2026-07-09T19:05:10",
        "expires_at": "2026-10-07",
        "owner": "Avery Stone"
      },
      {
        "id": "credential_16151d24d4",
        "connection_id": "provider_calendar_google",
        "created_at": "2026-07-09T19:05:10",
        "rotation_count": 0,
        "connection_name": "Google Calendar",
        "auth_mode": "oauth2",
        "masked_secret": "\u2022\u2022\u2022\u2022stub",
        "status": "configured_stub",
        "rotated_at": "2026-07-09T19:05:10",
        "expires_at": "2026-10-07",
        "owner": "Avery Stone"
      },
      {
        "id": "credential_053ec8149c",
        "connection_id": "provider_email_google",
        "created_at": "2026-07-09T19:05:10",
        "rotation_count": 0,
        "connection_name": "Google Workspace Email",
        "auth_mode": "oauth2",
        "masked_secret": "\u2022\u2022\u2022\u2022stub",
        "status": "configured_stub",
        "rotated_at": "2026-07-09T19:05:10",
        "expires_at": "2026-10-07",
        "owner": "Avery Stone"
      }
    ],
    "field_mappings": [
      {
        "id": "map_contact_email",
        "object_type": "contact",
        "provider_kind": "email",
        "local_fields": [
          "name",
          "email",
          "consent.email"
        ],
        "provider_fields": [
          "displayName",
          "emailAddress",
          "subscriptionStatus"
        ],
        "status": "active"
      },
      {
        "id": "map_deal_crm",
        "object_type": "deal",
        "provider_kind": "crm",
        "local_fields": [
          "company_name",
          "stage",
          "amount",
          "next_step"
        ],
        "provider_fields": [
          "accountName",
          "stageName",
          "amount",
          "nextStep"
        ],
        "status": "active"
      },
      {
        "id": "map_invoice_finance",
        "object_type": "invoice",
        "provider_kind": "finance",
        "local_fields": [
          "company_name",
          "subtotal_amount",
          "tax_amount",
          "total_amount",
          "status"
        ],
        "provider_fields": [
          "customer",
          "lineTotal",
          "taxTotal",
          "balance",
          "paymentStatus"
        ],
        "status": "active"
      }
    ],
    "webhook_events": [],
    "sync_jobs": [
      {
        "id": "sync_job_86d831e132",
        "connection_id": "provider_calendar_google",
        "connection_name": "Google Calendar",
        "provider_kind": "calendar",
        "object_type": "meeting",
        "direction": "push",
        "mode": "manual",
        "records_seen": 0,
        "records_synced": 0,
        "status": "completed",
        "error": "",
        "started_at": "2026-07-09T20:40:15",
        "finished_at": "2026-07-09T20:40:15",
        "canonical_id": "CAN-PROV-JOB_86D831E132"
      }
    ],
    "dead_letter": [],
    "summary": {
      "connections": 5,
      "connected": 4,
      "attention": 1,
      "webhook_events": 0,
      "pending_webhooks": 0,
      "failed_sync_jobs": 0,
      "dead_letters": 0,
      "field_mappings": 3
    },
    "verified_webhooks": [],
    "verification_events": []
  },
  "commercial_ops": {
    "tax_profiles": [
      {
        "id": "tax_us_mi",
        "region": "US-MI",
        "label": "Michigan standard sales tax",
        "rate_pct": 6.0,
        "taxable_families": [
          "Subscription",
          "Add-On",
          "Services"
        ],
        "status": "active"
      },
      {
        "id": "tax_us_ca",
        "region": "US-CA",
        "label": "California digital services estimate",
        "rate_pct": 8.25,
        "taxable_families": [
          "Subscription",
          "Add-On"
        ],
        "status": "active"
      },
      {
        "id": "tax_us_ny",
        "region": "US-NY",
        "label": "New York digital services estimate",
        "rate_pct": 8.875,
        "taxable_families": [
          "Subscription",
          "Add-On"
        ],
        "status": "active"
      },
      {
        "id": "tax_exempt",
        "region": "EXEMPT",
        "label": "Tax exempt / certificate required",
        "rate_pct": 0.0,
        "taxable_families": [],
        "status": "active"
      }
    ],
    "currency_rates": [
      {
        "code": "USD",
        "label": "US Dollar",
        "rate_to_usd": 1.0,
        "status": "base"
      },
      {
        "code": "CAD",
        "label": "Canadian Dollar",
        "rate_to_usd": 0.73,
        "status": "simulated"
      },
      {
        "code": "EUR",
        "label": "Euro",
        "rate_to_usd": 1.08,
        "status": "simulated"
      },
      {
        "code": "GBP",
        "label": "Pound Sterling",
        "rate_to_usd": 1.25,
        "status": "simulated"
      }
    ],
    "payment_terms": [
      {
        "key": "due_on_receipt",
        "label": "Due on receipt",
        "days": 0,
        "requires_approval": false,
        "risk": "low"
      },
      {
        "key": "net_15",
        "label": "Net 15",
        "days": 15,
        "requires_approval": false,
        "risk": "low"
      },
      {
        "key": "net_30",
        "label": "Net 30",
        "days": 30,
        "requires_approval": false,
        "risk": "medium"
      },
      {
        "key": "net_45",
        "label": "Net 45",
        "days": 45,
        "requires_approval": true,
        "risk": "high"
      },
      {
        "key": "net_60",
        "label": "Net 60",
        "days": 60,
        "requires_approval": true,
        "risk": "high"
      }
    ],
    "assessments": [],
    "procurement_cases": [],
    "revenue_schedules": [],
    "customer_health": [],
    "renewal_plans": [],
    "summary": {
      "open_procurement_cases": 0,
      "ready_procurement_cases": 0,
      "revenue_schedules": 0,
      "deferred_revenue": 0,
      "recognized_revenue": 0,
      "at_risk_customers": 0,
      "renewals_due": 0,
      "commercial_assessments": 0
    }
  },
  "security_ops": {
    "identity_providers": [
      {
        "id": "idp_nexa_identity_oidc",
        "name": "Nexa Identity OIDC",
        "protocol": "oidc",
        "domain": "nexabuilder.local",
        "issuer": "https://identity.nexabuilder.local/oidc",
        "sso_status": "connected",
        "mfa_policy": "required",
        "scim_enabled": true,
        "scim_status": "synced",
        "certificate_expires_at": "2027-01-04",
        "last_test_at": null,
        "notes": "Local simulated identity provider for SSO/MFA/SCIM control-plane validation.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "status": "connected",
        "users_synced": 6,
        "mfa_gaps": 1,
        "certificate_status": "current",
        "canonical_id": "CAN-IDEN-NEXA_IDENTITY_OIDC"
      },
      {
        "id": "idp_customer_saml_stub",
        "name": "Customer SAML Stub",
        "protocol": "saml",
        "domain": "customer.example",
        "issuer": "https://idp.customer.example/saml",
        "sso_status": "simulated",
        "mfa_policy": "step_up_required",
        "scim_enabled": false,
        "scim_status": "not_configured",
        "certificate_expires_at": "2026-08-22",
        "last_test_at": null,
        "notes": "Placeholder for enterprise customer SAML metadata and cert-expiry review.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "status": "simulated",
        "users_synced": 6,
        "mfa_gaps": 1,
        "certificate_status": "expires_soon",
        "canonical_id": "CAN-IDEN-CUSTOMER_SAML_STUB"
      }
    ],
    "access_reviews": [],
    "credential_rotations": [],
    "scim_events": [],
    "mfa_challenges": [],
    "summary": {
      "identity_providers": 2,
      "connected_identity_providers": 2,
      "active_users": 6,
      "privileged_users": 4,
      "mfa_unverified_users": 1,
      "open_access_reviews": 0,
      "overdue_access_reviews": 0,
      "scim_events": 0,
      "credential_rotations": 0,
      "credential_rotations_due": 0
    }
  },
  "event_delivery": {
    "topics": [
      {
        "key": "all",
        "label": "All platform events",
        "description": "Catch-all subscription filter for every local event."
      },
      {
        "key": "crm.deal",
        "label": "Deal lifecycle",
        "description": "Lead, account, deal, quote, and pipeline updates."
      },
      {
        "key": "contract.signature",
        "label": "Contract + signature",
        "description": "Contracts, redlines, signature packets, and e-sign callbacks."
      },
      {
        "key": "finance.invoice",
        "label": "Invoice + revenue",
        "description": "Invoices, payments, procurement, revenue schedules, and renewals."
      },
      {
        "key": "provider.webhook",
        "label": "Provider webhooks",
        "description": "External provider callback and sync readiness events."
      },
      {
        "key": "security.identity",
        "label": "Security + identity",
        "description": "SSO, SCIM, MFA, access reviews, and credential rotation."
      },
      {
        "key": "retention.governance",
        "label": "Retention + audit",
        "description": "Retention runs, legal holds, backups, and audit exports."
      },
      {
        "key": "ops.release",
        "label": "Release + operations",
        "description": "Production-readiness gates, deployments, incidents, SLA monitor checks, and rollback planning."
      },
      {
        "key": "provider.certification",
        "label": "Provider certification",
        "description": "Provider readiness checks, certification runs, and go-live evidence packets."
      },
      {
        "key": "signature.envelope",
        "label": "E-sign envelope lifecycle",
        "description": "Envelope creation, callback intake, completion, decline, and contract-execution handoff."
      },
      {
        "key": "finance.settlement",
        "label": "Finance settlement rails",
        "description": "Tax calculations, settlement batches, seller payout batches, and reconciliation milestones."
      },
      {
        "key": "resilience.vault",
        "label": "Resilience and backup vault",
        "description": "Consumer-lag checks, immutable archive evidence, synthetic UAT, and recovery proof."
      },
      {
        "key": "tenant.provisioning",
        "label": "Tenant provisioning",
        "description": "Tenant creation, domain verification, residency binding, provisioning, and health-check evidence."
      },
      {
        "key": "trust.review",
        "label": "Trust and security review",
        "description": "Trust artifacts, questionnaires, DPA requests, evidence packets, and approval outcomes."
      },
      {
        "key": "ai.governance",
        "label": "AI governance",
        "description": "Model registry, prompt policy, evaluation, agent-action review, and risk acceptance events."
      },
      {
        "key": "customer.billing",
        "label": "Customer billing operations",
        "description": "Billing accounts, subscription records, payment terms, and credit requests."
      },
      {
        "key": "customer.entitlement",
        "label": "Customer entitlement control",
        "description": "Plan assignment, feature gates, seat limits, and provisioning state changes."
      },
      {
        "key": "customer.usage",
        "label": "Customer usage metering",
        "description": "Usage events, monthly rollups, limit alerts, and overage records."
      },
      {
        "key": "customer.success",
        "label": "Customer success and support",
        "description": "Support tickets, SLA outcomes, success plans, QBR packets, and renewal-ready evidence."
      },
      {
        "key": "subscription.billing",
        "label": "Subscription billing",
        "description": "Billing provider connections, subscription refs, invoice jobs, payment attempts, and subscription invoices."
      },
      {
        "key": "subscription.telemetry",
        "label": "Usage telemetry and entitlement enforcement",
        "description": "Raw usage ingestion, metered charges, plan-limit decisions, and feature entitlement checks."
      },
      {
        "key": "subscription.collections",
        "label": "Collections and dunning",
        "description": "Payment-failure handling, dunning-step progression, service-risk holds, and collection resolution."
      },
      {
        "key": "support.integration",
        "label": "Support desk integration",
        "description": "Support desk sync, external ticket references, SLA breach write-back, and credit memo handoff."
      },
      {
        "key": "partner.onboarding",
        "label": "Partner onboarding and certification",
        "description": "Partner profile creation, agreement evidence, certification status, and portal readiness."
      },
      {
        "key": "partner.marketplace",
        "label": "Marketplace listings",
        "description": "Marketplace listing governance, approved claims, publish evidence, and syndication status."
      },
      {
        "key": "partner.cosell",
        "label": "Partner deal registration and co-sell",
        "description": "Referral registration, account protection, conflicts, co-sell plans, and CRM handoff."
      },
      {
        "key": "partner.mdf",
        "label": "MDF requests and campaigns",
        "description": "Marketing development fund requests, approvals, campaign proof, and budget control."
      },
      {
        "key": "partner.payouts",
        "label": "Partner payout reconciliation",
        "description": "Partner payout statement generation, approval, payment simulation, and finance reconciliation."
      },
      {
        "key": "growth.audience",
        "label": "Audience segments",
        "description": "Consent-safe growth segments, target-account coverage, and suppression-aware audience membership."
      },
      {
        "key": "growth.campaign",
        "label": "Campaign orchestration",
        "description": "Governed campaign creation, approved-material readiness, launch simulation, and spend tracking."
      },
      {
        "key": "growth.attribution",
        "label": "Campaign attribution",
        "description": "Campaign-touch events, MQL creation, opportunity influence, revenue influence, and ROI evidence."
      },
      {
        "key": "growth.scoring",
        "label": "Lead scoring and routing",
        "description": "Lead scoring, sales-ready thresholding, owner assignment, and CRM write-back."
      },
      {
        "key": "growth.experiment",
        "label": "Experimentation",
        "description": "A/B tests, conversion results, guardrails, and winning variant decisions."
      },
      {
        "key": "intelligence.metrics",
        "label": "Revenue intelligence metrics",
        "description": "Snapshots, scorecards, KPI deltas, executive health, and cross-stack revenue signals."
      },
      {
        "key": "intelligence.anomaly",
        "label": "Anomaly alerts",
        "description": "Pipeline, growth, support, billing, provider, and sync anomalies that require review."
      },
      {
        "key": "intelligence.board",
        "label": "Board reporting",
        "description": "Board packets, decision requests, risk summaries, and evidence-pack readiness."
      },
      {
        "key": "intelligence.playbook",
        "label": "Revenue playbooks",
        "description": "Playbook templates, remediation runs, assigned owners, and alert closure evidence."
      },
      {
        "key": "analytics.warehouse",
        "label": "Analytics warehouse sync",
        "description": "Warehouse connection metadata, ELT runs, record counts, load evidence, and sync health."
      },
      {
        "key": "analytics.contracts",
        "label": "Analytics data contracts",
        "description": "Data-contract validation runs, required-field failures, freshness signals, and violation closure."
      },
      {
        "key": "analytics.metrics",
        "label": "Metric semantic layer",
        "description": "Governed KPI definitions, formulas, dimensions, owners, and lineage to executive snapshots."
      },
      {
        "key": "analytics.forecasts",
        "label": "Forecasting and model governance",
        "description": "Forecast models, backtests, forecast runs, confidence bands, and human-review status."
      },
      {
        "key": "analytics.dashboards",
        "label": "BI dashboard refreshes",
        "description": "Dashboard refresh jobs, publish status, subscribers, and evidence links."
      },
      {
        "key": "modelops.features",
        "label": "ModelOps feature governance",
        "description": "Feature-set definitions, source dependencies, data-contract bindings, and freshness posture."
      },
      {
        "key": "modelops.training",
        "label": "ModelOps training and evaluation",
        "description": "Training datasets, model evaluations, backtest evidence, retraining jobs, and quality gates."
      },
      {
        "key": "modelops.drift",
        "label": "ModelOps drift monitoring",
        "description": "Prediction, confidence, and data-quality drift checks with retraining recommendations."
      },
      {
        "key": "modelops.deployment",
        "label": "ModelOps deployment approval",
        "description": "Deployment approvals, champion/challenger changes, risk acceptance, and deployment records."
      },
      {
        "key": "modelops.lineage",
        "label": "ModelOps lineage graph",
        "description": "Lineage evidence from warehouse sources through data contracts, metrics, forecasts, and dashboards."
      },
      {
        "key": "agentops.policies",
        "label": "AgentOps policy governance",
        "description": "Policy, tool, data-scope, autonomy, and kill-switch changes."
      },
      {
        "key": "agentops.prompts",
        "label": "AgentOps prompt registry",
        "description": "Prompt versions, safety evaluations, and release approvals."
      },
      {
        "key": "agentops.tools",
        "label": "AgentOps tool authorization",
        "description": "Tool catalog changes, sandbox authorizations, and human-approval evidence."
      },
      {
        "key": "agentops.runs",
        "label": "AgentOps runtime traces",
        "description": "Workflow runs, dry-runs, executed actions, blocked actions, and trace evidence."
      },
      {
        "key": "agentops.guardrails",
        "label": "AgentOps guardrails",
        "description": "Guardrail incidents, resolutions, schedules, and runtime review items."
      },
      {
        "key": "observability.traces",
        "label": "Runtime trace sessions",
        "description": "Trace sessions, correlation IDs, replayable spans, and workflow evidence."
      },
      {
        "key": "observability.telemetry",
        "label": "Tool telemetry events",
        "description": "Tool calls, runtime metrics, severity signals, and escalation triggers."
      },
      {
        "key": "observability.incidents",
        "label": "Incident routing",
        "description": "Escalation routes, cases, on-call ownership, resolution, and evidence."
      },
      {
        "key": "observability.kill_switch",
        "label": "Kill-switch control",
        "description": "Scoped runtime, outreach, provider, billing, and finance kill-switch actions."
      },
      {
        "key": "observability.replay",
        "label": "Runtime replay lab",
        "description": "Replay jobs, deterministic reruns, mismatches, and replay evidence links."
      },
      {
        "key": "observability.slos",
        "label": "Service-level monitoring",
        "description": "SLO objectives, checks, breaches, and recovery evidence."
      },
      {
        "key": "runtime.worker_pools",
        "label": "Runtime worker pools",
        "description": "Worker pools, leases, active loads, and queue routing controls."
      },
      {
        "key": "runtime.jobs",
        "label": "Runtime jobs",
        "description": "Queued, leased, completed, failed, retried, and dead-lettered runtime jobs."
      },
      {
        "key": "runtime.tool_proxies",
        "label": "Tool proxy gateway",
        "description": "Scoped proxy registration, tool invocation evidence, and sandbox/policy decisions."
      },
      {
        "key": "runtime.deployments",
        "label": "Runtime deployments",
        "description": "Runtime deployment manifests, canary promotions, approvals, and rollback evidence."
      },
      {
        "key": "runtime.capacity",
        "label": "Runtime capacity checks",
        "description": "Capacity checks, autoscale recommendations, overload warnings, and readiness score changes."
      },
      {
        "key": "orchestration.agents",
        "label": "Orchestration agent registry",
        "description": "Agent skills, tool scopes, availability, and runtime handoff posture."
      },
      {
        "key": "orchestration.workflows",
        "label": "Durable workflow runs",
        "description": "Blueprints, run state, step cursors, runtime dispatch receipts, and completion evidence."
      },
      {
        "key": "orchestration.locks",
        "label": "State locks",
        "description": "Cross-agent object locks, lock conflicts, releases, and expiry posture."
      },
      {
        "key": "orchestration.handoffs",
        "label": "Agent handoffs",
        "description": "Context transfers, acceptances, due dates, and blocked ownership handoffs."
      },
      {
        "key": "orchestration.compensation",
        "label": "Saga compensation",
        "description": "Failed workflow compensation runs, rollback actions, retry evidence, and recovery decisions."
      }
    ],
    "subscriptions": [
      {
        "id": "sub_dd6819138c",
        "name": "Customer webhook replay target",
        "topic_filter": "all",
        "endpoint": "webhook://customer-success-target",
        "target_system": "webhook://customer-success-target",
        "delivery_mode": "signed_webhook",
        "status": "active",
        "signing_secret_status": "configured_stub",
        "deliveries": 7,
        "failures": 0,
        "last_delivery_at": "2026-07-17T19:33:52",
        "created_at": "2026-07-09T20:41:01",
        "updated_at": "2026-07-09T20:41:01",
        "canonical_id": "CAN-EVEN-DD6819138C"
      },
      {
        "id": "sub_nexacrm_all",
        "name": "NexaCRM canonical sync",
        "topic_filter": "all",
        "endpoint": "nexacrm://canonical-sync",
        "target_system": "NexaCRM",
        "delivery_mode": "signed_webhook",
        "status": "active",
        "signing_secret_status": "configured_stub",
        "deliveries": 12,
        "failures": 0,
        "last_delivery_at": "2026-07-17T19:33:52",
        "created_at": null,
        "updated_at": null,
        "canonical_id": "CAN-EVEN-NEXACRM_ALL"
      },
      {
        "id": "sub_finance_invoice",
        "name": "Finance invoice handoff",
        "topic_filter": "finance.invoice",
        "endpoint": "finance://invoice-ledger",
        "target_system": "Finance Rail",
        "delivery_mode": "signed_webhook",
        "status": "active",
        "signing_secret_status": "configured_stub",
        "deliveries": 0,
        "failures": 0,
        "last_delivery_at": null,
        "created_at": null,
        "updated_at": null,
        "canonical_id": "CAN-EVEN-FINANCE_INVOICE"
      },
      {
        "id": "sub_security_audit",
        "name": "Security audit ledger",
        "topic_filter": "security.identity",
        "endpoint": "audit://security-ledger",
        "target_system": "Security Ledger",
        "delivery_mode": "audit_append",
        "status": "active",
        "signing_secret_status": "configured_stub",
        "deliveries": 0,
        "failures": 0,
        "last_delivery_at": null,
        "created_at": null,
        "updated_at": null,
        "canonical_id": "CAN-EVEN-SECURITY_AUDIT"
      }
    ],
    "deliveries": [
      {
        "id": "delivery_2b704f5779",
        "event_id": "event_07edcc8a7a",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "all",
        "action": "queued",
        "object_type": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-17T19:33:52",
        "delivered_at": "2026-07-17T19:33:52",
        "error": ""
      },
      {
        "id": "delivery_2167be6f6f",
        "event_id": "event_07edcc8a7a",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "all",
        "action": "queued",
        "object_type": "catalog_change",
        "object_id": "catalog_change_b089a47cc9",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-17T19:33:52",
        "delivered_at": "2026-07-17T19:33:52",
        "error": ""
      },
      {
        "id": "delivery_100073cb48",
        "event_id": "event_c4a43a9170",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "all",
        "action": "approval_queued",
        "object_type": "catalog_change",
        "object_id": "approval_9bcdd9c074",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-17T19:33:52",
        "delivered_at": "2026-07-17T19:33:52",
        "error": ""
      },
      {
        "id": "delivery_12dc13742d",
        "event_id": "event_c4a43a9170",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "all",
        "action": "approval_queued",
        "object_type": "catalog_change",
        "object_id": "approval_9bcdd9c074",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-17T19:33:52",
        "delivered_at": "2026-07-17T19:33:52",
        "error": ""
      },
      {
        "id": "delivery_d07fd41e7e",
        "event_id": "event_b0137ca6e2",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "analytics.dashboards",
        "action": "published_simulated",
        "object_type": "analytics_dashboard_refresh",
        "object_id": "dashboard_refresh_ffc92770ea",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-12T01:35:50",
        "delivered_at": "2026-07-12T01:35:50",
        "error": ""
      },
      {
        "id": "delivery_8fe7a6ca08",
        "event_id": "event_b0137ca6e2",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "analytics.dashboards",
        "action": "published_simulated",
        "object_type": "analytics_dashboard_refresh",
        "object_id": "dashboard_refresh_ffc92770ea",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-12T01:35:50",
        "delivered_at": "2026-07-12T01:35:50",
        "error": ""
      },
      {
        "id": "delivery_a7170e87f2",
        "event_id": "event_e81ba36608",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "intelligence.metrics",
        "action": "created",
        "object_type": "intelligence_metric_snapshot",
        "object_id": "snapshot_749adf2d44",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-12T01:35:50",
        "delivered_at": "2026-07-12T01:35:50",
        "error": ""
      },
      {
        "id": "delivery_2ff9df94c4",
        "event_id": "event_e81ba36608",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "intelligence.metrics",
        "action": "created",
        "object_type": "intelligence_metric_snapshot",
        "object_id": "snapshot_749adf2d44",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-12T01:35:50",
        "delivered_at": "2026-07-12T01:35:50",
        "error": ""
      },
      {
        "id": "delivery_a80debd77d",
        "event_id": "event_80737020e1",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "all",
        "action": "resolved",
        "object_type": "sync_conflict",
        "object_id": "conflict_provider_provider_esign_stub",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-12T01:22:17",
        "delivered_at": "2026-07-12T01:22:17",
        "error": ""
      },
      {
        "id": "delivery_8d424ca146",
        "event_id": "event_80737020e1",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "all",
        "action": "resolved",
        "object_type": "sync_conflict",
        "object_id": "conflict_provider_provider_esign_stub",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-12T01:22:17",
        "delivered_at": "2026-07-12T01:22:17",
        "error": ""
      },
      {
        "id": "delivery_b46cb42118",
        "event_id": "event_8dcd406944",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "all",
        "action": "resolved",
        "object_type": "sync_conflict",
        "object_id": "conflict_modelops_no_training_dataset",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:45:01",
        "delivered_at": "2026-07-09T20:45:01",
        "error": ""
      },
      {
        "id": "delivery_6e8dc5381f",
        "event_id": "event_8dcd406944",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "all",
        "action": "resolved",
        "object_type": "sync_conflict",
        "object_id": "conflict_modelops_no_training_dataset",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:45:01",
        "delivered_at": "2026-07-09T20:45:01",
        "error": ""
      },
      {
        "id": "delivery_8da748c3e6",
        "event_id": "event_ab9f79566f",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "all",
        "action": "created",
        "object_type": "event_subscription",
        "object_id": "sub_dd6819138c",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:41:01",
        "delivered_at": "2026-07-09T20:41:01",
        "error": ""
      },
      {
        "id": "delivery_bbb48ac852",
        "event_id": "event_ab9f79566f",
        "subscription_id": "sub_dd6819138c",
        "subscription_name": "Customer webhook replay target",
        "topic": "all",
        "action": "created",
        "object_type": "event_subscription",
        "object_id": "sub_dd6819138c",
        "endpoint": "webhook://customer-success-target",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:41:01",
        "delivered_at": "2026-07-09T20:41:01",
        "error": ""
      },
      {
        "id": "delivery_1c212a1508",
        "event_id": "event_153a5bac3f",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "provider.webhook",
        "action": "completed",
        "object_type": "sync_job",
        "object_id": "sync_job_86d831e132",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:40:15",
        "delivered_at": "2026-07-09T20:40:15",
        "error": ""
      },
      {
        "id": "delivery_2a2cdb2b9c",
        "event_id": "event_524d5bc869",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "provider.webhook",
        "action": "test_passed",
        "object_type": "provider_connection",
        "object_id": "provider_calendar_google",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:40:12",
        "delivered_at": "2026-07-09T20:40:12",
        "error": ""
      },
      {
        "id": "delivery_e034a9afd2",
        "event_id": "event_05e81d3652",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "crm.deal",
        "action": "forecast_updated",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:39:02",
        "delivered_at": "2026-07-09T20:39:02",
        "error": ""
      },
      {
        "id": "delivery_0f6dfa94f9",
        "event_id": "event_050aec77e2",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "crm.deal",
        "action": "forecast_updated",
        "object_type": "deal",
        "object_id": "placeholder_deal_source_control_seed",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:39:00",
        "delivered_at": "2026-07-09T20:39:00",
        "error": ""
      },
      {
        "id": "delivery_5e7574a2fd",
        "event_id": "event_a30bf15457",
        "subscription_id": "sub_nexacrm_all",
        "subscription_name": "NexaCRM canonical sync",
        "topic": "all",
        "action": "no_match",
        "object_type": "task",
        "object_id": "task_521be1cd49",
        "endpoint": "nexacrm://canonical-sync",
        "status": "delivered_simulated",
        "attempt": 1,
        "created_at": "2026-07-09T20:38:35",
        "delivered_at": "2026-07-09T20:38:35",
        "error": ""
      }
    ],
    "replay_jobs": [],
    "dead_letter": [],
    "summary": {
      "topics": 68,
      "subscriptions": 4,
      "active_subscriptions": 4,
      "deliveries": 19,
      "failed_deliveries": 0,
      "replay_jobs": 0
    }
  },
  "retention_ops": {
    "policies": [
      {
        "id": "ret_audit_center",
        "name": "Audit-center retention",
        "target": "audit_center",
        "retention_days": 2555,
        "action": "archive",
        "status": "active",
        "legal_hold_exempt": true,
        "description": "Keep approval, activity, and audit records for seven years before archive review.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10"
      },
      {
        "id": "ret_event_bus",
        "name": "Event-bus delivery retention",
        "target": "event_bus",
        "retention_days": 730,
        "action": "archive",
        "status": "active",
        "legal_hold_exempt": true,
        "description": "Retain delivery/replay metadata for two years before archive review.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10"
      },
      {
        "id": "ret_provider_webhooks",
        "name": "Provider webhook retention",
        "target": "provider_webhooks",
        "retention_days": 1095,
        "action": "archive",
        "status": "active",
        "legal_hold_exempt": true,
        "description": "Retain simulated provider callbacks for three years.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10"
      },
      {
        "id": "ret_privacy_requests",
        "name": "Privacy request retention",
        "target": "privacy_requests",
        "retention_days": 2555,
        "action": "retain",
        "status": "active",
        "legal_hold_exempt": true,
        "description": "Privacy request logs are retained for compliance review.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10"
      }
    ],
    "legal_holds": [],
    "retention_runs": [],
    "backup_snapshots": [],
    "summary": {
      "policies": 4,
      "active_policies": 4,
      "legal_holds": 0,
      "retention_runs": 0,
      "backup_snapshots": 0,
      "last_sweep_at": null,
      "last_backup_at": null,
      "recovery_drills": 0
    },
    "recovery_drills": []
  },
  "release_ops": {
    "environments": [
      {
        "id": "env_sandbox",
        "name": "Sandbox",
        "tier": "sandbox",
        "status": "active",
        "current_version": "3.2.0",
        "last_promoted_at": null,
        "readiness_status": "attention",
        "change_window": "Anytime",
        "rollback_version": "3.0.0",
        "owner": "RevOps",
        "notes": "Safe test environment for simulated connector, workflow, and data-quality checks.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ENVI-SANDBOX"
      },
      {
        "id": "env_staging",
        "name": "Staging",
        "tier": "staging",
        "status": "active",
        "current_version": "3.2.0",
        "last_promoted_at": null,
        "readiness_status": "attention",
        "change_window": "Business-hours approval",
        "rollback_version": "3.0.0",
        "owner": "Revenue Engineering",
        "notes": "Pre-production validation layer for release gates and provider readiness.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ENVI-STAGING"
      },
      {
        "id": "env_production",
        "name": "Production",
        "tier": "production",
        "status": "gated",
        "current_version": "3.2.0",
        "last_promoted_at": null,
        "readiness_status": "blocked",
        "change_window": "Approved maintenance window",
        "rollback_version": "3.0.0",
        "owner": "Operations",
        "notes": "Production remains gated until release, security, event, provider, backup, and incident gates pass.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ENVI-PRODUCTION"
      }
    ],
    "release_gates": [
      {
        "key": "data_quality_clean",
        "label": "Data quality scan clean",
        "description": "No high-severity open data-quality issue blocks promotion.",
        "required": true
      },
      {
        "key": "provider_gateway_ready",
        "label": "Provider gateway ready",
        "description": "No connector is in an alert or rotation-required state.",
        "required": true
      },
      {
        "key": "security_review_clean",
        "label": "Security review clean",
        "description": "No open access review, overdue review, or active MFA gap blocks launch.",
        "required": true
      },
      {
        "key": "event_delivery_clean",
        "label": "Event delivery clean",
        "description": "No failed event delivery remains unreplayed.",
        "required": true
      },
      {
        "key": "backup_snapshot_current",
        "label": "Backup snapshot current",
        "description": "At least one completed backup snapshot exists before deployment.",
        "required": true
      },
      {
        "key": "incident_free",
        "label": "No open critical incident",
        "description": "No Sev1/Sev2 incident is open for the release scope.",
        "required": true
      }
    ],
    "release_plans": [],
    "deployments": [],
    "data_quality_scans": [],
    "quality_issues": [],
    "incidents": [],
    "sla_monitors": [
      {
        "id": "sla_provider_delivery",
        "name": "Provider event delivery",
        "service": "Event Delivery",
        "target": "99.0% successful delivery",
        "status": "healthy",
        "threshold": 1,
        "metric_key": "failed_event_deliveries",
        "owner": "Platform Ops",
        "last_checked_at": null,
        "last_result": "0 exception(s) measured against threshold 1.",
        "canonical_id": "CAN-SLA_-PROVIDER_DELIVERY"
      },
      {
        "id": "sla_identity_access",
        "name": "Identity and access posture",
        "service": "Security Admin",
        "target": "0 unverified MFA users in privileged launch scope",
        "status": "breach",
        "threshold": 0,
        "metric_key": "mfa_gaps",
        "owner": "Security",
        "last_checked_at": null,
        "last_result": "1 exception(s) measured against threshold 0.",
        "canonical_id": "CAN-SLA_-IDENTITY_ACCESS"
      },
      {
        "id": "sla_finance_reconciliation",
        "name": "Finance reconciliation queue",
        "service": "Revenue Ops",
        "target": "No failed sync job or stale open payment queue",
        "status": "healthy",
        "threshold": 0,
        "metric_key": "finance_exceptions",
        "owner": "Finance Ops",
        "last_checked_at": null,
        "last_result": "0 exception(s) measured against threshold 0.",
        "canonical_id": "CAN-SLA_-FINANCE_RECONCILIATION"
      },
      {
        "id": "sla_backup_coverage",
        "name": "Backup coverage",
        "service": "Retention + Backup",
        "target": "At least one completed snapshot before promotion",
        "status": "breach",
        "threshold": 1,
        "metric_key": "backup_snapshots",
        "owner": "Operations",
        "last_checked_at": null,
        "last_result": "0 completed snapshot(s) available.",
        "canonical_id": "CAN-SLA_-BACKUP_COVERAGE"
      }
    ],
    "monitor_runs": [],
    "runbooks": [
      {
        "id": "runbook_provider_webhook_failure",
        "title": "Provider webhook failure response",
        "trigger": "Failed event delivery or provider webhook dead-letter",
        "owner": "Platform Ops",
        "severity": "sev2",
        "steps": [
          "Pause affected subscription if retry storm is active.",
          "Replay failed delivery from Event Replay after credential and endpoint validation.",
          "Attach provider payload and event id to the incident record.",
          "Run release gate check before resuming promotion."
        ],
        "last_reviewed_at": null,
        "status": "active"
      },
      {
        "id": "runbook_finance_reconciliation",
        "title": "Finance reconciliation exception",
        "trigger": "Invoice, payment, or revenue-schedule mismatch",
        "owner": "Finance Ops",
        "severity": "sev3",
        "steps": [
          "Export RevOps and finance CSV snapshots.",
          "Compare invoice status, payment reference, revenue schedule, and seller attribution.",
          "Open procurement or revenue-ops case for mismatched terms.",
          "Resolve schedule period or payment status before deployment."
        ],
        "last_reviewed_at": null,
        "status": "active"
      },
      {
        "id": "runbook_release_rollback",
        "title": "Release rollback checklist",
        "trigger": "Failed production promotion or high-severity launch incident",
        "owner": "Operations",
        "severity": "sev1",
        "steps": [
          "Freeze new outbound, contract, and sync executions.",
          "Capture backup snapshot and audit export.",
          "Restore prior environment version reference and reopen release gates.",
          "Complete incident root cause and executive communication note."
        ],
        "last_reviewed_at": null,
        "status": "active"
      }
    ],
    "summary": {
      "environments": 3,
      "release_plans": 0,
      "open_release_plans": 0,
      "blocked_releases": 0,
      "ready_releases": 0,
      "deployments": 0,
      "quality_scans": 0,
      "open_quality_issues": 0,
      "high_quality_issues": 0,
      "open_incidents": 0,
      "critical_incidents": 0,
      "sla_breaches": 2,
      "runbooks": 3,
      "last_deployment_at": null,
      "production_ready": false
    }
  },
  "launch_ops": {
    "feature_flags": [
      {
        "key": "provider_live_mode",
        "label": "Provider live mode",
        "status": "off",
        "target_environment": "production",
        "risk": "high",
        "description": "Switches simulated provider gateway flows toward provider-backed live execution readiness.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "history": []
      },
      {
        "key": "strict_webhook_signatures",
        "label": "Strict webhook signatures",
        "status": "shadow",
        "target_environment": "production",
        "risk": "high",
        "description": "Requires signed webhook payloads and idempotency checks before processing callbacks.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "history": []
      },
      {
        "key": "nexacrm_source_of_truth",
        "label": "NexaCRM source of truth",
        "status": "limited",
        "target_environment": "staging",
        "risk": "high",
        "description": "Promotes NexaCRM bridge from mirror mode toward canonical system-of-record ownership.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "history": []
      },
      {
        "key": "finance_settlement_rails",
        "label": "Finance settlement rails",
        "status": "off",
        "target_environment": "production",
        "risk": "high",
        "description": "Controls finance-rail settlement readiness for invoice and payout workflows.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "history": []
      }
    ],
    "cutover_runs": [],
    "summary": {
      "feature_flags": 4,
      "live_flags": 0,
      "limited_flags": 2,
      "cutover_runs": 0,
      "blocked_cutovers": 0,
      "ready_cutovers": 0,
      "webhook_verifications": 0,
      "readiness_score": 25,
      "blocked_gates": 0,
      "warning_gates": 6,
      "release_blockers": 3
    },
    "release_gates": [
      {
        "key": "data_quality_clean",
        "name": "Data quality scan clean",
        "status": "not_started",
        "owner": "Operations",
        "evidence": "No high-severity open data-quality issue blocks promotion.",
        "required": true
      },
      {
        "key": "provider_gateway_ready",
        "name": "Provider gateway ready",
        "status": "not_started",
        "owner": "Operations",
        "evidence": "No connector is in an alert or rotation-required state.",
        "required": true
      },
      {
        "key": "security_review_clean",
        "name": "Security review clean",
        "status": "not_started",
        "owner": "Operations",
        "evidence": "No open access review, overdue review, or active MFA gap blocks launch.",
        "required": true
      },
      {
        "key": "event_delivery_clean",
        "name": "Event delivery clean",
        "status": "not_started",
        "owner": "Operations",
        "evidence": "No failed event delivery remains unreplayed.",
        "required": true
      },
      {
        "key": "backup_snapshot_current",
        "name": "Backup snapshot current",
        "status": "not_started",
        "owner": "Operations",
        "evidence": "At least one completed backup snapshot exists before deployment.",
        "required": true
      },
      {
        "key": "incident_free",
        "name": "No open critical incident",
        "status": "not_started",
        "owner": "Operations",
        "evidence": "No Sev1/Sev2 incident is open for the release scope.",
        "required": true
      }
    ],
    "environments": [
      {
        "id": "env_sandbox",
        "name": "Sandbox",
        "tier": "sandbox",
        "status": "active",
        "current_version": "3.2.0",
        "last_promoted_at": null,
        "readiness_status": "attention",
        "change_window": "Anytime",
        "rollback_version": "3.0.0",
        "owner": "RevOps",
        "notes": "Safe test environment for simulated connector, workflow, and data-quality checks.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ENVI-SANDBOX",
        "kind": "sandbox",
        "base_url": "https://sandbox.nexamarket.local",
        "data_residency": "US",
        "deployment_status": "active",
        "readiness_score": 75
      },
      {
        "id": "env_staging",
        "name": "Staging",
        "tier": "staging",
        "status": "active",
        "current_version": "3.2.0",
        "last_promoted_at": null,
        "readiness_status": "attention",
        "change_window": "Business-hours approval",
        "rollback_version": "3.0.0",
        "owner": "Revenue Engineering",
        "notes": "Pre-production validation layer for release gates and provider readiness.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ENVI-STAGING",
        "kind": "staging",
        "base_url": "https://staging.nexamarket.local",
        "data_residency": "US",
        "deployment_status": "active",
        "readiness_score": 75
      },
      {
        "id": "env_production",
        "name": "Production",
        "tier": "production",
        "status": "gated",
        "current_version": "3.2.0",
        "last_promoted_at": null,
        "readiness_status": "blocked",
        "change_window": "Approved maintenance window",
        "rollback_version": "3.0.0",
        "owner": "Operations",
        "notes": "Production remains gated until release, security, event, provider, backup, and incident gates pass.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ENVI-PRODUCTION",
        "kind": "production",
        "base_url": "https://production.nexamarket.local",
        "data_residency": "US",
        "deployment_status": "gated",
        "readiness_score": 25
      }
    ]
  },
  "crm_bridge": {
    "profiles": [
      {
        "id": "crm_profile_nexacrm_stub",
        "name": "NexaCRM production bridge stub",
        "provider": "NexaCRM",
        "mode": "mirror",
        "status": "simulated",
        "system_of_record": false,
        "objects": [
          "accounts",
          "contacts",
          "deals",
          "quotes",
          "contracts",
          "invoices"
        ],
        "last_validated_at": null,
        "last_promoted_at": null,
        "notes": "Local bridge profile for validating source-of-truth migration before a live NexaCRM deployment.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "owner_system": "NexaCRM"
      }
    ],
    "migration_batches": [],
    "validation_runs": [],
    "promotion_state": {},
    "summary": {
      "profiles": 1,
      "migration_batches": 0,
      "validated_batches": 0,
      "system_of_record_profiles": 0,
      "last_promotion_at": null,
      "object_count": 139,
      "open_conflicts": 9,
      "critical_conflicts": 0,
      "source_of_truth_status": "local"
    }
  },
  "go_live_ops": {
    "certification_templates": [
      {
        "key": "credential_valid",
        "label": "Credential configured and not expired",
        "required": true
      },
      {
        "key": "connection_healthy",
        "label": "Connection test or sync is healthy",
        "required": true
      },
      {
        "key": "field_mapping_active",
        "label": "Field mapping active for provider kind",
        "required": true
      },
      {
        "key": "webhook_ready",
        "label": "Webhook verified when enabled",
        "required": true
      },
      {
        "key": "runbook_reviewed",
        "label": "Related runbook reviewed",
        "required": false
      },
      {
        "key": "backup_evidence",
        "label": "Backup or vault evidence exists",
        "required": true
      }
    ],
    "provider_certifications": [],
    "uat_scenarios": [
      {
        "id": "uat_lead_to_cash",
        "name": "Lead-to-cash governed path",
        "description": "Confirms that CRM, quote, contract, invoice, revenue schedule, and settlement evidence can be chained.",
        "required_objects": [
          "deals",
          "quotes",
          "contracts",
          "invoices"
        ],
        "created_at": "2026-07-09T19:05:10",
        "status": "active"
      },
      {
        "id": "uat_provider_callback",
        "name": "Provider callback safety",
        "description": "Confirms verified webhook, idempotency, and callback tracking records exist before live-mode promotion.",
        "required_objects": [
          "verified_webhooks",
          "provider_certifications"
        ],
        "created_at": "2026-07-09T19:05:10",
        "status": "active"
      },
      {
        "id": "uat_finance_reconcile",
        "name": "Finance reconciliation path",
        "description": "Confirms tax, settlement, payout, and RevOps export evidence is present for finance go-live.",
        "required_objects": [
          "tax_calculations",
          "settlement_batches"
        ],
        "created_at": "2026-07-09T19:05:10",
        "status": "active"
      },
      {
        "id": "uat_resilience_restore",
        "name": "Resilience and restore path",
        "description": "Confirms backup snapshot, vault archive, recovery drill, and event-bus health evidence exist.",
        "required_objects": [
          "backup_snapshots",
          "vault_archives",
          "consumer_checks"
        ],
        "created_at": "2026-07-09T19:05:10",
        "status": "active"
      }
    ],
    "uat_runs": [],
    "summary": {
      "provider_certifications": 0,
      "certified_providers": 0,
      "blocked_certifications": 0,
      "uat_scenarios": 4,
      "uat_runs": 0,
      "passed_uat_runs": 0,
      "failed_uat_runs": 0,
      "ready_for_live_provider_mode": false,
      "latest_readiness_score": 0
    }
  },
  "signature_provider_ops": {
    "envelopes": [],
    "callback_events": [],
    "summary": {
      "envelopes": 0,
      "sent": 0,
      "completed": 0,
      "declined": 0,
      "callbacks": 0
    }
  },
  "settlement_ops": {
    "rails": [
      {
        "id": "rail_ach_us",
        "name": "US ACH rail",
        "rail_type": "ach",
        "currency": "USD",
        "fee_pct": 0.8,
        "flat_fee": 0.25,
        "settlement_days": 2,
        "status": "simulated_ready"
      },
      {
        "id": "rail_card_us",
        "name": "US card rail",
        "rail_type": "card",
        "currency": "USD",
        "fee_pct": 2.9,
        "flat_fee": 0.3,
        "settlement_days": 1,
        "status": "simulated_ready"
      },
      {
        "id": "rail_wire_us",
        "name": "US wire rail",
        "rail_type": "wire",
        "currency": "USD",
        "fee_pct": 0.2,
        "flat_fee": 10.0,
        "settlement_days": 0,
        "status": "requires_approval"
      }
    ],
    "tax_calculations": [],
    "settlement_batches": [],
    "payout_batches": [],
    "summary": {
      "rails": 3,
      "tax_calculations": 0,
      "settlement_batches": 0,
      "open_settlement_batches": 0,
      "settled_batches": 0,
      "payout_batches": 0,
      "paid_payout_batches": 0,
      "gross_settlement": 0,
      "net_settlement": 0
    }
  },
  "resilience_ops": {
    "event_bus_consumers": [
      {
        "id": "consumer_nexacrm",
        "name": "NexaCRM projection consumer",
        "topic_filter": "crm.*",
        "owner": "Platform Sync",
        "max_lag_events": 5,
        "status": "not_checked",
        "created_at": "2026-07-09T19:05:10",
        "last_lag_events": 0
      },
      {
        "id": "consumer_finance",
        "name": "Finance ledger consumer",
        "topic_filter": "finance.*",
        "owner": "Finance Ops",
        "max_lag_events": 3,
        "status": "not_checked",
        "created_at": "2026-07-09T19:05:10",
        "last_lag_events": 0
      },
      {
        "id": "consumer_signature",
        "name": "Contract signature consumer",
        "topic_filter": "signature.*",
        "owner": "Legal Ops",
        "max_lag_events": 3,
        "status": "not_checked",
        "created_at": "2026-07-09T19:05:10",
        "last_lag_events": 0
      },
      {
        "id": "consumer_audit",
        "name": "Audit evidence consumer",
        "topic_filter": "*",
        "owner": "Operations",
        "max_lag_events": 10,
        "status": "not_checked",
        "created_at": "2026-07-09T19:05:10",
        "last_lag_events": 0
      }
    ],
    "consumer_checks": [],
    "vault_archives": [],
    "summary": {
      "event_bus_consumers": 4,
      "consumer_checks": 0,
      "latest_consumer_status": "not_checked",
      "vault_archives": 0,
      "verified_archives": 0,
      "unverified_archives": 0
    }
  },
  "tenant_ops": {
    "tenants": [],
    "domain_claims": [],
    "tenant_environments": [],
    "provisioning_runs": [],
    "tenant_health_checks": [],
    "data_residency_policies": [
      {
        "id": "residency_us_commercial",
        "name": "US commercial default",
        "region": "US",
        "allowed_environments": [
          "sandbox",
          "staging",
          "production"
        ],
        "data_classes": [
          "crm",
          "contract_metadata",
          "audit_metadata",
          "usage_metadata"
        ],
        "retention_profile": "standard_7_year",
        "encryption_profile": "nexa_standard_kms",
        "status": "active"
      },
      {
        "id": "residency_eu_restricted",
        "name": "EU restricted buyer workspace",
        "region": "EU",
        "allowed_environments": [
          "staging",
          "production"
        ],
        "data_classes": [
          "crm",
          "contract_metadata",
          "audit_metadata"
        ],
        "retention_profile": "eu_customer_controlled",
        "encryption_profile": "eu_region_kms",
        "status": "active"
      },
      {
        "id": "residency_global_redacted_pilot",
        "name": "Global pilot with redaction",
        "region": "Global",
        "allowed_environments": [
          "sandbox",
          "staging"
        ],
        "data_classes": [
          "crm",
          "usage_metadata"
        ],
        "retention_profile": "pilot_180_day",
        "encryption_profile": "redacted_shared_kms",
        "status": "active"
      }
    ],
    "environment_templates": [
      {
        "key": "sandbox",
        "label": "Sandbox",
        "status": "available",
        "isolated": true
      },
      {
        "key": "staging",
        "label": "Staging",
        "status": "available",
        "isolated": true
      },
      {
        "key": "production",
        "label": "Production",
        "status": "requires_provisioning",
        "isolated": true
      }
    ],
    "summary": {
      "tenants": 0,
      "active_tenants": 0,
      "verified_domains": 0,
      "unverified_domains": 0,
      "provisioning_runs": 0,
      "blocked_provisioning_runs": 0,
      "health_checks": 0,
      "latest_health_status": "not_checked"
    }
  },
  "trust_center_ops": {
    "artifacts": [
      {
        "id": "trust_soc2_placeholder",
        "title": "SOC 2 readiness summary",
        "category": "security",
        "version": "2026.04",
        "classification": "restricted",
        "nda_required": true,
        "status": "published",
        "description": "Internal readiness summary and control mapping for enterprise buyer security teams.",
        "coverage_tags": [
          "soc2",
          "controls",
          "audit"
        ],
        "expires_on": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-TRUS-SOC2_PLACEHOLDER"
      },
      {
        "id": "trust_dpa_template",
        "title": "DPA template",
        "category": "privacy",
        "version": "2026.04",
        "classification": "controlled",
        "nda_required": false,
        "status": "published",
        "description": "Template data processing addendum for buyer legal review.",
        "coverage_tags": [
          "dpa",
          "privacy",
          "processing"
        ],
        "expires_on": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-TRUS-DPA_TEMPLATE"
      },
      {
        "id": "trust_security_whitepaper",
        "title": "Security architecture whitepaper",
        "category": "security",
        "version": "2026.04",
        "classification": "controlled",
        "nda_required": false,
        "status": "published",
        "description": "High-level security architecture, encryption, access control, and audit posture.",
        "coverage_tags": [
          "security",
          "encryption",
          "mfa",
          "backup"
        ],
        "expires_on": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-TRUS-SECURITY_WHITEPAPER"
      },
      {
        "id": "trust_subprocessor_inventory",
        "title": "Subprocessor inventory",
        "category": "privacy",
        "version": "2026.04",
        "classification": "public_controlled",
        "nda_required": false,
        "status": "published",
        "description": "Maintained inventory of simulated provider and platform subprocessors.",
        "coverage_tags": [
          "subprocessors",
          "privacy",
          "vendor"
        ],
        "expires_on": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-TRUS-SUBPROCESSOR_INVENTORY"
      },
      {
        "id": "trust_ai_governance_statement",
        "title": "AI governance statement",
        "category": "ai_governance",
        "version": "2026.04",
        "classification": "controlled",
        "nda_required": false,
        "status": "published",
        "description": "Human-review, redaction, evaluation, and risk-acceptance overview for governed agent actions.",
        "coverage_tags": [
          "ai",
          "human_review",
          "redaction",
          "risk"
        ],
        "expires_on": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-TRUS-AI_GOVERNANCE_STATEMENT"
      }
    ],
    "questionnaire_requests": [],
    "dpa_requests": [],
    "evidence_packets": [],
    "security_review_cases": [],
    "summary": {
      "artifacts": 5,
      "published_artifacts": 5,
      "restricted_artifacts": 1,
      "expiring_artifacts": 0,
      "questionnaires": 0,
      "open_questionnaires": 0,
      "dpa_requests": 0,
      "open_dpa_requests": 0,
      "evidence_packets": 0,
      "open_security_reviews": 0
    }
  },
  "ai_governance_ops": {
    "model_registry": [
      {
        "id": "model_nexa_orchestrator_local",
        "name": "Nexa Orchestrator Local Policy Agent",
        "provider": "NexaBuilderAI",
        "model_family": "local_policy",
        "use_case": "Internal workflow orchestration and policy checks",
        "risk_tier": "medium",
        "status": "approved_for_demo",
        "human_review_required": true,
        "data_classes_allowed": [
          "crm",
          "contract_metadata",
          "audit_metadata"
        ],
        "last_evaluated_at": null,
        "notes": "Simulated registry entry for the embedded workflow agent.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-AI_M-NEXA_ORCHESTRATOR_LOCAL"
      },
      {
        "id": "model_outbound_compliance_guard",
        "name": "Outbound Compliance Guard",
        "provider": "NexaMarket",
        "model_family": "rules_plus_llm",
        "use_case": "Consent, approved-material, and sensitive-claim review before outreach",
        "risk_tier": "medium",
        "status": "approved_for_demo",
        "human_review_required": true,
        "data_classes_allowed": [
          "crm",
          "approved_materials",
          "audit_metadata"
        ],
        "last_evaluated_at": null,
        "notes": "Simulated compliance model for governed outbound execution.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-AI_M-OUTBOUND_COMPLIANCE_GUARD"
      }
    ],
    "prompt_policies": [
      {
        "id": "prompt_policy_no_secrets",
        "title": "No secrets or credential disclosure",
        "status": "active",
        "severity": "critical",
        "description": "Blocks prompts and agent actions from exposing tokens, credentials, or vault references."
      },
      {
        "id": "prompt_policy_redact_sensitive_buyer_data",
        "title": "Redact sensitive buyer data",
        "status": "active",
        "severity": "high",
        "description": "Requires redaction before AI evaluation when restricted buyer, finance, or privacy data is included."
      },
      {
        "id": "prompt_policy_human_review_external_actions",
        "title": "Human review for high-risk external actions",
        "status": "active",
        "severity": "high",
        "description": "Routes sensitive or high-risk external agent actions to approval before release."
      }
    ],
    "evaluation_runs": [],
    "agent_action_reviews": [],
    "risk_acceptances": [],
    "summary": {
      "models": 2,
      "approved_models": 2,
      "high_risk_models": 0,
      "active_prompt_policies": 3,
      "evaluation_runs": 0,
      "failed_evaluations": 0,
      "agent_action_reviews": 0,
      "pending_action_reviews": 0,
      "risk_acceptances": 0
    }
  },
  "customer_ops": {
    "subscription_plans": [
      {
        "id": "plan_pilot",
        "name": "NexaMarket Pilot",
        "tier": "pilot",
        "billing_cycle": "monthly",
        "base_mrr": 1500,
        "seat_limit": 5,
        "usage_limits": {
          "ai_actions": 800,
          "outbound_messages": 300,
          "workflow_runs": 150,
          "evidence_packets": 8
        },
        "feature_keys": [
          "crm_core",
          "guided_outbound",
          "deal_rooms",
          "basic_reporting"
        ],
        "support_tier": "standard",
        "status": "active"
      },
      {
        "id": "plan_growth",
        "name": "NexaMarket Growth",
        "tier": "growth",
        "billing_cycle": "annual",
        "base_mrr": 4200,
        "seat_limit": 15,
        "usage_limits": {
          "ai_actions": 2500,
          "outbound_messages": 1200,
          "workflow_runs": 500,
          "evidence_packets": 35
        },
        "feature_keys": [
          "crm_core",
          "governed_outbound",
          "deal_rooms",
          "cpq",
          "customer_health",
          "trust_center"
        ],
        "support_tier": "priority",
        "status": "active"
      },
      {
        "id": "plan_enterprise",
        "name": "NexaMarket Enterprise",
        "tier": "enterprise",
        "billing_cycle": "annual",
        "base_mrr": 9800,
        "seat_limit": 50,
        "usage_limits": {
          "ai_actions": 9000,
          "outbound_messages": 4500,
          "workflow_runs": 1800,
          "evidence_packets": 120
        },
        "feature_keys": [
          "crm_core",
          "governed_outbound",
          "deal_rooms",
          "cpq",
          "contract_ops",
          "provider_gateway",
          "tenant_ops",
          "trust_center",
          "ai_governance",
          "customer_success"
        ],
        "support_tier": "enterprise",
        "status": "active"
      }
    ],
    "billing_accounts": [],
    "entitlements": [],
    "usage_events": [],
    "usage_rollups": [],
    "support_tickets": [],
    "sla_credit_requests": [],
    "success_plans": [],
    "qbr_packets": [],
    "support_sla_policies": [
      {
        "severity": "sev1",
        "label": "Critical production outage",
        "response_hours": 1,
        "resolution_hours": 8,
        "credit_pct": 10
      },
      {
        "severity": "sev2",
        "label": "High customer-impacting issue",
        "response_hours": 4,
        "resolution_hours": 24,
        "credit_pct": 5
      },
      {
        "severity": "sev3",
        "label": "Standard support issue",
        "response_hours": 12,
        "resolution_hours": 72,
        "credit_pct": 0
      },
      {
        "severity": "sev4",
        "label": "Low priority question",
        "response_hours": 24,
        "resolution_hours": 120,
        "credit_pct": 0
      }
    ],
    "summary": {
      "billing_accounts": 0,
      "subscription_plans": 3,
      "entitlements": 0,
      "active_entitlements": 0,
      "pending_entitlements": 0,
      "renewal_due_entitlements": 0,
      "estimated_mrr": 0,
      "usage_events": 0,
      "usage_rollups": 0,
      "over_limit_rollups": 0,
      "approaching_limit_rollups": 0,
      "support_tickets": 0,
      "open_support_tickets": 0,
      "sla_breached_tickets": 0,
      "sla_credit_requests": 0,
      "pending_sla_credits": 0,
      "success_plans": 0,
      "at_risk_success_plans": 0,
      "qbr_packets": 0,
      "latest_usage_period": "2026-07",
      "as_of": "2026-07-27"
    }
  },
  "subscription_ops": {
    "billing_provider_connections": [
      {
        "id": "bill_conn_stripe_stub",
        "name": "Stripe Billing Stub",
        "provider": "stripe_stub",
        "environment": "sandbox",
        "status": "connected_simulated",
        "webhook_status": "verified_simulated",
        "sync_mode": "bidirectional",
        "external_account_id": "acct_demo_nexamarket",
        "object_types": [
          "customer",
          "subscription",
          "invoice",
          "usage_record",
          "credit_memo"
        ],
        "last_synced_at": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-BILL-CONN_STRIPE_STUB"
      },
      {
        "id": "bill_conn_chargebee_stub",
        "name": "Chargebee Billing Stub",
        "provider": "chargebee_stub",
        "environment": "sandbox",
        "status": "ready",
        "webhook_status": "not_configured",
        "sync_mode": "pull",
        "external_account_id": "site_demo_nexamarket",
        "object_types": [
          "customer",
          "subscription",
          "invoice",
          "usage_record"
        ],
        "last_synced_at": null,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-BILL-CONN_CHARGEBEE_STUB"
      }
    ],
    "subscription_sync_jobs": [],
    "external_subscriptions": [],
    "subscription_invoices": [],
    "usage_ingestion_batches": [],
    "metered_charges": [],
    "payment_attempts": [],
    "dunning_cases": [],
    "credit_memos": [],
    "support_sync_jobs": [],
    "entitlement_enforcement_checks": [],
    "usage_rates": {
      "ai_actions": {
        "included_label": "AI actions",
        "overage_rate": 0.04,
        "billable_unit": "action"
      },
      "outbound_messages": {
        "included_label": "Outbound messages",
        "overage_rate": 0.02,
        "billable_unit": "message"
      },
      "workflow_runs": {
        "included_label": "Workflow runs",
        "overage_rate": 0.25,
        "billable_unit": "run"
      },
      "evidence_packets": {
        "included_label": "Evidence packets",
        "overage_rate": 3.0,
        "billable_unit": "packet"
      }
    },
    "dunning_policy": {
      "retry_interval_days": 3,
      "service_risk_after_days": 14,
      "steps": [
        {
          "key": "payment_failed_notice",
          "label": "Payment failed notice",
          "offset_days": 0,
          "owner": "finance"
        },
        {
          "key": "billing_owner_followup",
          "label": "Billing owner follow-up",
          "offset_days": 3,
          "owner": "finance"
        },
        {
          "key": "executive_success_notice",
          "label": "Executive success notice",
          "offset_days": 7,
          "owner": "customer_success"
        },
        {
          "key": "service_risk_review",
          "label": "Service-risk review",
          "offset_days": 14,
          "owner": "manager"
        }
      ]
    },
    "summary": {
      "billing_provider_connections": 2,
      "connected_billing_providers": 2,
      "subscription_sync_jobs": 0,
      "external_subscriptions": 0,
      "active_external_subscriptions": 0,
      "subscription_invoices": 0,
      "open_subscription_invoices": 0,
      "overdue_subscription_invoices": 0,
      "subscription_invoice_total": 0,
      "open_subscription_balance": 0,
      "usage_ingestion_batches": 0,
      "accepted_usage_records": 0,
      "metered_charges": 0,
      "pending_metered_amount": 0,
      "payment_attempts": 0,
      "failed_payment_attempts": 0,
      "dunning_cases": 0,
      "open_dunning_cases": 0,
      "credit_memos": 0,
      "pending_credit_memos": 0,
      "support_sync_jobs": 0,
      "entitlement_enforcement_checks": 0,
      "blocked_entitlement_checks": 0,
      "as_of": "2026-07-27"
    }
  },
  "partner_ops": {
    "partners": [
      {
        "id": "partner_nexa_growth_advisors",
        "name": "Nexa Growth Advisors",
        "partner_type": "referral",
        "tier": "Gold",
        "region": "North America",
        "owner": "Avery Stone",
        "primary_contact": "Jordan Lee",
        "contact_email": "jordan@nexagrowth.example",
        "domain": "nexagrowth.example",
        "status": "active",
        "compliance_status": "approved",
        "certification_status": "certified",
        "marketplace_status": "eligible",
        "revenue_share_pct": 12.5,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "notes": "Seeded certified referral partner for channel-control workflows.",
        "canonical_id": "CAN-PART-NEXA_GROWTH_ADVISORS"
      },
      {
        "id": "partner_builder_systems",
        "name": "Builder Systems Collective",
        "partner_type": "implementation",
        "tier": "Silver",
        "region": "EMEA",
        "owner": "Marcus Hill",
        "primary_contact": "Priya Nandan",
        "contact_email": "partners@buildersystems.example",
        "domain": "buildersystems.example",
        "status": "onboarding_review",
        "compliance_status": "pending_review",
        "certification_status": "training_required",
        "marketplace_status": "not_eligible",
        "revenue_share_pct": 10.0,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "notes": "Seeded onboarding partner used to demonstrate certification/listing gates.",
        "canonical_id": "CAN-PART-BUILDER_SYSTEMS"
      }
    ],
    "partner_certifications": [],
    "marketplace_listings": [],
    "deal_registrations": [],
    "cosell_plans": [],
    "mdf_requests": [],
    "partner_payout_statements": [],
    "mdf_budget": {
      "annual_budget": 100000.0,
      "currency": "USD",
      "fiscal_year": "2026",
      "approval_threshold": 15000.0,
      "committed_amount": 0,
      "pending_amount": 0,
      "remaining_amount": 100000.0
    },
    "summary": {
      "partners": 2,
      "active_partners": 1,
      "certified_partners": 1,
      "certifications": 0,
      "expired_or_remediation_certs": 0,
      "marketplace_listings": 0,
      "published_listings": 0,
      "pending_listings": 0,
      "deal_registrations": 0,
      "open_deal_registrations": 0,
      "conflict_registrations": 0,
      "partner_pipeline": 0,
      "closed_partner_value": 0,
      "cosell_plans": 0,
      "open_cosell_plans": 0,
      "mdf_requests": 0,
      "pending_mdf_requests": 0,
      "approved_mdf_amount": 0,
      "pending_mdf_amount": 0,
      "payout_statements": 0,
      "pending_partner_payouts": 0,
      "pending_partner_payout_amount": 0,
      "as_of": "2026-07-27"
    }
  },
  "growth_ops": {
    "audience_segments": [
      {
        "id": "segment_enterprise_healthcare",
        "name": "Enterprise healthcare operators",
        "description": "Seeded account-based segment for healthcare operations leaders with email or LinkedIn consent.",
        "criteria": [
          "health",
          "operations"
        ],
        "allowed_channels": [
          "email",
          "linkedin"
        ],
        "status": "active",
        "requires_opt_in": true,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-27T15:37:40",
        "notes": "Seeded demo segment for growth-ops readiness.",
        "matched_contact_ids": [],
        "matched_account_ids": [],
        "matched_contacts": 0,
        "matched_accounts": 0,
        "consent_ready": false,
        "canonical_id": "CAN-GROW-ENTERPRISE_HEALTHCARE"
      }
    ],
    "campaign_programs": [],
    "attribution_events": [],
    "lead_scores": [],
    "routing_runs": [],
    "experiments": [],
    "experiment_results": [],
    "budget": {
      "period": "2026",
      "currency": "USD",
      "budget": 120000.0,
      "approval_threshold": 25000.0,
      "committed_spend": 0,
      "pending_spend": 0,
      "remaining_budget": 120000.0
    },
    "routing_rules": [
      {
        "id": "routing_enterprise_sales_ready",
        "name": "Enterprise sales-ready routing",
        "segment": "enterprise",
        "threshold": 75,
        "owner": "Sam Zbair",
        "sla_hours": 24,
        "status": "active"
      },
      {
        "id": "routing_partner_sourced",
        "name": "Partner-sourced routing",
        "segment": "partner",
        "threshold": 70,
        "owner": "Avery Stone",
        "sla_hours": 12,
        "status": "active"
      }
    ],
    "summary": {
      "segments": 1,
      "total_audience_contacts": 0,
      "campaigns": 0,
      "ready_campaigns": 0,
      "blocked_campaigns": 0,
      "launched_campaigns": 0,
      "campaign_spend": 0,
      "influenced_pipeline": 0,
      "attributed_revenue": 0,
      "pipeline_roi_pct": 0.0,
      "revenue_roi_pct": 0.0,
      "attribution_events": 0,
      "mqls": 0,
      "lead_scores": 0,
      "sales_ready_leads": 0,
      "routed_leads": 0,
      "experiments": 0,
      "open_experiments": 0,
      "winning_experiments": 0,
      "as_of": "2026-07-27"
    }
  },
  "intelligence_ops": {
    "metric_snapshots": [
      {
        "id": "snapshot_749adf2d44",
        "period": "2026-07",
        "snapshot_type": "executive_revenue_health",
        "source_mode": "cross_stack_rollup",
        "metrics": {
          "open_pipeline": 0.0,
          "weighted_forecast": 0.0,
          "commit_pipeline": 0.0,
          "best_case_pipeline": 0,
          "pipeline_deals": 1,
          "closed_won_pipeline": 0,
          "paid_invoice_amount": 0,
          "open_invoice_balance": 0,
          "subscription_mrr": 0.0,
          "subscription_arr": 0.0,
          "active_entitlements": 0,
          "attributed_revenue": 0.0,
          "influenced_pipeline": 0.0,
          "campaign_spend": 0.0,
          "pipeline_roi_pct": 0.0,
          "sales_ready_leads": 0,
          "routed_leads": 0,
          "partner_pipeline": 0.0,
          "partner_payout_due": 0.0,
          "open_support_tickets": 0,
          "sla_breaches": 2,
          "at_risk_success_plans": 0,
          "failed_payment_attempts": 0,
          "open_dunning_cases": 0,
          "open_approvals": 0,
          "provider_alerts": 14,
          "open_sync_conflicts": 9,
          "high_quality_issues": 0,
          "operational_risk_count": 25,
          "pipeline_coverage_ratio": 0.0
        },
        "deltas": {},
        "segment_breakdown": {
          "deal_stage_amounts": {
            "placeholder": 0.0
          },
          "forecast_category_amounts": {
            "commit": 0.0
          },
          "growth_campaigns": {},
          "support_severity_counts": {},
          "provider_status_counts": {
            "healthy": 59,
            "simulated": 13,
            "planned": 1,
            "attention": 13
          }
        },
        "health_score": 53,
        "status": "at_risk",
        "owner": "Avery Stone",
        "created_at": "2026-07-12T01:35:50",
        "notes": "Auto-generated for BI dashboard refresh.",
        "canonical_id": "CAN-INTE-749ADF2D44"
      }
    ],
    "executive_scorecards": [],
    "anomaly_runs": [],
    "anomaly_alerts": [],
    "board_packets": [],
    "anomaly_policies": [
      {
        "id": "policy_pipeline_coverage",
        "name": "Pipeline coverage guardrail",
        "metric_key": "pipeline_coverage_ratio",
        "operator": "lt",
        "threshold": 3.0,
        "severity": "medium",
        "status": "active",
        "recommended_action": "Create or route qualified pipeline and verify forecast coverage before the next executive review."
      },
      {
        "id": "policy_growth_roi",
        "name": "Growth ROI guardrail",
        "metric_key": "pipeline_roi_pct",
        "operator": "lt",
        "threshold": 300.0,
        "severity": "warning",
        "status": "active",
        "recommended_action": "Review campaign segment quality, offer/message experiment evidence, and attribution completeness."
      },
      {
        "id": "policy_operational_risk",
        "name": "Operational risk guardrail",
        "metric_key": "operational_risk_count",
        "operator": "gt",
        "threshold": 0.0,
        "severity": "high",
        "status": "active",
        "recommended_action": "Resolve provider alerts, SLA breaches, open incidents, and source-of-truth conflicts."
      }
    ],
    "playbooks": [
      {
        "id": "playbook_pipeline_coverage",
        "name": "Pipeline coverage recovery",
        "trigger_category": "pipeline",
        "owner_role": "manager",
        "default_owner": "Sam Zbair",
        "steps": [
          "Review commit and best-case forecast gaps.",
          "Run growth routing for sales-ready leads.",
          "Create governed campaign or partner co-sell action for target segment.",
          "Update next steps on under-covered strategic deals."
        ],
        "status": "active",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-INTE-PIPELINE_COVERAGE"
      },
      {
        "id": "playbook_operational_risk",
        "name": "Operational risk cleanup",
        "trigger_category": "operations",
        "owner_role": "manager",
        "default_owner": "Avery Stone",
        "steps": [
          "Triage provider alerts, source-of-truth conflicts, and SLA breaches.",
          "Open or resolve incidents with owner notes.",
          "Run backup/event-health checks and attach evidence.",
          "Confirm blockers are cleared before release or board review."
        ],
        "status": "active",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-INTE-OPERATIONAL_RISK"
      }
    ],
    "playbook_runs": [],
    "summary": {
      "latest_period": "2026-07",
      "metric_snapshots": 1,
      "scorecards": 0,
      "board_packets": 0,
      "open_alerts": 0,
      "high_alerts": 0,
      "playbooks": 2,
      "playbook_runs": 0,
      "readiness_score": 30,
      "readiness_status": "at_risk",
      "open_pipeline": 0.0,
      "weighted_forecast": 0.0,
      "subscription_mrr": 0.0,
      "attributed_revenue": 0.0,
      "operational_risk_count": 23,
      "latest_snapshot_id": "snapshot_749adf2d44",
      "latest_board_packet_id": null,
      "active_scorecard_id": null,
      "as_of": "2026-07-27"
    }
  },
  "analytics_ops": {
    "warehouse_connections": [
      {
        "id": "wh_local_revenue_lake",
        "name": "Nexa Revenue Lakehouse",
        "provider": "Local Lakehouse Stub",
        "environment": "sandbox",
        "dataset": "nexamarket_revenue_ops",
        "region": "us-east-1",
        "sync_mode": "incremental",
        "status": "connected_simulated",
        "owner": "Revenue Operations",
        "secret_ref": "vault://analytics/local-revenue-lake",
        "masked_secret": "\u2022\u2022\u2022\u2022lake",
        "created_at": "2026-07-09T19:05:10",
        "last_sync_at": null,
        "last_tested_at": null,
        "notes": "Local governed warehouse stub for pipeline, finance, subscription, partner, growth, and intelligence rollups.",
        "canonical_id": "CAN-ANAL-LOCAL_REVENUE_LAKE"
      }
    ],
    "warehouse_sync_jobs": [],
    "data_contracts": [
      {
        "id": "contract_crm_deals",
        "name": "CRM deals contract",
        "source_path": "crm.deals",
        "owner": "Revenue Operations",
        "required_fields": [
          "id",
          "company_name",
          "stage",
          "amount"
        ],
        "freshness_sla_hours": 24,
        "severity": "high",
        "status": "active",
        "notes": "Every open and historical deal must carry identity, company, stage, and value fields for forecast and warehouse sync.",
        "canonical_id": "CAN-ANAL-CRM_DEALS"
      },
      {
        "id": "contract_invoices",
        "name": "Invoice revenue contract",
        "source_path": "invoices",
        "owner": "Finance Operations",
        "required_fields": [
          "id",
          "company_name",
          "amount",
          "status"
        ],
        "freshness_sla_hours": 24,
        "severity": "high",
        "status": "active",
        "notes": "Invoice records must support finance, recognition, settlement, and executive revenue evidence.",
        "canonical_id": "CAN-ANAL-INVOICES"
      },
      {
        "id": "contract_growth_attribution",
        "name": "Growth attribution contract",
        "source_path": "growth_ops.attribution_events",
        "owner": "Growth Operations",
        "required_fields": [
          "id",
          "event_type",
          "company_name",
          "value"
        ],
        "freshness_sla_hours": 48,
        "severity": "medium",
        "status": "active",
        "notes": "Campaign attribution must preserve event type, buyer/company context, and value for ROI calculations.",
        "canonical_id": "CAN-ANAL-GROWTH_ATTRIBUTION"
      },
      {
        "id": "contract_subscription_usage",
        "name": "Subscription telemetry contract",
        "source_path": "subscription_ops.usage_ingestion_batches",
        "owner": "Customer Operations",
        "required_fields": [
          "id",
          "accepted_records",
          "rejected_records",
          "status"
        ],
        "freshness_sla_hours": 24,
        "severity": "medium",
        "status": "active",
        "notes": "Usage records must be complete enough to power entitlement enforcement, overages, and lifecycle analytics.",
        "canonical_id": "CAN-ANAL-SUBSCRIPTION_USAGE"
      }
    ],
    "data_contract_validation_runs": [],
    "data_contract_violations": [],
    "metric_definitions": [
      {
        "id": "metric_open_pipeline",
        "name": "Open Pipeline",
        "metric_key": "open_pipeline",
        "formula": "sum(crm.deals.amount where stage not in Closed Won/Closed Lost)",
        "grain": "deal",
        "owner": "Revenue Operations",
        "dimensions": [
          "stage",
          "forecast_category",
          "owner"
        ],
        "status": "approved",
        "lineage_sources": [
          "crm.deals"
        ],
        "notes": "Canonical operating metric for executive pipeline coverage and forecast quality.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ANAL-OPEN_PIPELINE"
      },
      {
        "id": "metric_weighted_forecast",
        "name": "Weighted Forecast",
        "metric_key": "weighted_forecast",
        "formula": "sum(open deal amount \u00d7 probability/confidence)",
        "grain": "deal",
        "owner": "Revenue Operations",
        "dimensions": [
          "stage",
          "forecast_category"
        ],
        "status": "approved",
        "lineage_sources": [
          "crm.deals",
          "intelligence.metric_snapshots"
        ],
        "notes": "Forecast value calculated from open pipeline and confidence signals.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ANAL-WEIGHTED_FORECAST"
      },
      {
        "id": "metric_subscription_mrr",
        "name": "Subscription MRR",
        "metric_key": "subscription_mrr",
        "formula": "sum(active entitlement monthly recurring value)",
        "grain": "tenant_entitlement",
        "owner": "Customer Operations",
        "dimensions": [
          "plan",
          "tenant",
          "status"
        ],
        "status": "approved",
        "lineage_sources": [
          "customer_ops.entitlements",
          "subscription_ops.external_subscriptions"
        ],
        "notes": "Recurring-revenue signal for customer lifecycle and board reporting.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ANAL-SUBSCRIPTION_MRR"
      },
      {
        "id": "metric_operational_risk_count",
        "name": "Operational Risk Count",
        "metric_key": "operational_risk_count",
        "formula": "open incidents + SLA breaches + open conflicts + provider alerts + dunning cases + high data-quality issues",
        "grain": "risk_signal",
        "owner": "Operations",
        "dimensions": [
          "risk_type",
          "owner",
          "severity"
        ],
        "status": "approved",
        "lineage_sources": [
          "release_ops",
          "platform_sync",
          "integrations.health",
          "subscription_ops",
          "customer_ops"
        ],
        "notes": "Cross-stack risk counter used by intelligence anomaly policies and launch/readiness gates.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ANAL-OPERATIONAL_RISK_COUNT"
      }
    ],
    "dashboard_refreshes": [
      {
        "id": "dashboard_refresh_ffc92770ea",
        "dashboard_name": "Executive Revenue BI Dashboard",
        "period": "2026-07",
        "snapshot_id": "snapshot_749adf2d44",
        "scorecard_id": null,
        "widgets": [
          "Pipeline",
          "Forecast",
          "MRR",
          "Growth ROI",
          "Operational Risk"
        ],
        "subscribers": [
          "executive-team@nexabuilder.local"
        ],
        "status": "published_simulated",
        "blocked_reasons": [],
        "evidence_links": [
          "/api/export/intelligence",
          "/api/export/analytics",
          "/api/export/growth",
          "/api/export/subscription"
        ],
        "created_at": "2026-07-12T01:35:50",
        "published_at": "2026-07-12T01:35:50",
        "owner": "Avery Stone",
        "notes": "Dashboard refresh generated from metric snapshot, semantic definitions, and current data-contract posture.",
        "canonical_id": "CAN-ANAL-REFRESH_FFC92770EA"
      }
    ],
    "forecast_models": [
      {
        "id": "forecast_model_revenue_baseline",
        "name": "Revenue Baseline Forecast",
        "target_metric": "weighted_forecast",
        "algorithm": "deterministic_weighted_pipeline",
        "training_window_months": 6,
        "feature_set": [
          "open_pipeline",
          "commit_pipeline",
          "best_case_pipeline",
          "subscription_mrr",
          "growth_influenced_pipeline"
        ],
        "status": "trained_simulated",
        "owner": "Revenue Operations",
        "last_trained_at": "2026-07-09T19:05:10",
        "backtest_mape_pct": 14.0,
        "risk_grade": "medium",
        "notes": "Local deterministic baseline until a production forecasting/ML pipeline is attached.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ANAL-MODEL_REVENUE_BASELINE"
      }
    ],
    "forecast_runs": [],
    "summary": {
      "warehouse_connections": 1,
      "active_connections": 1,
      "warehouse_sync_jobs": 0,
      "last_sync_status": "not_run",
      "data_contracts": 4,
      "open_contract_violations": 0,
      "last_validation_status": "not_run",
      "metric_definitions": 4,
      "dashboard_refreshes": 1,
      "latest_dashboard_status": "published_simulated",
      "forecast_models": 1,
      "trained_models": 1,
      "forecast_runs": 0,
      "latest_forecast_value": 0,
      "latest_forecast_status": "not_run",
      "data_quality_score": 100,
      "data_quality_status": "healthy",
      "as_of": "2026-07-27"
    }
  },
  "model_ops": {
    "feature_sets": [
      {
        "id": "feature_set_revenue_forecast",
        "name": "Revenue Forecast Feature Set",
        "model_id": "forecast_model_revenue_baseline",
        "status": "approved",
        "owner": "Revenue Operations",
        "sources": [
          "crm",
          "subscription",
          "growth",
          "partner",
          "intelligence"
        ],
        "features": [
          "open_pipeline",
          "commit_pipeline",
          "best_case_pipeline",
          "subscription_mrr",
          "growth_influenced_pipeline",
          "operational_risk_count"
        ],
        "transformations": [
          "weighted_pipeline",
          "risk_adjustment",
          "mrr_normalization"
        ],
        "data_contract_ids": [
          "contract_crm_deals",
          "contract_growth_attribution",
          "contract_subscription_usage"
        ],
        "freshness_sla_hours": 24,
        "last_refreshed_at": "2026-07-09T19:05:10",
        "created_at": "2026-07-09T19:05:10",
        "notes": "Canonical deterministic feature set for the revenue forecast baseline model.",
        "canonical_id": "CAN-MODE-SET_REVENUE_FORECAST"
      }
    ],
    "training_datasets": [],
    "model_evaluations": [],
    "drift_monitors": [
      {
        "id": "drift_monitor_revenue_forecast",
        "name": "Revenue Forecast Drift Monitor",
        "model_id": "forecast_model_revenue_baseline",
        "status": "active",
        "owner": "Revenue Operations",
        "prediction_drift_threshold_pct": 25.0,
        "confidence_floor_pct": 70.0,
        "data_quality_floor": 80,
        "severity": "medium",
        "created_at": "2026-07-09T19:05:10",
        "last_run_at": null,
        "notes": "Flags forecast swings, low confidence, and data-quality posture that should trigger retraining review.",
        "canonical_id": "CAN-MODE-MONITOR_REVENUE_FORECAST"
      }
    ],
    "drift_runs": [],
    "retraining_jobs": [],
    "deployment_approvals": [],
    "lineage_runs": [],
    "summary": {
      "feature_sets": 1,
      "training_datasets": 0,
      "model_evaluations": 0,
      "drift_monitors": 1,
      "drift_runs": 0,
      "open_drift_alerts": 0,
      "retraining_jobs": 0,
      "deployment_approvals": 0,
      "pending_deployments": 0,
      "lineage_runs": 0,
      "latest_dataset_status": "not_built",
      "latest_evaluation_status": "not_run",
      "latest_drift_status": "not_run",
      "modelops_readiness_score": 84,
      "modelops_readiness_status": "watch",
      "as_of": "2026-07-27"
    }
  },
  "agent_ops": {
    "tool_catalog": [
      {
        "key": "crm_read",
        "name": "CRM read",
        "category": "crm",
        "risk_level": "low",
        "requires_human_review": false,
        "description": "Read CRM contacts, accounts, opportunities, and timeline records."
      },
      {
        "key": "crm_write",
        "name": "CRM write",
        "category": "crm",
        "risk_level": "medium",
        "requires_human_review": true,
        "description": "Create or update CRM leads, tasks, notes, and next steps."
      },
      {
        "key": "outbound_send",
        "name": "Outbound send",
        "category": "outreach",
        "risk_level": "high",
        "requires_human_review": true,
        "description": "Send governed email/SMS/WhatsApp/LinkedIn outreach through approved channels."
      },
      {
        "key": "meeting_schedule",
        "name": "Meeting scheduling",
        "category": "calendar",
        "risk_level": "medium",
        "requires_human_review": true,
        "description": "Create calendar holds or meetings with buyer-facing context."
      },
      {
        "key": "quote_prepare",
        "name": "Quote preparation",
        "category": "cpq",
        "risk_level": "medium",
        "requires_human_review": true,
        "description": "Prepare CPQ quote drafts using price-book and deal-desk constraints."
      },
      {
        "key": "contract_prepare",
        "name": "Contract packet preparation",
        "category": "contract",
        "risk_level": "high",
        "requires_human_review": true,
        "description": "Prepare contract packet drafts, clause references, and signature authority evidence."
      },
      {
        "key": "billing_read",
        "name": "Billing read",
        "category": "finance",
        "risk_level": "medium",
        "requires_human_review": false,
        "description": "Read subscription, invoice, usage, dunning, and credit memo status."
      }
    ],
    "agent_policies": [
      {
        "id": "agent_policy_revenue_assistant",
        "name": "Revenue Assistant Policy",
        "scope": "pipeline_followup_and_customer_context",
        "allowed_tools": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "outbound_send"
        ],
        "approval_required_for": [
          "crm_write",
          "meeting_schedule",
          "outbound_send"
        ],
        "data_scopes": [
          "crm",
          "approved_materials",
          "meetings",
          "customer_success"
        ],
        "max_autonomy_level": 2,
        "status": "approved",
        "kill_switch_enabled": false,
        "owner": "Revenue Operations",
        "notes": "Seeded policy for buyer follow-up, CRM updates, and safe meeting scheduling.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-AGEN-POLICY_REVENUE_ASSISTANT"
      },
      {
        "id": "agent_policy_revops_analyst",
        "name": "RevOps Analyst Policy",
        "scope": "analysis_explainability_and_board_context",
        "allowed_tools": [
          "crm_read",
          "billing_read"
        ],
        "approval_required_for": [],
        "data_scopes": [
          "analytics",
          "intelligence",
          "billing_readonly"
        ],
        "max_autonomy_level": 1,
        "status": "approved",
        "kill_switch_enabled": false,
        "owner": "RevOps",
        "notes": "Seeded read-only policy for analytics and executive explanation workflows.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-AGEN-POLICY_REVOPS_ANALYST"
      }
    ],
    "prompt_versions": [
      {
        "id": "prompt_revenue_assistant_v1",
        "prompt_key": "revenue_assistant_followup",
        "version": "v1.0",
        "agent_name": "Revenue Assistant",
        "policy_id": "agent_policy_revenue_assistant",
        "risk_level": "medium",
        "tools_required": [
          "crm_read",
          "crm_write",
          "meeting_schedule"
        ],
        "data_scopes": [
          "crm",
          "approved_materials",
          "meetings"
        ],
        "status": "evaluated",
        "prompt_summary": "Creates governed follow-up recommendations and meeting next steps from CRM and buyer workspace evidence.",
        "created_by": "System",
        "notes": "Seeded prompt version awaiting production release approval if used outside dry-run mode.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-AGEN-REVENUE_ASSISTANT_V1"
      },
      {
        "id": "prompt_revops_explainer_v1",
        "prompt_key": "revops_executive_explainer",
        "version": "v1.0",
        "agent_name": "RevOps Explainer",
        "policy_id": "agent_policy_revops_analyst",
        "risk_level": "low",
        "tools_required": [
          "crm_read",
          "billing_read"
        ],
        "data_scopes": [
          "analytics",
          "intelligence",
          "billing_readonly"
        ],
        "status": "evaluated",
        "prompt_summary": "Explains scorecards, anomalies, and board packet evidence without write access.",
        "created_by": "System",
        "notes": "Seeded prompt version for read-only executive context.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-AGEN-REVOPS_EXPLAINER_V1"
      }
    ],
    "prompt_evaluations": [],
    "agent_release_approvals": [],
    "tool_authorizations": [],
    "workflow_blueprints": [
      {
        "id": "agent_workflow_pipeline_followup",
        "name": "Pipeline Follow-up Agent",
        "objective": "Identify stale or high-fit deals, draft compliant follow-up, and prepare meeting next steps.",
        "policy_id": "agent_policy_revenue_assistant",
        "prompt_version_id": "prompt_revenue_assistant_v1",
        "required_tools": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "outbound_send"
        ],
        "default_autonomy_level": 1,
        "requires_human_review": true,
        "status": "active",
        "notes": "Recommended first workflow for dry-run validation before production outreach.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "agent_workflow_exec_briefing",
        "name": "Executive Briefing Agent",
        "objective": "Summarize revenue intelligence, analytics, billing, and board packet evidence.",
        "policy_id": "agent_policy_revops_analyst",
        "prompt_version_id": "prompt_revops_explainer_v1",
        "required_tools": [
          "crm_read",
          "billing_read"
        ],
        "default_autonomy_level": 1,
        "requires_human_review": false,
        "status": "active",
        "notes": "Read-only briefing workflow for executive review packets.",
        "created_at": "2026-07-09T19:05:10"
      }
    ],
    "workflow_runs": [],
    "run_traces": [],
    "automation_schedules": [],
    "guardrail_incidents": [],
    "summary": {
      "agent_policies": 2,
      "prompt_versions": 2,
      "prompt_evaluations": 0,
      "tool_authorizations": 0,
      "workflow_blueprints": 2,
      "workflow_runs": 0,
      "automation_schedules": 0,
      "guardrail_incidents": 0,
      "open_guardrail_incidents": 0,
      "agent_release_approvals": 0,
      "pending_release_approvals": 0,
      "blocked_workflow_runs": 0,
      "expired_tool_authorizations": 0,
      "latest_run_status": "not_run",
      "latest_evaluation_status": "not_run",
      "agentops_readiness_score": 100,
      "agentops_readiness_status": "healthy",
      "as_of": "2026-07-27"
    }
  },
  "observability_ops": {
    "telemetry_sources": [
      {
        "id": "telemetry_source_agent_runtime",
        "name": "AgentOps Runtime Observer",
        "source_key": "agent_runtime",
        "category": "agentops",
        "status": "active",
        "sampling_rate_pct": 100,
        "last_seen_at": null,
        "description": "Captures workflow-run status, tool actions, blocked reasons, and review posture.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "telemetry_source_provider_gateway",
        "name": "Provider Gateway Telemetry",
        "source_key": "provider_gateway",
        "category": "integrations",
        "status": "active",
        "sampling_rate_pct": 100,
        "last_seen_at": null,
        "description": "Captures provider tests, sync jobs, webhooks, and credential events.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "telemetry_source_billing",
        "name": "Subscription Billing Telemetry",
        "source_key": "billing_runtime",
        "category": "billing",
        "status": "active",
        "sampling_rate_pct": 100,
        "last_seen_at": null,
        "description": "Captures invoice, payment failure, dunning, metered charge, and credit-memo signals.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "telemetry_source_modelops",
        "name": "ModelOps Drift Telemetry",
        "source_key": "modelops_drift",
        "category": "modelops",
        "status": "active",
        "sampling_rate_pct": 100,
        "last_seen_at": null,
        "description": "Captures forecast evaluation, drift, retraining, and deployment-gate signals.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "telemetry_source_runtime_worker",
        "name": "Runtime Worker Telemetry",
        "source_key": "runtime_worker",
        "category": "runtime",
        "status": "active",
        "sampling_rate_pct": 100,
        "last_seen_at": null,
        "description": "Captures job queue leases, completion signals, tool proxy decisions, deployment changes, and capacity warnings.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "telemetry_source_orchestration_engine",
        "name": "Orchestration Engine Telemetry",
        "source_key": "orchestration_engine",
        "category": "runtime",
        "status": "active",
        "sampling_rate_pct": 100,
        "last_seen_at": null,
        "description": "Captures durable workflow state transitions, lock conflicts, retries, handoffs, and compensation decisions.",
        "created_at": "2026-07-09T19:05:10"
      }
    ],
    "trace_sessions": [],
    "telemetry_events": [],
    "replay_runs": [],
    "incident_routes": [
      {
        "id": "route_agent_runtime_high",
        "name": "Agent runtime high-severity route",
        "condition": "agent_runtime high critical blocked unsafe_tool_use",
        "severity_floor": "high",
        "target_team": "RevOps On-Call",
        "pager_target": "pager://revops-agent-runtime",
        "response_sla_minutes": 30,
        "auto_escalate": true,
        "status": "active",
        "owner": "Revenue Operations",
        "notes": "Routes high-severity AgentOps runtime, unsafe tool-use, and kill-switch cases.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-OBSE-AGENT_RUNTIME_HIGH"
      },
      {
        "id": "route_provider_failure",
        "name": "Provider gateway incident route",
        "condition": "provider webhook sync credential failure",
        "severity_floor": "medium",
        "target_team": "Integration Operations",
        "pager_target": "pager://integration-ops",
        "response_sla_minutes": 60,
        "auto_escalate": true,
        "status": "active",
        "owner": "Integration Operations",
        "notes": "Routes provider-webhook, credential, and sync-delivery cases.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-OBSE-PROVIDER_FAILURE"
      },
      {
        "id": "route_finance_controls",
        "name": "Finance controls incident route",
        "condition": "settlement payout invoice credit dunning finance",
        "severity_floor": "high",
        "target_team": "Finance Operations",
        "pager_target": "pager://finance-ops",
        "response_sla_minutes": 45,
        "auto_escalate": true,
        "status": "active",
        "owner": "Finance Operations",
        "notes": "Routes settlement, payout, invoice, credit, and dunning exceptions.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-OBSE-FINANCE_CONTROLS"
      }
    ],
    "escalation_cases": [],
    "kill_switches": [
      {
        "id": "kill_agent_runtime_global",
        "name": "Agent runtime global kill switch",
        "scope": "agent_runtime",
        "target_capabilities": [
          "agent_runtime",
          "agent_workflows",
          "tool_execution"
        ],
        "status": "inactive",
        "severity": "critical",
        "owner": "Revenue Operations",
        "reason": "Emergency stop for production agent workflow execution.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "expires_at": null,
        "last_toggled_at": null,
        "decision_notes": "Seeded inactive control.",
        "canonical_id": "CAN-OBSE-AGENT_RUNTIME_GLOBAL"
      },
      {
        "id": "kill_outbound_send",
        "name": "Outbound send kill switch",
        "scope": "outbound_send",
        "target_capabilities": [
          "outbound_send",
          "messaging",
          "campaign_launch"
        ],
        "status": "inactive",
        "severity": "high",
        "owner": "Compliance",
        "reason": "Pause buyer-facing messaging if consent, claims, or provider controls fail.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "expires_at": null,
        "last_toggled_at": null,
        "decision_notes": "Seeded inactive control.",
        "canonical_id": "CAN-OBSE-OUTBOUND_SEND"
      },
      {
        "id": "kill_provider_live_mode",
        "name": "Provider live-mode kill switch",
        "scope": "provider_live_mode",
        "target_capabilities": [
          "provider_sync",
          "webhook_intake",
          "live_connectors"
        ],
        "status": "inactive",
        "severity": "high",
        "owner": "Integration Operations",
        "reason": "Pause live provider traffic during credential, webhook, or sync incidents.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "expires_at": null,
        "last_toggled_at": null,
        "decision_notes": "Seeded inactive control.",
        "canonical_id": "CAN-OBSE-PROVIDER_LIVE_MODE"
      },
      {
        "id": "kill_finance_settlement",
        "name": "Finance settlement kill switch",
        "scope": "finance_settlement",
        "target_capabilities": [
          "settlement_capture",
          "payout_payment",
          "credit_memo_apply"
        ],
        "status": "inactive",
        "severity": "critical",
        "owner": "Finance Operations",
        "reason": "Pause finance write-backs and payout simulation when settlement controls need review.",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "expires_at": null,
        "last_toggled_at": null,
        "decision_notes": "Seeded inactive control.",
        "canonical_id": "CAN-OBSE-FINANCE_SETTLEMENT"
      }
    ],
    "service_level_objectives": [
      {
        "id": "slo_agent_runtime_success",
        "name": "Agent runtime success rate",
        "metric_key": "agent_runtime_success_rate_pct",
        "target_direction": ">=",
        "target_value": 98.0,
        "unit": "%",
        "window": "24h",
        "owner": "Revenue Operations",
        "status": "active",
        "notes": "Production-grade target for workflow runs without guardrail-blocking errors.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "slo_tool_telemetry_latency",
        "name": "Telemetry ingestion latency",
        "metric_key": "telemetry_ingestion_latency_minutes",
        "target_direction": "<=",
        "target_value": 5.0,
        "unit": "minutes",
        "window": "1h",
        "owner": "Platform Operations",
        "status": "active",
        "notes": "Ensures runtime telemetry is visible quickly enough for operator action.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "slo_provider_webhook_success",
        "name": "Provider webhook success rate",
        "metric_key": "provider_webhook_success_rate_pct",
        "target_direction": ">=",
        "target_value": 99.0,
        "unit": "%",
        "window": "24h",
        "owner": "Integration Operations",
        "status": "active",
        "notes": "Maintains strict live-provider callback reliability.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "slo_event_bus_lag",
        "name": "Event-bus consumer lag",
        "metric_key": "event_bus_consumer_lag",
        "target_direction": "<=",
        "target_value": 10.0,
        "unit": "events",
        "window": "15m",
        "owner": "Platform Operations",
        "status": "active",
        "notes": "Keeps cross-product sync lag within go-live limits.",
        "created_at": "2026-07-09T19:05:10"
      },
      {
        "id": "slo_human_review_age",
        "name": "Human-review queue age",
        "metric_key": "human_review_age_hours",
        "target_direction": "<=",
        "target_value": 24.0,
        "unit": "hours",
        "window": "7d",
        "owner": "Revenue Operations",
        "status": "active",
        "notes": "Prevents automation approvals and blocked runtime reviews from aging out.",
        "created_at": "2026-07-09T19:05:10"
      }
    ],
    "service_level_checks": [],
    "oncall_roster": [
      {
        "id": "oncall_revops",
        "team": "RevOps On-Call",
        "primary": "Morgan Lee",
        "backup": "Avery Stone",
        "channel": "pager://revops-agent-runtime",
        "status": "active"
      },
      {
        "id": "oncall_integration",
        "team": "Integration Operations",
        "primary": "Sam Rivera",
        "backup": "Priya Shah",
        "channel": "pager://integration-ops",
        "status": "active"
      },
      {
        "id": "oncall_finance",
        "team": "Finance Operations",
        "primary": "Taylor Kim",
        "backup": "Jordan Patel",
        "channel": "pager://finance-ops",
        "status": "active"
      }
    ],
    "summary": {
      "telemetry_sources": 6,
      "telemetry_events": 0,
      "trace_sessions": 0,
      "replay_runs": 0,
      "incident_routes": 3,
      "escalation_cases": 0,
      "open_escalations": 0,
      "kill_switches": 4,
      "active_kill_switches": 0,
      "service_level_objectives": 5,
      "service_level_checks": 0,
      "failed_service_level_checks": 0,
      "critical_telemetry_events": 0,
      "replay_mismatches": 0,
      "latest_telemetry_status": "not_seen",
      "latest_trace_status": "not_captured",
      "latest_slo_status": "not_checked",
      "observability_readiness_score": 100,
      "observability_readiness_status": "healthy",
      "as_of": "2026-07-27"
    }
  },
  "runtime_ops": {
    "sandbox_policies": [
      {
        "id": "sandbox_agent_default",
        "name": "Default Agent Runtime Sandbox",
        "status": "active",
        "network_mode": "restricted",
        "pii_mode": "masked",
        "max_runtime_seconds": 600,
        "max_tool_calls": 12,
        "allowed_tools": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "quote_prepare",
          "billing_read"
        ],
        "blocked_tools": [
          "finance_settlement",
          "payout_payment"
        ],
        "require_human_approval_for": [
          "outbound_send",
          "contract_prepare",
          "finance_settlement"
        ],
        "evidence_required": true,
        "owner": "AgentOps",
        "last_reviewed_at": "2026-07-09T19:05:10",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-AGENT_DEFAULT"
      },
      {
        "id": "sandbox_finance_strict",
        "name": "Strict Finance Control Sandbox",
        "status": "active",
        "network_mode": "allowlisted",
        "pii_mode": "masked",
        "max_runtime_seconds": 300,
        "max_tool_calls": 6,
        "allowed_tools": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "blocked_tools": [
          "payout_payment",
          "bank_update"
        ],
        "require_human_approval_for": [
          "settlement_capture",
          "credit_memo_apply",
          "payout_payment"
        ],
        "evidence_required": true,
        "owner": "Finance Operations",
        "last_reviewed_at": "2026-07-09T19:05:10",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-FINANCE_STRICT"
      },
      {
        "id": "sandbox_provider_sync",
        "name": "Provider Sync Sandbox",
        "status": "active",
        "network_mode": "provider_allowlist",
        "pii_mode": "minimum_required",
        "max_runtime_seconds": 900,
        "max_tool_calls": 20,
        "allowed_tools": [
          "provider_sync",
          "webhook_verify",
          "event_replay"
        ],
        "blocked_tools": [
          "outbound_send",
          "payout_payment"
        ],
        "require_human_approval_for": [
          "provider_live_mode"
        ],
        "evidence_required": true,
        "owner": "Integration Operations",
        "last_reviewed_at": "2026-07-09T19:05:10",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC"
      },
      {
        "id": "sandbox_modelops_training",
        "name": "ModelOps Training Sandbox",
        "status": "active",
        "network_mode": "warehouse_only",
        "pii_mode": "deidentified",
        "max_runtime_seconds": 1800,
        "max_tool_calls": 8,
        "allowed_tools": [
          "warehouse_read",
          "feature_materialize",
          "model_evaluate",
          "lineage_scan"
        ],
        "blocked_tools": [
          "crm_write",
          "outbound_send",
          "finance_settlement"
        ],
        "require_human_approval_for": [
          "model_deploy",
          "champion_promote"
        ],
        "evidence_required": true,
        "owner": "ModelOps",
        "last_reviewed_at": "2026-07-09T19:05:10",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING"
      }
    ],
    "job_queues": [
      {
        "id": "queue_agent_runtime",
        "name": "Agent Runtime Jobs",
        "queue_key": "agent_runtime",
        "status": "active",
        "priority": 70,
        "max_attempts": 3,
        "dead_letter_queue": "agent_runtime_dead_letter",
        "owner": "AgentOps",
        "sla_minutes": 15,
        "queued_jobs": 0,
        "leased_jobs": 0,
        "failed_jobs": 0,
        "dead_letter_jobs": 0,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-27T15:37:40",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME"
      },
      {
        "id": "queue_provider_sync",
        "name": "Provider Sync Jobs",
        "queue_key": "provider_sync",
        "status": "active",
        "priority": 60,
        "max_attempts": 4,
        "dead_letter_queue": "provider_sync_dead_letter",
        "owner": "Integration Operations",
        "sla_minutes": 30,
        "queued_jobs": 0,
        "leased_jobs": 0,
        "failed_jobs": 0,
        "dead_letter_jobs": 0,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-27T15:37:40",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC"
      },
      {
        "id": "queue_finance_settlement",
        "name": "Finance Settlement Jobs",
        "queue_key": "finance_settlement",
        "status": "active",
        "priority": 90,
        "max_attempts": 2,
        "dead_letter_queue": "finance_settlement_dead_letter",
        "owner": "Finance Operations",
        "sla_minutes": 10,
        "queued_jobs": 0,
        "leased_jobs": 0,
        "failed_jobs": 0,
        "dead_letter_jobs": 0,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-27T15:37:40",
        "canonical_id": "CAN-RUNT-FINANCE_SETTLEMENT"
      },
      {
        "id": "queue_modelops_training",
        "name": "ModelOps Training Jobs",
        "queue_key": "modelops_training",
        "status": "active",
        "priority": 40,
        "max_attempts": 2,
        "dead_letter_queue": "modelops_training_dead_letter",
        "owner": "ModelOps",
        "sla_minutes": 120,
        "queued_jobs": 0,
        "leased_jobs": 0,
        "failed_jobs": 0,
        "dead_letter_jobs": 0,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-27T15:37:40",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING"
      },
      {
        "id": "queue_multi_agent_orchestration",
        "name": "Multi-Agent Orchestration Jobs",
        "queue_key": "multi_agent_orchestration",
        "status": "active",
        "priority": 85,
        "max_attempts": 3,
        "dead_letter_queue": "multi_agent_orchestration_dead_letter",
        "owner": "AgentOps",
        "sla_minutes": 20,
        "queued_jobs": 0,
        "leased_jobs": 0,
        "failed_jobs": 0,
        "dead_letter_jobs": 0,
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-27T15:37:40",
        "canonical_id": "CAN-RUNT-MULTI_AGENT_ORCHESTRATION"
      }
    ],
    "worker_pools": [
      {
        "id": "pool_agent_runtime_prod",
        "name": "Agent Runtime Production Pool",
        "pool_key": "agent_runtime_prod",
        "environment": "production",
        "status": "active",
        "worker_count": 4,
        "max_concurrency": 12,
        "current_load": 0,
        "queue_names": [
          "agent_runtime",
          "multi_agent_orchestration"
        ],
        "sandbox_policy_id": "sandbox_agent_default",
        "autoscale_enabled": true,
        "min_workers": 2,
        "max_workers": 10,
        "last_heartbeat_at": "2026-07-09T19:05:10",
        "owner": "AgentOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME_PROD"
      },
      {
        "id": "pool_provider_sync",
        "name": "Provider Sync Worker Pool",
        "pool_key": "provider_sync",
        "environment": "production",
        "status": "active",
        "worker_count": 3,
        "max_concurrency": 9,
        "current_load": 0,
        "queue_names": [
          "provider_sync"
        ],
        "sandbox_policy_id": "sandbox_provider_sync",
        "autoscale_enabled": true,
        "min_workers": 1,
        "max_workers": 8,
        "last_heartbeat_at": "2026-07-09T19:05:10",
        "owner": "Integration Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-PROVIDER_SYNC"
      },
      {
        "id": "pool_finance_controls",
        "name": "Finance Control Worker Pool",
        "pool_key": "finance_controls",
        "environment": "production",
        "status": "active",
        "worker_count": 2,
        "max_concurrency": 4,
        "current_load": 0,
        "queue_names": [
          "finance_settlement"
        ],
        "sandbox_policy_id": "sandbox_finance_strict",
        "autoscale_enabled": false,
        "min_workers": 2,
        "max_workers": 4,
        "last_heartbeat_at": "2026-07-09T19:05:10",
        "owner": "Finance Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-FINANCE_CONTROLS"
      },
      {
        "id": "pool_modelops_training",
        "name": "ModelOps Training Worker Pool",
        "pool_key": "modelops_training",
        "environment": "staging",
        "status": "standby",
        "worker_count": 2,
        "max_concurrency": 3,
        "current_load": 0,
        "queue_names": [
          "modelops_training"
        ],
        "sandbox_policy_id": "sandbox_modelops_training",
        "autoscale_enabled": false,
        "min_workers": 1,
        "max_workers": 4,
        "last_heartbeat_at": "2026-07-09T19:05:10",
        "owner": "ModelOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING"
      }
    ],
    "tool_proxies": [
      {
        "id": "proxy_crm_tool_v1",
        "name": "CRM Tool Proxy",
        "proxy_key": "crm_tool_v1",
        "target_system": "NexaCRM",
        "target_connector_id": "conn_nexacrm_sync_endpoint",
        "status": "active",
        "allowed_scopes": [
          "crm_read",
          "crm_write",
          "deal_update",
          "lead_create"
        ],
        "sandbox_policy_id": "sandbox_agent_default",
        "rate_limit_per_minute": 120,
        "require_human_approval": false,
        "invocation_count": 0,
        "blocked_count": 0,
        "last_invoked_at": null,
        "owner": "RevOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-CRM_TOOL_V1"
      },
      {
        "id": "proxy_outbound_guarded",
        "name": "Governed Outbound Tool Proxy",
        "proxy_key": "outbound_guarded",
        "target_system": "Messaging Provider",
        "target_connector_id": "conn_provider_email",
        "status": "active",
        "allowed_scopes": [
          "outbound_send",
          "campaign_launch",
          "meeting_followup"
        ],
        "sandbox_policy_id": "sandbox_agent_default",
        "rate_limit_per_minute": 45,
        "require_human_approval": true,
        "invocation_count": 0,
        "blocked_count": 0,
        "last_invoked_at": null,
        "owner": "Compliance",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-OUTBOUND_GUARDED"
      },
      {
        "id": "proxy_finance_read",
        "name": "Finance Read Tool Proxy",
        "proxy_key": "finance_read",
        "target_system": "Finance Rail Stub",
        "target_connector_id": "conn_provider_finance_rail",
        "status": "active",
        "allowed_scopes": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "sandbox_policy_id": "sandbox_finance_strict",
        "rate_limit_per_minute": 60,
        "require_human_approval": false,
        "invocation_count": 0,
        "blocked_count": 0,
        "last_invoked_at": null,
        "owner": "Finance Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-FINANCE_READ"
      },
      {
        "id": "proxy_modelops_training",
        "name": "ModelOps Training Proxy",
        "proxy_key": "modelops_training",
        "target_system": "Feature Store / Training Stub",
        "target_connector_id": "conn_modelops_training_pipeline",
        "status": "active",
        "allowed_scopes": [
          "warehouse_read",
          "feature_materialize",
          "model_evaluate",
          "lineage_scan"
        ],
        "sandbox_policy_id": "sandbox_modelops_training",
        "rate_limit_per_minute": 30,
        "require_human_approval": false,
        "invocation_count": 0,
        "blocked_count": 0,
        "last_invoked_at": null,
        "owner": "ModelOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-MODELOPS_TRAINING"
      }
    ],
    "deployments": [
      {
        "id": "deploy_agent_runtime_v56",
        "name": "Agent Runtime v5.6",
        "service_name": "agent-runtime",
        "environment": "production",
        "version": "5.6.0",
        "status": "active",
        "strategy": "rolling",
        "target_worker_pool_id": "pool_agent_runtime_prod",
        "desired_replicas": 4,
        "current_replicas": 4,
        "canary_percent": 100,
        "requires_approval": false,
        "approved_by": "Release Readiness",
        "promoted_at": "2026-07-09T19:05:10",
        "rollback_version": "5.4.0",
        "owner": "AgentOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-AGENT_RUNTIME_V56"
      },
      {
        "id": "deploy_tool_proxy_v1",
        "name": "Tool Proxy Gateway v1",
        "service_name": "tool-proxy-gateway",
        "environment": "production",
        "version": "1.0.0",
        "status": "active",
        "strategy": "blue_green",
        "target_worker_pool_id": "pool_provider_sync",
        "desired_replicas": 3,
        "current_replicas": 3,
        "canary_percent": 100,
        "requires_approval": false,
        "approved_by": "Release Readiness",
        "promoted_at": "2026-07-09T19:05:10",
        "rollback_version": "0.9.0",
        "owner": "Integration Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-RUNT-TOOL_PROXY_V1"
      }
    ],
    "jobs": [],
    "tool_invocations": [],
    "capacity_checks": [],
    "summary": {
      "worker_pools": 4,
      "active_worker_pools": 3,
      "job_queues": 5,
      "jobs": 0,
      "queued_jobs": 0,
      "leased_jobs": 0,
      "failed_jobs": 0,
      "dead_letter_jobs": 0,
      "sandbox_policies": 4,
      "tool_proxies": 4,
      "tool_invocations": 0,
      "blocked_invocations": 0,
      "deployments": 2,
      "pending_deployments": 0,
      "capacity_checks": 0,
      "failed_capacity_checks": 0,
      "overloaded_queues": 0,
      "latest_job_status": "not_enqueued",
      "latest_invocation_status": "not_invoked",
      "latest_capacity_status": "not_checked",
      "runtime_readiness_score": 100,
      "runtime_readiness_status": "healthy",
      "as_of": "2026-07-27"
    }
  },
  "orchestration_ops": {
    "agents": [
      {
        "id": "orch_agent_revenue_coordinator",
        "name": "Revenue Coordinator Agent",
        "agent_key": "revenue_coordinator",
        "status": "active",
        "role": "orchestrator",
        "skills": [
          "workflow_planning",
          "handoff_routing",
          "approval_coordination",
          "risk_triage"
        ],
        "allowed_tool_scopes": [
          "crm_read",
          "crm_write",
          "meeting_schedule",
          "quote_prepare",
          "contract_prepare"
        ],
        "default_queue_key": "multi_agent_orchestration",
        "sandbox_policy_id": "sandbox_agent_default",
        "max_parallel_runs": 5,
        "current_runs": 0,
        "owner": "RevOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-AGENT_REVENUE_COORDINATOR"
      },
      {
        "id": "orch_agent_crm_operator",
        "name": "CRM Operator Agent",
        "agent_key": "crm_operator",
        "status": "active",
        "role": "crm",
        "skills": [
          "account_enrichment",
          "lead_conversion",
          "timeline_writeback",
          "dedupe_review"
        ],
        "allowed_tool_scopes": [
          "crm_read",
          "crm_write"
        ],
        "default_queue_key": "multi_agent_orchestration",
        "sandbox_policy_id": "sandbox_agent_default",
        "max_parallel_runs": 8,
        "current_runs": 0,
        "owner": "Sales Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-AGENT_CRM_OPERATOR"
      },
      {
        "id": "orch_agent_deal_desk",
        "name": "Deal Desk Agent",
        "agent_key": "deal_desk",
        "status": "active",
        "role": "deal_desk",
        "skills": [
          "cpq_validation",
          "discount_review",
          "quote_exception_routing",
          "signature_authority"
        ],
        "allowed_tool_scopes": [
          "quote_prepare",
          "contract_prepare",
          "crm_read"
        ],
        "default_queue_key": "multi_agent_orchestration",
        "sandbox_policy_id": "sandbox_agent_default",
        "max_parallel_runs": 4,
        "current_runs": 0,
        "owner": "Deal Desk",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-AGENT_DEAL_DESK"
      },
      {
        "id": "orch_agent_finance_controller",
        "name": "Finance Controller Agent",
        "agent_key": "finance_controller",
        "status": "active",
        "role": "finance",
        "skills": [
          "invoice_review",
          "settlement_reconciliation",
          "tax_check",
          "payout_hold"
        ],
        "allowed_tool_scopes": [
          "billing_read",
          "invoice_read",
          "settlement_prepare"
        ],
        "default_queue_key": "finance_settlement",
        "sandbox_policy_id": "sandbox_finance_strict",
        "max_parallel_runs": 3,
        "current_runs": 0,
        "owner": "Finance Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-AGENT_FINANCE_CONTROLLER"
      },
      {
        "id": "orch_agent_success_manager",
        "name": "Customer Success Agent",
        "agent_key": "customer_success",
        "status": "active",
        "role": "customer_success",
        "skills": [
          "onboarding_plan",
          "renewal_risk",
          "qbr_packet",
          "support_escalation"
        ],
        "allowed_tool_scopes": [
          "crm_read",
          "meeting_schedule",
          "billing_read"
        ],
        "default_queue_key": "agent_runtime",
        "sandbox_policy_id": "sandbox_agent_default",
        "max_parallel_runs": 6,
        "current_runs": 0,
        "owner": "Customer Success",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-AGENT_SUCCESS_MANAGER"
      },
      {
        "id": "orch_agent_runtime_supervisor",
        "name": "Runtime Supervisor Agent",
        "agent_key": "runtime_supervisor",
        "status": "active",
        "role": "runtime_supervisor",
        "skills": [
          "queue_triage",
          "replay_check",
          "capacity_check",
          "kill_switch_review"
        ],
        "allowed_tool_scopes": [
          "provider_sync",
          "event_replay",
          "lineage_scan"
        ],
        "default_queue_key": "multi_agent_orchestration",
        "sandbox_policy_id": "sandbox_provider_sync",
        "max_parallel_runs": 4,
        "current_runs": 0,
        "owner": "Runtime Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-AGENT_RUNTIME_SUPERVISOR"
      }
    ],
    "retry_policies": [
      {
        "id": "orch_retry_standard",
        "name": "Standard orchestration retry",
        "status": "active",
        "max_attempts": 3,
        "backoff_minutes": 10,
        "dead_letter_after_attempts": 3,
        "escalate_on_final_failure": true,
        "compensation_required_on_failure": true,
        "owner": "RevOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10"
      },
      {
        "id": "orch_retry_finance_strict",
        "name": "Finance strict retry",
        "status": "active",
        "max_attempts": 2,
        "backoff_minutes": 20,
        "dead_letter_after_attempts": 2,
        "escalate_on_final_failure": true,
        "compensation_required_on_failure": true,
        "owner": "Finance Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10"
      }
    ],
    "workflow_blueprints": [
      {
        "id": "orch_bp_lead_to_cash_saga",
        "name": "Lead-to-cash durable saga",
        "blueprint_key": "lead_to_cash_saga",
        "status": "active",
        "category": "revenue",
        "description": "Coordinate CRM enrichment, quote prep, deal-desk review, contract handoff, invoice review, and onboarding handoff as a durable multi-agent workflow.",
        "default_retry_policy_id": "orch_retry_standard",
        "lock_resource_type": "deal",
        "requires_human_review": false,
        "default_agent_ids": [
          "orch_agent_revenue_coordinator",
          "orch_agent_crm_operator",
          "orch_agent_deal_desk",
          "orch_agent_finance_controller",
          "orch_agent_success_manager"
        ],
        "steps": [
          {
            "key": "crm_enrichment",
            "title": "Enrich account and timeline",
            "agent_id": "orch_agent_crm_operator",
            "action_type": "crm_write",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "crm_write",
            "requires_handoff": false,
            "compensation_action": "Restore prior CRM stage and annotate reverted enrichment."
          },
          {
            "key": "quote_readiness",
            "title": "Validate quote and approval posture",
            "agent_id": "orch_agent_deal_desk",
            "action_type": "quote_prepare",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "quote_prepare",
            "requires_handoff": true,
            "compensation_action": "Withdraw quote packet and reopen deal-desk review."
          },
          {
            "key": "contract_packet",
            "title": "Prepare contract packet",
            "agent_id": "orch_agent_deal_desk",
            "action_type": "contract_prepare",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "contract_prepare",
            "requires_handoff": true,
            "compensation_action": "Void staged signature packet and notify legal reviewer."
          },
          {
            "key": "finance_handoff",
            "title": "Finance invoice and settlement review",
            "agent_id": "orch_agent_finance_controller",
            "action_type": "billing_read",
            "queue_key": "finance_settlement",
            "tool_scope": "billing_read",
            "requires_handoff": true,
            "compensation_action": "Place invoice/settlement on hold and reverse simulated handoff."
          },
          {
            "key": "success_onboarding",
            "title": "Customer success onboarding handoff",
            "agent_id": "orch_agent_success_manager",
            "action_type": "meeting_schedule",
            "queue_key": "agent_runtime",
            "tool_scope": "meeting_schedule",
            "requires_handoff": true,
            "compensation_action": "Pause onboarding tasks until finance/contract recovery completes."
          }
        ],
        "owner": "RevOps",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-BP_LEAD_TO_CASH_SAGA"
      },
      {
        "id": "orch_bp_renewal_risk_save",
        "name": "Renewal risk-save orchestration",
        "blueprint_key": "renewal_risk_save",
        "status": "active",
        "category": "customer_success",
        "description": "Coordinate customer health review, support SLA evidence, renewal plan, executive packet, and escalation handoff.",
        "default_retry_policy_id": "orch_retry_standard",
        "lock_resource_type": "tenant",
        "requires_human_review": false,
        "default_agent_ids": [
          "orch_agent_revenue_coordinator",
          "orch_agent_success_manager",
          "orch_agent_finance_controller"
        ],
        "steps": [
          {
            "key": "health_snapshot",
            "title": "Collect health and usage evidence",
            "agent_id": "orch_agent_success_manager",
            "action_type": "billing_read",
            "queue_key": "agent_runtime",
            "tool_scope": "billing_read",
            "requires_handoff": false,
            "compensation_action": "Mark snapshot stale and require refreshed evidence."
          },
          {
            "key": "sla_review",
            "title": "Review support/SLA exposure",
            "agent_id": "orch_agent_finance_controller",
            "action_type": "invoice_read",
            "queue_key": "finance_settlement",
            "tool_scope": "invoice_read",
            "requires_handoff": true,
            "compensation_action": "Remove pending credit recommendation and reopen SLA review."
          },
          {
            "key": "exec_packet",
            "title": "Assemble executive renewal packet",
            "agent_id": "orch_agent_revenue_coordinator",
            "action_type": "crm_read",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "crm_read",
            "requires_handoff": true,
            "compensation_action": "Archive draft packet and notify customer-success owner."
          }
        ],
        "owner": "Customer Success",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-BP_RENEWAL_RISK_SAVE"
      },
      {
        "id": "orch_bp_runtime_incident_saga",
        "name": "Runtime incident recovery saga",
        "blueprint_key": "runtime_incident_recovery",
        "status": "active",
        "category": "operations",
        "description": "Coordinate kill-switch review, replay validation, capacity check, runtime job recovery, and stakeholder update.",
        "default_retry_policy_id": "orch_retry_standard",
        "lock_resource_type": "runtime_resource",
        "requires_human_review": true,
        "default_agent_ids": [
          "orch_agent_runtime_supervisor",
          "orch_agent_revenue_coordinator"
        ],
        "steps": [
          {
            "key": "kill_switch_review",
            "title": "Review scoped kill switches",
            "agent_id": "orch_agent_runtime_supervisor",
            "action_type": "event_replay",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "event_replay",
            "requires_handoff": false,
            "compensation_action": "Reinstate kill switch if replay evidence fails."
          },
          {
            "key": "capacity_recheck",
            "title": "Run capacity and queue-depth check",
            "agent_id": "orch_agent_runtime_supervisor",
            "action_type": "provider_sync",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "provider_sync",
            "requires_handoff": false,
            "compensation_action": "Pause automation schedule and reopen incident route."
          },
          {
            "key": "stakeholder_update",
            "title": "Publish stakeholder recovery update",
            "agent_id": "orch_agent_revenue_coordinator",
            "action_type": "crm_read",
            "queue_key": "multi_agent_orchestration",
            "tool_scope": "crm_read",
            "requires_handoff": true,
            "compensation_action": "Send corrected recovery note and add audit annotation."
          }
        ],
        "owner": "Runtime Operations",
        "created_at": "2026-07-09T19:05:10",
        "updated_at": "2026-07-09T19:05:10",
        "canonical_id": "CAN-ORCH-BP_RUNTIME_INCIDENT_SAGA"
      }
    ],
    "workflow_runs": [],
    "workflow_steps": [],
    "state_locks": [],
    "handoffs": [],
    "compensation_runs": [],
    "decisions": [],
    "summary": {
      "agents": 6,
      "active_agents": 6,
      "workflow_blueprints": 3,
      "workflow_runs": 0,
      "active_runs": 0,
      "completed_runs": 0,
      "blocked_runs": 0,
      "workflow_steps": 0,
      "failed_steps": 0,
      "retrying_steps": 0,
      "state_locks": 0,
      "active_locks": 0,
      "lock_conflicts": 0,
      "handoffs": 0,
      "pending_handoffs": 0,
      "compensation_runs": 0,
      "open_compensation_runs": 0,
      "retry_policies": 2,
      "latest_run_status": "not_started",
      "latest_compensation_status": "none",
      "orchestration_readiness_score": 100,
      "orchestration_readiness_status": "healthy",
      "as_of": "2026-07-27"
    }
  }
}