{"schema":"veilos.promises-ledger.v1","ok":true,"counts":{"total":10,"pending":7,"kept":2,"overdue":0,"released":0,"undischargeable":1,"unknown":0},"human_twin":"/promises","promises":[{"id":"node-only:veil/crossing.mjs","status":"pending","reason":"due at S270; currently S262","due":{"kind":"session","value":270},"discharge":"entry removed from NODE_ONLY_MODULES, or recheckSession advanced with a decision","decision":"D-S260.5","owner":"founder","promise":"Recheck the owned gap in veil/crossing.mjs: the Phase-0-manifest-pinned crossing entry point; engine.crossVeil (its only implementation) is Node-lane-only, so no veil crossing is ever policy-evaluated or recorded at the edge. Whether to build an edge policy-evaluation twin (receipts, quarantine, telemetry with real traffic) is a product decision, not a refactor."},{"id":"record:no-control-characters","status":"pending","reason":"undated promise — recorded, never judged","due":null,"discharge":"tests/s260-carrier-and-vocabulary.test.mjs control-character ratchet over the record surfaces","decision":"D-S260.8","owner":"agent","promise":"Record prose is written with the editor or via a file, never through shell interpolation — PowerShell reads the backtick as an escape introducer and eats the first character of every Markdown code span. D-S250.32 promised this in prose and it recurred ten sessions later."},{"id":"parity:unbacked-claims-shrink","status":"pending","reason":"undated promise — recorded, never judged","due":null,"discharge":"tests/s250-parity-claims.test.mjs BASELINE_UNBACKED monotone ceiling","decision":"D-S250.59","owner":"agent","promise":"Every comment claiming parity with a named module or symbol must actually READ that counterparty; the population that does not is debt and may only ever shrink."},{"id":"upstream:writeback-currency-root","status":"pending","reason":"undated promise — recorded, never judged","due":null,"discharge":"upstream scripts/check-writeback-currency.mjs resolves root from git or cwd","decision":"D-S260.4","owner":"founder","promise":"The control plane's write-back currency probe resolves its repository root from its own module path and can therefore only measure studio-ops. The corrected resolution was shipped as Ark cargo so every sibling can inherit it; VEILOS no longer waits on it."},{"id":"outward-claim:every-crossing-is-policy-evaluated","status":"kept","reason":"discharged by either an edge twin evaluates crossings, or the ip.mjs sentence is rewritten to describe what production actually does — asserted by a test that drives the live","due":{"kind":"session","value":265},"discharge":"either an edge twin evaluates crossings, or the ip.mjs sentence is rewritten to describe what production actually does — asserted by a test that drives the live","decision":"D-S261.3","owner":"founder","promise":"src/worker/ip.mjs publishes, to the public: \"Every crossing is policy-evaluated and produces a signed verdict; nothing crosses unwitnessed.\" That is FALSE in production. crossVeil — the only implementation of the faculty — is Node-lane only, so no crossing at the edge is ever policy-evaluated, no verdict is ever signed, and state.veilCrossings is permanently empty. The sentence is not aspirational"},{"id":"veil:edge-trigger-decision","status":"pending","reason":"due at S270; currently S262","due":{"kind":"session","value":270},"discharge":"a trigger is chosen and recorded as a decision, or the faculty is retired","decision":"D-S261.4","owner":"founder","promise":"Decide what edge event constitutes a veil crossing, so the faculty can reach production. S261 proposed shadow mode (evaluate and record, deny nothing) as a way to convert the enforcement question into a measurement — and that proposal was too strong, which is recorded here rather than quietly dropped: shadow mode still requires a TRIGGER, and choosing the trigger is precisely the product decision "},{"id":"release:responsive-evidence-reason-split-enumerates","status":"pending","reason":"due at S266; currently S262","due":{"kind":"session","value":266},"discharge":"the reason classification is derived rather than enumerated, with deploy.mjs's refusal verified BEFORE the suite is relaxed and asserted after — or a real deplo","decision":"D-S262.2","owner":"agent","promise":"D-S259.3 split responsiveEvidenceCurrent by REASON rather than force-greening it, and that was right. But it enumerated ONE tolerable reason — build_sha_mismatch — and a second reason that is equally deploy-gated sits outside the classification. S262's suite reds on verified_at_stale: the cached capture has simply aged out, and only a fresh Playwright run against a real deploy can clear it. That i"},{"id":"guard:parity-scan-has-no-quote-rule","status":"pending","reason":"due at S268; currently S262","due":{"kind":"session","value":268},"discharge":"parityScan gains a quote-disqualifier with a control proving a quoted claim does not red and an asserted one still does","decision":"D-S261.7","owner":"agent","promise":"The parity guard reads a QUOTED example of a parity claim as a real claim. Found live at S261: a comment in src/core/obligations.mjs quoting an illustrative claim reddened the guard, because the claim form is verbatim identical whether it is asserted or merely recounted. This is the same blind spot D-S260.7 fixed in the production-claim predicate, where the rule adopted was that a quotation mark i"},{"id":"placement:coherence-gate-runs-last","status":"kept","reason":"discharged by tests/s258-production-sha-carriers.test.mjs asserts steps.at(-1) === 'closeout:coherence' against the autopilot's own parsed step list","due":null,"discharge":"tests/s258-production-sha-carriers.test.mjs asserts steps.at(-1) === 'closeout:coherence' against the autopilot's own parsed step list","decision":"D-S258.3","owner":"agent","promise":"The closeout coherence gate runs LAST, on the final tree, right before commit — a claim stated in three files at once, and false for seventeen sessions (D-S258.3): the gate was on none of the autopilot's eleven steps while every one of those three comments said it ran."},{"id":"founder:outward-claim-class","status":"undischargeable","reason":"no discharge predicate — this promise is recorded but nothing can decide it","due":null,"discharge":null,"decision":"D-S256.7","owner":"founder","promise":"THE OUTWARD CLAIM CLASS — scope decision remains founder-owned and unstarted."}]}