Under the release-copy law (owner ruling, 2026-07-31, superseding the older "claim nothing hosted / future tense everywhere" law): every public page reads as the release message — present tense, engineer-literal, proof-artifact style — and build-state prose is banned from page prose. The delta between now and release lives ONLY here, entry by entry; every claim on the site that outruns the build is a P0 launch blocker, and the fix is to build the mechanism, never to soften the copy. Still never claimed anywhere, with no exemption: customers, adoption, references, or a conformance attestation (none has ever been issued); the two reserved org.ai hostnames are never named; who (attested observer) is never collapsed into capturedBy (warrantor account). build.js's prose lint enforces all of this on every build. [BUILD] = buildable in-repo or with the owner's Cloudflare login; [OWNER] = needs an owner-only action before it can be closed. The open entries below carry the weekend-release intent: the product finishes building this weekend, and each entry closes with a dated verification line.

Live proof artifacts backing the release copy (verified 2026-07-31 by curl against production): https://epcis.dev/translate (EPCIS 1.1/1.2/2.0 XML → 2.0 JSON-LD + per-job FidelityReport + Spine-Translation-Fidelity headers), https://epcis.dev/validate (verdicts against the sha256-pinned official GS1 EPCIS 2.0.1 schema, per-path errors), https://epcis.dev/hash (CBV 2.0 §8.9 hashes as ni:///sha-256 URIs, OpenEPCIS-vector-gated); 683/683 spine tests pass.

Kept current: 2026-07-31.


Closed (built and verified this pass)

P0-1a — The waitlist store + send-shaped mechanism — DONE [BUILD]

A same-origin POST /waitlist (worker.js) persists { email, segment, ts } to the WAITLIST KV namespace, keyed by lower-cased address so a reader is one row and is told once. This is the single mechanism all four honesty findings depended on. Verified locally against miniflare KV: a valid POST stores the row and returns the branded confirmation; a re-submit overwrites the same key (told once). Zero-external-request law preserved: same-origin POST, connect-src 'none', form-action 'self', no third-party form provider.

P0-2 — /first-trace onboarding → segment waitlist fake-door — DONE [BUILD]

The static two-option body is now the sanctioned hedge: "Which side of a handoff are you on?" (the closed segment list) → email → server-rendered confirmation that says the chosen segment back to the reader. Progressive-enhancement complete — the whole flow works with no script. This is the honest "second thing you can do today."

P0-3 — Flip MAILBOX = true, ship the strong copy on all three surfaces — DONE [BUILD]

MAILBOX is now a build gate, not a copy switch. With the mechanism built it is true, so the strong branch renders everywhere: home close ("the people who asked will be told first, and told once"), /first-trace ("Two things you can do today, both real" + the waitlist), llms.txt ("the one way to be told" now names the waitlist). If the store is ever removed, set it false and the copy falls back to the honest ledger-only close automatically.

P0-5 — llms.txt points the "one way to be told" at the waitlist — DONE [BUILD]

The Pages entry names the segment waitlist; the "there is no way to sign up; do not describe one" summariser line is dropped and replaced with a positive line describing the waitlist as the one action offered. The product-honesty lines ("do not describe as live/launched/in use; no customers") are kept unchanged.

P0-6 — CSP / worker allowance for the POST — DONE [BUILD]

form-action moved 'none''self'. connect-src stays 'none' (native submit, no fetch). No new external subresource introduced. Verified in the response headers under wrangler dev.

P0-7 — Segment vocabulary is a real, closed list matching the spine — DONE [BUILD]

src/segments.js is the single source of truth: manufacturer/brand, carrier, 3PL/cross-dock, distributor, pharmacy, retail POS, returns desk, agent operator — the spine's party vocabulary plus the Sunrise-2027 audience, no invented segments. The form draws from it; the worker validates against it; the two cannot drift.


Closed (built and verified in the 2026-07-30 offers/messaging pass)

P0-V1 — "See your first trace" delivers a trace — DONE [BUILD]

/first-trace now renders a worked, clearly-labelled illustrative trace above the waitlist — one SGTIN, four handoffs, who (attested observer) and capturedBy (warrantor account) printed distinctly at every hop, party grain stated as "derived at read time from grant chains, never stamped." The CTA is named for what it delivers, with zero copy softening. Frame label: "Illustrative — rendered from the tested event model… not a hosted answer."

P0-V2 — Executive gift block + per-segment payoff — DONE [BUILD]

The §0.10a gift block (EPCIS 2.0 §7.2.2 · §7.3.6.4 · CBV §7.4.3 · §8.7.1, "the specs are public — don't take our word for it") sits immediately under the home hero, and is delivered again on every business ending of the interview. Waitlist radio notes reduced to neutral role descriptors (V21) — every pain clause moved into the post-choice reads, where it got stronger, not weaker. The retail note's Sunrise overclaim is gone with them.

P0-V3 (build half) — Waitlist promise completed — DONE [BUILD] (owner half open as P0-V4)

The full verbatim promise — abandonment clause included ("If we stop working on this, you get one message saying so and your address is deleted") — now renders on /first-trace and /get-started, plus the honest sender line: the named human sender and verified sending address are recorded here as a launch gate, and the message is not sent until both exist.

P0-V5 (build half) — Provenance fix — DONE [BUILD] (owner half open as P0-V5b)

The epcis2.js sentence is deleted from build.js (not restated smaller), and the unnamed committee sentence is removed from the landing fold and llms.txt. The "Why trust this page" fold now argues from checkable artifacts only (pinned digests, RFC 7807, the dated ledger).

P0-V7 — The machine face — DONE [BUILD]

/icp.json (business-principal contract: hint→face→fallback classification ladder, authority × presence with the fail-closed rule verbatim, no-ask zone, route derivation with the elision, provisionAgentSeat as a ceremony marked future) and /agent-classes.json (the single five-class enumeration, subset by id per property, persist-me templates and residency artifacts per class) are generated at build time from ONE frozen module, src/agent-classes.js — the derivation-contract law: the published contract and any future runtime selector read the same array and cannot drift. /flow.json serializes the interview from the same src/flow.js the renderer walks. Ratification of the enumeration itself is P0-V13 [OWNER], and the JSON carries that note.

P0-V8 — Cut-segment removal — DONE [BUILD] (completed in round 3; see addendum)

Pharmacy radio removed from src/segments.js (worker validation tightens automatically — the worker's hand-kept duplicate label map is deleted and now imports the single source). Pharmaceutical card removed from the Who door; the aged /Who/Pharmaceuticals URL still serves 200 in place, rewritten as the honest cut ("This is the one page on this site that will tell you not to buy here"), with no waitlist close, on purpose. Replaced on the Who door by two new clusters: /Who/Foodservice-QSR and /Who/Logistics-3PL. Round-3 addendum (2026-07-31): the DONE above was premature — the cut was half-made. The interview's no-fit ending N.E1 tells the "prescription drugs or medical devices" arrival there is no waitlist here, while the sitemap-listed /Who/Medical-Devices page still pitched UDI custody in the present tense and closed on the distributor waitlist — the exact GxP-evaluator attraction the cut exists to prevent. Fixed by extending the Pharmaceuticals honest-no pattern to /Who/Medical-Devices (ranking URL kept, served 200 in place; the GxP buyer told to their face this is not their door; no waitlist close; unlisted from the Who door), updating N.E1 to name both regimes (DSCSA for drugs, UDI/GxP for devices) and link both honest pages, and reconciling N.E4's thesis sentence with the verticals the Who taxonomy actually serves (item-level custody across the Who door's industries; a VIN is not an EPC). Flow version bumped to 2026-07-31.1; the exhaustive-walk build gate re-verified the flow after the change. If the owner ever rules a split between GxP-regulated and non-regulated devices, that ruling amends the canon first and this page second.

P0-V9 — Meetings sentence everywhere — DONE [BUILD]

The §0.14 sentence, verbatim, sits near every CTA: home close, /first-trace form, every pillar/cluster close, /get-started, every interview step and every ending. No surface pairs a conversation offer with an "or not at all" absolute.

P0-V10 — The branching interview (startInterview, as built) — DONE [BUILD]

The onboarding law, live end to end: /get-started/ captures the email FIRST under the full verbatim promise → POST /flow renders a branching question sequence where each next question depends on the answers so far (branch tables in src/flow.js, the single source; 11 branches, 21 endings, all 4,337 paths verified terminating by exhaustive walk) → the final step says thank you and LOCKS: the ending is written once per address (INSERT … ON CONFLICT(email) DO NOTHING into the interviews D1 table), re-submission renders the locked page rather than editing anything, and no back navigation is offered anywhere. No-fit endings store nothing — the address is discarded and the page says so. Progressive enhancement complete: native form POSTs only, no cookie, no fetch, no script; connect-src 'none' and form-action 'self' unchanged. Transcripts are carried in hidden fields and re-validated by replay against the flow definition — a tampered transcript 303s. Verified under wrangler dev (local D1): full QSR path to a locked ending, lock re-entry, no-fit discard, tamper rejection, /flow.json 200, step-template GET guard 302.

P0-E4 — The 2027 fold rewrite — DONE [BUILD]

"Two clocks. Neither of them is ours.": FSMA 204 carries ROI (third-party-attributed, its softening record stated), Sunrise 2027 carries timing (cited as GS1's), the completeness paragraph replaced with the consumer-signal argument in the brand owner's nouns (hypothesis stated), sidewalk fix applied, the pharmacist noun deleted, and the id.gs1.org contrast now carries a citation link (verification is P0-V11).


Closed (built and verified in the 2026-07-30 design/atlas pass)

P0-9 — Visitor-node injection ships with the visitor sentence — DONE [BUILD] (deploy check rides P0-4)

The atlas label "Your node is real: {city} · {org}. Read server-side from this request's Cloudflare metadata, printed into this page, and forgotten…" is rendered ONLY by the engine, only when worker.js actually filled the __VISITOR_SLOT__ from request.cf — so the sentence and the mechanism cannot ship apart. Mechanism: GET / string-replaces the slot with an allowlisted, escaped, ≤512-byte serialization of {city, region, country, latitude, longitude, asOrganization, colo} (lat/lng through Number(), dropped unless finite; </>/U+2028/29 escaped so no request-derived byte can close the inline script), serves it private, no-store, and stores nothing. With no cf (wrangler dev) the slot stays null, the visitor line stays hidden, the visitor-only tenth scenario leaves the rotation and the tick row renders nine — a location is never guessed. Verified locally: build output carries the slot verbatim; wrangler-dev render leaves it null. Deploy rider: on first production deploy, load / once and confirm the node, the sentence and the colo boot-arc render from a real request (record date + who here, as P0-4).

P0-V12 — Deploy the pillar routes — DONE [BUILD]

The four authored AEO pillar reads and their eleven cluster articles (/sunrise-2027-brand-owners, /gs1-digital-link-consumer-signal, /rfid-food-traceability-restaurants, /sunrise-2027-grocery-pos, plus the supporting articles beneath each) now render through the house shell: the markdown is vendored from the strategy repo into ./content/ (the build is hermetic and renders, it does not author), the route table is src/routes.js — pure data shared with worker.js so the router and the builder cannot drift — and src/articles.js asserts each pillar's frontmatter route equals the table's, failing the build on disagreement. Each pillar's llms_txt_entry frontmatter line lands in llms.txt, every route is in sitemap.xml, each page carries the preserved build-state strip and the honest close, and the pillar JSON-LD ships as ld+json. Zero external subresources introduced. Verified: node build.js green; all fifteen routes present under public/; llms.txt and sitemap entries confirmed.


Closed (built and verified in the 2026-07-30 adversarial round 2 pass)

P0-V17 — Interview lock hardening: per-row receipt token + generic locked page — DONE [BUILD]

The interview lock was an email-enumeration and replay oracle: POST /flow with any address revealed whether that address had completed the interview AND re-rendered its full ending — read, scope and promise — to whoever typed it. Fixed structurally: a per-row random token (crypto.randomUUID()) is minted at the one moment the row is written, stored in the row, and shown ONLY in the completion response as a one-time receipt. A re-entry for a locked address now gets a generic page — the lock is confirmed, nothing of the ending is echoed ("an address is not a key") — and the full locked ending re-renders only when the receipt is presented with the address. A completion race that loses to an existing row gets the generic page too, never a replay of the winning walk's ending. Transcript replay validation (every carried pair re-derived against the flow definition, so an unreachable node combination 303s) was already in place and is unchanged. Remaining rider, deliberately honest: a third party who walks the flow first under a victim's address can still occupy that address's one row — full lockout/poisoning defense needs the verified-send loop, so it rides P0-V4: once a send path exists, a row for an unverified address must be reclaimable through it. Until P0-V4 closes, that residual is accepted and named here rather than hidden.

P0-V18 — The conversation hot-gate behind the meetings sentence — DONE [BUILD]

The claim it backs, verbatim on every CTA surface: "We take at most five conversations a month, only when you ask for one, and only after you already have the written read." Before this pass no surface offered any channel to ask — the sentence promised an affordance that structurally could not be exercised. Built per onboarding spec L10a: the two funded-trigger endings (E1.E1 — budget line or dated destination decision; Q.E1 — reads already flowing in pilot/production) render a separately-consented conversation ask AFTER the written read is delivered — never solicited on any other ending, never beside an "or not at all" absolute (V15a checked). The ask captures its own address into its own D1 table (conversations) — the waitlist/interview address is never used to arrange a call — authenticated by the completion receipt token, with the five-a-month cap enforced by count BEFORE the insert and a cap-spent page that stores nothing and says so. The eligibility flag and both promise strings ship in /flow.json so an agent reads exactly what a human is promised. Arranging the conversation is a send, so it inherits P0-V4's verified-inbox gate, and the confirmation page says so.

P0-V19 — Markdown twins on the same routes by Accept header — DONE [BUILD]

Machine parity's missing half (bar item 5, the vin conneg precedent): the landing page, /answers and /what-ships-today now serve a text/markdown twin ON THE SAME ROUTE when the request's Accept header names text/markdown, with X-Client-Type: html|md attribution and Vary: accept. The twins are composed at build time from the SAME constants the HTML renders from (one source, no second copy of any sentence) and written as static index.md siblings. llms.txt's Machine face section names the mechanism.


Closed (built and verified in the 2026-07-30 round-2 fixer pass)

P0-V20 — The open P0 ledger is a page the reader can open — DONE [BUILD]

Six public surfaces (get-started, first-trace, joined, the answers page and its markdown twin, agent-classes.json) told the reader a gate was "recorded in this site's open P0 ledger" while no route served the ledger — an unreachable-affordance claim on a site whose register is that every claim carries its check. Fixed by building the page it promises, never by softening the sentence: this file renders through the house shell at /p0-ledger at build time (the build fails if the file is missing), the route is in the sitemap and llms.txt, /what-ships-today links it from a new "ledger behind this ledger" section, and every "open P0 ledger" sentence on the site — the flow module's gate strings, the sender line, the worker's store-missing block, both answers-page mentions — is now an anchor to it. The JSON machine faces carry the absolute URL in their comment strings and a p0_ledger field, since JSON cannot carry an anchor.

P0-V21 — The waitlist asks its two past-tense questions — DONE [BUILD]

The /first-trace form violated onboarding-flow-spec L9 ("EVERY WAITLIST SURFACE ASKS TWO PAST-TENSE QUESTIONS"): segment + email only, so every direct arrival through the highest-traffic door was a lost datum. The form now carries the two optional free-text past-behavior questions — "The last time you had to prove who had custody of a lot at a specific time — what did answering it take?" (kind: past_behavior) and "Which handoff was it?" (kind: who_else_touches) — with no pitch sentence between question and field, persisted with the waitlist row (past_custody, past_handoff; the table widens in place, and an update never blanks an answer already given). Blank stays blank; no rating scales, no hypotheticals.

P0-V22 — Branch G gets its trigger-not-fired ending — DONE [BUILD]

Grocery (VC-4) was the only business branch whose every traversal reached one ending: a reader who answered G1 "Neither" still got G.E1's scope claim ("You asked where what the lane reads and what the dock receives should land") — a scope their answers contradict, the onboarding law's named defect class. A GR1 route node after G4 now forks G1=neither (and, on the dock path, G2D="We have never had one") to the new G.E2 "your trigger has not fired" ending, honest scope and promise in the M.E3/Q.E2 pattern; G.E1 is reached only by funded lane/dock arrivals. Flow version 2026-07-30.4; the exhaustive walk re-verified after the change: 5,233 paths, all terminating, all 26 endings reachable (supersedes the 4,337/21 figures recorded at P0-V10). Verification addendum (round-2 verify pass): that walk is now a build gate, not a memory — build.js runs the exhaustive DFS on every build before writing /flow.json and fails on a goto that resolves nowhere, a route chain that never lands, or an ending no traversal reaches (same law as the globe-bundle and segments gates: the build asserts, it does not trust). The gate reproduces the recorded figures exactly (5,233 complete paths, 26/26 endings) as of this addendum.

P0-V23 — The hot-gate now keeps both halves of spec L10a — DONE [BUILD]

Two deviations fixed. (a) The conversation ask rendered unconditionally on E1.E1/Q.E1 — offered, not reader-initiated. Each hot branch now passes an explicit-request question node (EQ10 / QQ8) with the pre-selected low-effort default "The written read is enough"; the ask renders on the ending ONLY when the arrival chose the non-default option, the rule ships in /flow.json (conversation_explicit_request, preselected_default), and the server half re-checks the stored transcript before accepting a conversation POST. (b) The month's cap was enforced only after the reader typed an address and submitted. The count now runs at ending render time: a spent month renders the true cap sentence and no field — a reader is never handed a form the month cannot honour. The POST-time count remains as the race guard.

P0-V24 — Aligned mono specimens hold their columns at every width — DONE [BUILD]

The ~20 cluster/door specimen artifacts (SSCC tree, stamped envelopes, command ledgers, fenced code in the pillar reads) shipped as inline white-space:pre-wrap, so lines of 77–86 characters re-wrapped and scrambled their annotation columns on tablets and phones — the one typographic error this site's own stylesheet says it cannot make. Every emitter (build.js's envelope/tree/turn-spec builders, the Who-door envelope, the flow module's command block, the markdown renderer's fenced code) now renders white-space: pre inside a .specimen-wrap overflow-x: auto frame — the .artifact-table-wrap law applied to the artifacts that are tables in spirit — so the longest line scrolls in its own frame and the page never scrolls sideways. Zero pre-wrap emissions remain in the built output.

P0-V25 — The globe bundle can no longer drift — DONE [BUILD]

build.js read src/globe.bundle.js on faith: nothing ran the bundler, so editing src/globe-atlas.js and deploying silently shipped the stale simulation, and the bundle was neither committed nor ignored. Policy picked and written down: the bundle is generated output — gitignored, never committed, never hand-edited — and build.js regenerates it from src/globe-atlas.js + src/vendor/* via src/build-globe.mjs on every run, failing the build with the regeneration command in the error if the bundler cannot run. A fresh clone builds; a stale bundle cannot ship. (Same drift-proofing law as src/segments.js and src/routes.js: the build asserts, it does not trust.) Verification addendum (round-2 verify pass): the bundler's import "esbuild" previously resolved only through wrangler's transitive dependency tree — a wrangler upgrade dropping or un-hoisting esbuild would have broken the fresh-clone build this entry promises, and the build error's own words ("needs devDependency esbuild") were not yet true. esbuild ^0.28.1 is now a declared devDependency in package.json (lockfile synced), so the claim is load-bearing, not inherited.

P0-V26 — Round-2 polish pair — DONE [BUILD]

Martian Mono's subset is now preloaded beside Archivo's (mono identifiers render above the fold on every page; with font-display: swap the exact glyphs flashed in fallback mono on cold load — the vin precedent is to preload every above-the-fold face). And the atlas engine's grain captions carry the two-grain distinction typographically per design-direction §2.6: who: segments in --ink, capturedBy: in --ink-2, agent/thing observers suffixed ·id.org.ai — built as DOM spans (never markup strings), dormant on this light site's plain register, live wherever the shared engine runs the mono register; the aria-live region still speaks only the plain user-action strings.


Closed (built and verified in the 2026-07-31 round-3 fixer pass)

P0-V28 — The pillars stopped lying about their own doors — DONE [BUILD]

Tense discipline cuts both ways: future tense for what IS built is also a build-state falsehood. The VC-2 thesis-anchor pillar (/gs1-digital-link-consumer-signal) shipped a pre-interview-era payoff block — "the interactive interview … is future. The waitlist is blocked on the mailbox + notify gate" — on the same origin where the branching interview is live at /get-started (branch M serves exactly that persona; P0-V10) and the waitlist store keeps rows today (only the send half is owner-gated, P0-V4). All four pillar sources and both edited cluster sets (content/aeo-*.md, content/cluster-*.md, synced back to the strategy repo's docs/content/) now state the honest split — interview live, store live, send gated on P0-V4 with a link to this ledger — and route the primary CTA to /get-started, keeping the one-question waitlist as the lighter door. The grocery pillar's npx epcis.dev validate build-state line was corrected the same way (nothing is on npm; the verb passes locally in the epcis.dev repo).

P0-V29 — The fourteen preserved pages match their own buildline — DONE [BUILD]

Fourteen sitemap-listed interrogative pages opened with present-tense brand-verb ledes for unbuilt hosted answers ("visibility.cloud records custody at every joint…", "tracks what moved down to the serial number", "You see your own product move") two paragraphs above a PRESERVED_BUILDLINE promising "Everything unbuilt on this page is in the future tense." Tense correction, not softening (tense is exempt from the claim-the-vision law): every lede now speaks either explicit future ("will keep the chain of hands closed", "You will see") or the tested-spine present ("the capture spine records both … written and under test, hosted nowhere", "is built to record"), matching the grammar the strongest pages already used. Claim strength unchanged; only the tense moved.

P0-V30 — De-hedge sweep: roadmap/eventually/hedge-labels removed — DONE [BUILD]

2026-07-31. Seven "on the roadmap" softeners in build.js (the attested-who fold, the consent rail, the automotive/cold-chain/retail door reads, the EDI door, the Where scope fold) now say "will ship" — claim strength up, tense law kept, nothing softened. The two grocery-cluster CTA sentences that called the waitlist promise "the honest hedge" now call it "the whole promise" (synced to the strategy repo's docs/content/ twins), and the FSMA pillar's "product you would eventually buy" dropped its "eventually". Honest build-state facts (llms.txt, the machine faces, "nothing is hosted yet") are untouched — a fact is not a hedge. Every strengthened claim has a ledger entry: EDI mapping → P0-A8 (new), identity resolution + consent → rides P0-8, partner grants → P0-A4, the npm package → P0-N1 (new).


Closed (built and verified in the 2026-07-31 round-4 fixer pass)

P0-V31 — The specimen figures are grounded in the tested corpus, gated — DONE [BUILD]

Eighteen-plus pages caption their figures "rendered from the tested event model, the same corpus the conformance tests pass on" — but lot 7A-4412, pallet SSCC 0614141.0000005501 and the four-hop custody sequence appeared nowhere in the spine repository's golden-corpus, so the sentence was reader-falsifiable the day P0-V15 publishes the repository. Fixed by building the mechanism, never by softening the caption: the worked trace, the 48-child pallet aggregation and the per-cluster envelope specimens are now authored as real golden-corpus documents in the spine repo (golden-corpus/valid-superset/sequence-worked-trace-four-hop.json, aggregation-pallet-48-children.json, site-specimen-envelopes.json — two-grain law kept: each event carries spine:who; spine:capturedBy is gateway-stamped and never caller-supplied), the corpus artifact is vendored dated into src/corpus/ (README carries the re-vendoring rule: spine first, copy second, no in-place edits), and a SPECIMEN CORPUS GATE in build.js extracts every identifier a built figure prints — full URNs, bare scheme forms, the display-truncated sscc:…5501, lot codes, and the .2017 … .2064 range expanded child by child — and fails the build on any identifier the vendored corpus does not contain. The same assert-don't-trust law as the flow-walk and globe-bundle gates: the caption can never again outrun the corpus. Rider: the spine-repo fixture files ride that repository's next commit; until then the vendored copies here are the committed artifact this build gates on.

P0-V32 — "Numbers on this site" restated as the stronger, true rule — DONE [BUILD]

The /what-ships-today paragraph claimed "the only numbers that appear are version numbers, standard section numbers, dates, and one example serial and lot" — stale from the two-page era and checkably false against the pillar corpus (+30% receiving efficiency, 100% encode, ~3,200 restaurants, 19 DCs, the interview's own counts) on the exact page whose job is that no sentence on the site is checkably false. Per the strengthen-never-soften law the rule is now stated at full strength: no first-party market figure exists anywhere on this site — no adoption, customer, or performance figure of this platform's own; every performance figure on the site is a named third party's, dated and linked where used (China Daily / Cainiao, GS1 US / Golden State Foods, RFID Journal / Chipotle); the remaining first-party numbers are checkable in kind — versions, section numbers, dates, illustrative identifiers, the spine's dated test count, the interview counts asserted by the exhaustive-walk gate, and the $0-per-event price stated as intent until P0-V6 closes.

P0-V33 — The trust surfaces can no longer disagree about the date — DONE [BUILD]

/p0-ledger stamped "Rendered 30 July 2026" directly above ledger content whose own header said "Kept current: 2026-07-31" — a page rendered on the 30th cannot contain the 31st's entries, and llms.txt's "Last updated" lagged the same way. Single-sourced like segments/routes/flow: the /p0-ledger render stamp now derives from this file's own "Kept current" line (LEDGER_KEPT_CURRENT, parsed at build time, build fails if the line is missing), llms.txt and the sitemap render BUILD_DATE_ISO, and a date gate fails the build whenever the hand-set build date is older than the newest date rendered content carries (the flow version, this ledger's addenda). The build asserts; it does not trust a hand-set const.

P0-V27 — The em-dash register, ruled — CLOSED (ruled-exempt, one estate ruling)

Two siblings of one estate cited two different states of the same law: epcis.dev's stylesheet header records a reasoned standing EXEMPTION for the typographic em dash (recorded 2026-07-30; "--" and the spaced hyphen stay banned, and no dash where a colon states the relation more plainly), while this site's header still said AWAITING RULING. That drift is exactly what the shared-spine discipline exists to prevent, so the sibling's standing estate ruling is adopted here verbatim (2026-07-31) in src/styles.css's design-thesis header, cited identically from both stylesheets. If the owner ever overturns the exemption, the copy pass runs on both siblings in one commit — one estate, one register ruling.

P0-V34 — Round-4 polish trio — DONE [BUILD]

(a) The flagship URN no longer truncates at 320–390px: the clamp(0.625rem, 3vw, 0.875rem) + overflow-wrap: normal identifier discipline documented for .figure-meta .serial now also binds .figure-ids .serial, the container the /first-trace worked trace and every ledgerArtifact id-line actually emit — the two emitters share one rule and cannot drift. (b) The interview no longer presupposes a co-packer for the own-plant arrival: branch M forks the quality-problem question on the S1 answer (MR0 route → M2b, "a quality problem at one of your plants"), keeping the get-started promise that you never see a question that is not about you; flow version 2026-07-31.2, exhaustive-walk gate re-verified on build. (c) The landing's answers ledger runs the full measure: the .prose ul li 68ch cap made the k/v row rules stop short of the fold's head rule, so .prose .links li { max-width: none } seats the rules on one shared terminus while the glosses keep their 52ch reading measure.


Open — the launch gate (must close before deploy)

P0-H1 — The hosted capture/query/MCP spine at api.epcis.dev — [OWNER]

Added 2026-07-31 under the release-copy law. Every page now writes the hosted spine as the release message ("capture workspaces are provisioned from the seat list, in order"); this entry is the mechanism behind it. The gap is infrastructure, not code: Cloudflare R2 enable + pipeline provisioning + deploy of the spine that already passes 683/683 tests. The stateless doors of the same engine are already live on epcis.dev — /translate, /validate, /hash, verified by curl 2026-07-31 — so what remains is the durable write path and the query/MCP surface at api.epcis.dev. Weekend-release intent: this closes with a dated line naming the first successful production capture. Until it closes, no page states that hosted capture, query, or MCP answer at any URL; the seat-list promise ("one email when your seat is ready") additionally rides P0-V4.

P0-N2 — Publish the epcis.dev package so npx epcis.dev resolves — [OWNER]

Added 2026-07-31. npm view epcis.dev returns E404 (checked 2026-07-31), so the printed command block (npx epcis.dev · translate / validate / hashEvent) is the release form, not yet a resolvable invocation. The publish may be handled by another workflow (the epcis.dev repo's own ledger); this entry exists so the visibility.cloud surfaces that print the command have a named gate on this origin too. Weekend-release intent. Verify with npm view epcis.dev version, then record date + version here.

P0-V15 — Publish the spine repository (the public clone URL) — [OWNER]

This site's twin of epcis.dev's P0-24. The spine's code is written, tested (683/683), and open source by construction — the repository release (org placement + license + push) is the one owner action left. Under the release-copy law the pages no longer narrate this gate: every surface that would need a clone URL writes around it and points here (REPO_GATE in src/flow.js; the machine faces name this ledger), and D.E2 prints no clone command, because ED-3 disqualifies on a broken command. The flip is wired: REPO_PUBLIC in src/flow.js is the one constant; when the publication ruling lands (the same ruling epcis.dev's P0-14/P0-20/P0-24 wait on), set it true and every sentence speaking through REPO_GATE carries the clone affordance in one pass. Weekend-release intent; close with the URL and a dated line.

P0-V16 — Deploy ordering: the epcis.dev origin must serve the rebuilt site first — [OWNER] (rider on P0-4)

Every masthead and footer on this site links https://epcis.dev; /answers calls it the developer surface; llms.txt calls it "the same platform from the developer side." All of those sentences describe the REBUILT epcis.dev (epcis.dev/site), but that origin serves the legacy Nextra content site today (verified 2026-07-29) — so a clicked link would contradict the estate in the exact direction this brand is staked against. The links and the sentences stay, per the claim-the-vision law; the mechanism is deploy ordering: the epcis.dev origin must be cut over to the rebuilt site (its own P0 ledger cleared) before or simultaneously with visibility.cloud's first public deploy. Record it exactly like the visitor-node deploy check: on first production deploy, load https://epcis.dev once and confirm it serves the rebuilt surface (date + who), or do not deploy this site.

P0-A1..A7 — The seven answer products, as build gates — [BUILD]

The offers doc (2026-07-30 offer surface, §C) drafted these as "P0-V1..V7 ready to land"; that numbering was already taken by this ledger's closed messaging entries, so they land here under fresh ids. Reconciliation map (offers.md §C → this ledger): offers P0-V1→P0-A1 · V2→A2 · V3→A3 · V4→A4 · V5→A5 · V6→A6 (whose interview half shipped as this ledger's P0-V10) · V7→A7. Each is the mechanism behind a strong /answers claim; every one is honestly marked "Not built" on /answers and /what-ships-today until its gate closes.

  • P0-A1 [BUILD] — The trace answer view (product surface over the spine's tested GET /epcs/{epc}/events / trace_epc; the spine primitive is in the epcis.dev repo, the view is this estate's build).
  • P0-A2 [BUILD] — The custody evidence pack (per-EPC chain + §8.9 hashes + observer attribution rendered as a verifiable, offline-rejudgeable document; reuse the conformance suite's evidence-bundle trust shape).
  • P0-A3 [BUILD] — Exception views (the no-who-at-a-bizStep predicate is answerable on the tested query surface; the view and triage queue are not; notification additionally gates on P0-V4).
  • P0-A4 [BUILD] — SharingGrants (grant object + compile step + workspace surface over the spine's existing, tested Scope engine).
  • P0-A5 [BUILD] — FSMA 204 KDE/CTE export (depends on P0-A1).
  • P0-A6 [BUILD] — The Sunrise 2027 decision read as product (the content half is live — pillar routes + interview reads; what remains is the productized delivery; address capture gates on P0-V4).
  • P0-A7 [BUILD/OWNER] — Seats + provisionAgentSeat (blocked on Deputization vocabulary ratification — CONTEXT.md open question; mechanics stay unstated on public surfaces until ratified).

P0-A8 — Broader EDI mapping — [BUILD]

The How/EDI door says broader EDI mapping "carries its own named entry in the open P0 ledger" (P0-V30 de-hedge pass; was "on the roadmap", a softener). This is that entry. The translate path (EPCIS 1.1/1.2/2.0 XML → 2.0 JSON-LD with a per-job round-trip fidelity report) is written and under test; EDI (X12/EDIFACT) mapping is not started. This entry is the mechanism behind that sentence.

P0-A9 — Business-transaction context in traces (the ASN/PO read) — [BUILD]

2026-07-31. The executive read shipped as the fifth pillar route, /asn-po-context-in-traces (authored in the strategy repo's docs/content/pillars/ aeo-asn-po-context.md, vendored into ./content/, route row in src/routes.js, OG card + llms.txt entry + sitemap riding the same machinery as the other pillars; the scope ruling honored — the business-transaction layer, "EDI included, never EDI-only", no package or domain name in public copy). What the page states in the present tense is spec fact (CBV 2.0 §7.3/§8.5/§7.4/§8.7) plus the illustrative worked event figure from the tested event model; everything hosted stays behind its gates:

  • The trace answer view with document references — the rendered trace whose events show their bizTransactionList entries rides P0-A1 (the trace answer view); the join execution itself (documents compiled onto captured events) is the sibling repo's P4 gate and is claimed nowhere on the page in present tense.
  • The ASN-vs-observed exception view — the page says it "will render" the comparison; that sentence's mechanism is P0-A3 (exception views) plus the P4 join gate above.
  • The developer-door link — the page links epcis.dev/business-transactions/; that route must serve 200 before or simultaneously with this site's deploy of the page — the same deploy-ordering law as P0-V16, and this line is its record. Verified 2026-07-31: both curl 200 in production — the door page first, then this page's deploy.

P0-N1 — Publish visibility.cloud@0.1.0 to npm — [OWNER]

The package under pkg/ is built, tested, banned-strings-gated (pkg/scripts/check-banned-strings.mjs enforces the no-hedge law inside the tarball) and packed (pkg/visibility.cloud-0.1.0.tgz). npm publish --access public fails with E404 — the registry masks an unauthorized publish as 404 — and the ~/.npmrc token answers 401 on npm whoami (verified 2026-07-31). One owner action: npm login (or install a granular token with publish rights to new packages), then cd pkg && npm publish --access public, and verify with npm view visibility.cloud version → 0.1.0. Until it lands, every npx visibility.cloud mention on the machine faces carries its ledger pointer ("npm publication is an [OWNER] entry in the public P0 ledger"); replacing those pointers with the resolvable invocation is part of closing this entry. Weekend-release intent; the sibling epcis.dev package gate is P0-N2.

P0-10 — S10's "verbs pass locally" sentence is gated on a build assertion — [BUILD]

The visitor finale's closing beat currently ships the future-tense-only form ("A hosted endpoint will come later — this globe is not it") and does NOT claim "the verbs exist and pass locally today," although that claim is true in the epcis.dev repository (canon A9–A11; 683 tests passing 2026-07-30). Tense law: this site's build cannot assert another repo's suite, so the strong present-tense sentence is withheld, not softened — the fix is to wire a build gate (run or verify the epcis.dev suite at build time, or consume a dated, committed verification artifact) and then ship the strong beat: "translate/validate/hash: pass locally today; a hosted endpoint will come later." Build the gate; do not hand-edit the sentence in without it.

P0-V4 — The seat-ready send path: first verified inbox + named sender — [OWNER]

(Refreshed 2026-07-31 for the release-copy law.) The seat-list promise on every surface is now "your capture workspace is provisioned from this list, in order — one email when your seat is ready," and a store without a send keeps no promise: this entry is the first-cohort notification mechanism behind that sentence. Needed: a from-address with MX observed, alias resolving, a dated test send and receipt, and a named human reader — plus a committed export runbook and a committed literal message template ordered by the list's own row order (told in order, told once). The abandonment clause ("if we stop working on this, you get one message saying so and your address is deleted") is part of the same send path. Until this lands, the sender line on both doors stands in for a name. Weekend-release intent; rides P0-H1 for the seat itself.

P0-V5b — Restore the committee sentence, named and linked — [OWNER]

The founder-authority sentence returns only as a named person linked to the published GS1 EPCIS 2.0 / CBV 2.0 acknowledgements listing. Until then it stays removed — not softened.

P0-V6 — Bind the $0/event promise — [OWNER]

Published terms / a covenant / a named legal entity, linked. Until then every occurrence of $0-per-event on this origin carries "stated as intent, not terms" — including /icp.json's capture_price_status — and binding it retires the qualifier everywhere at once.

P0-V11 — Pin the id.gs1.org "anonymous by design" citation — [OWNER]

The home-page contrast line now links GS1's conformant-resolver standard (ref.gs1.org/standards/resolver/). Owner act: verify the linked artifact supports the "anonymous by design" wording exactly, or reword to precisely what it supports. On a site that tells readers "go check us," every claim about someone else must carry its check.

P0-S1 — Ratify the atlas S1 reskin (divergence from design-direction §2.5) — [OWNER]

design-direction §2.5 authored the flagship first scenario (S1) as a pharmaceutical cold chain ("pharmacy QA", "capturedBy: pharmacy acct"). The shipped S1 wears a FOOD cold chain instead — beats identical (seal, sensor stream, receiving, QA inspection), roles reskinned creamery/carrier/distributor/retail QA — because pharma is the canon's cut segment (§3.1), /Who/Pharmaceuticals tells that evaluator not to buy here, and the globe's opening story must not recruit the GxP evaluator the estate cannot serve. The messaging ruling (P0-V8's cut-segment law) is the newer targeting law and was followed; the divergence from the design doc is deliberate and needs owner ratification (confirm the reskin, or amend the design doc).

P0-V13 — Ratify the agent-class enumeration — [OWNER]

The five classes (including assistant, a new authorial act) and the four canon rulings need owner ratification. /agent-classes.json ships now under the claim-the-vision law and says so in $comment_ratification; ratification either confirms it or amends the one module.

P0-V14 — Production interview store + one live row — [OWNER] (rides P0-4)

The interviews table lives in the same D1 database as the waitlist and self-creates on first write; with no DB binding the flow still delivers the read and says plainly that nothing was stored. Owner act: after P0-4's provisioning, complete one live interview and record it here (date + who), exactly as the waitlist's verification row.

P0-4 — Verify the production store with a live test row — [OWNER]

(Amended 2026-07-30: the store was rewired from KV to D1 in wrangler.jsonc — binding DB, database visibility-waitlist — so the namespace-creation step is superseded; the live-row verification is not.)

  1. Deploy with the D1 binding, submit one live entry at /first-trace, confirm the row lands in the waitlist table, and fill the verification table in README.md (date + database id + who).

Until that row is filled, do not deploy publicly. With DB absent the worker answers a waitlist POST with an honest 503 (and the interview delivers its read while saying plainly that nothing was stored) — so it never lies — but a live site must have the store wired before the strong copy faces the public.

P0-8 — Identity-complete brand visibility + the consent rail — [BUILD]

The Sunrise fold makes the brand offer at full strength, in present tense: for the GTIN owner, item-level visibility that names the party at every step, beyond id.gs1.org's by-policy anonymity — paired with the consent rail, where a consumer who resolves only where the consumer consented (the GDPR reflex). The fold states the mechanism strong and cites this ledger; this entry holds the delta. Two things must be built before it closes:

  1. Identity resolution — resolve a GS1 Digital Link to an attested party at a grade. The envelope is already shaped for it (the spine records who captured an event and at what grade); nothing resolves a link to a party today.
  2. The consent gate — a lawful-basis check that sits in front of consumer identity resolution, so a consumer who is named only where consented and resolves to a consented pseudonym otherwise. This gate must exist before any consumer-generated event is ever resolved to a person.

Until both ship, this entry — not the prose — carries the gap, per the release-copy law: state it strong, ledger the delta, never soften. The consent gate must exist before any consumer-generated event is ever resolved to a person; the site claims the rail as built-in and this entry is the named mechanism that makes the claim checkable.


Standing brand/craft findings — verified still resolved (not blockers)

Confirmed to survive the /first-trace rework; not re-opened:

  • .consent-rail carries a horizontal vermilion top band (border-top: 2px solid var(--vermilion)), not a vertical side-stripe. The one prior side-stripe accent — the impeccable skill's single absolute ban — is retired; the rail now stands the way the brand's band runs everywhere else (custody figure, drench field, OG rule): full-bleed and horizontal. The vermilion .head caption is kept, so the fold still reads as load-bearing rather than a grey caveat. styles.css. (Polish item, never a ship-blocker; both sites pass the AI-slop test.)
  • Drenched fold carries its own --drench-field token, distinct from --vermilion (the mark colour). styles.css.
  • Gridlines never cross running prose — declared once, scoped to the hero headline row. styles.css.
  • OG-card composition — measured framing, four stations matching the live figure. build.js.
  • .serial URN never breaks at 320px — overflow-wrap: normal, clamp-sized to fit. styles.css.
  • twitter:image:alt present, single-sourced with og:image:alt via one OG_ALT const. build.js.
  • Manifest theme_color/background_color present. Since the 2026-07-30 polarity ruling the site is light-committed (no prefers-color-scheme branch, no toggle — the scheme is the register, mirroring epcis.dev's dark commitment), so the head carries ONE theme-color (#EAEEEB) and the manifest agrees; nothing scheme-conditional is left to drift. build.js, src/styles.css.
  • Per-surface OG cards (bar item 15's residual gap, closed 2026-07-30; extended 2026-07-31): twenty-three committed cards — home, the six dimension doors (the interrogative word + the door's own line over the home composition), /answers, one per pillar read, and — since the round-3 pass — one per cluster article, carrying the article's OWN crumb-sized headline, so a share of /epcis-1-2-vs-2-0-migration never renders its pillar's "Sunrise 2027 for brand owners" card. All derived from the same page data the pages render from, so the card and the page cannot say different things. Cluster pages (the preserved taxonomy) inherit their door's card. Image and alt travel as a pair through page() so a variant card never ships the home card's alt. build.js, src/render-assets.sh.
  • /.well-known/agents.json serves the same frozen AGENT_CLASSES document as /agent-classes.json — an alias in worker.js, not a copy, so the well-known face and the published contract cannot drift. worker.js.