# EM-0021 execution plan

- Object ID: `em:documentation:sha256:c9c7451d1b3ec0efe452ddbf264b384327f76111c305b3c7d227ad080cf05f35`
- Kind: `documentation`
- Repository path: [`docs/execution-plans/EM-0021.md`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/docs/execution-plans/EM-0021.md)
- Content digest: `252aabd54aa1bc751eb538cc44a1907270757ec620ba1bc7ed48e25b7d6ec3eb`

**Also filed under:** [Disclosure and Public Projection](https://epistemedia.org/topics/disclosure/), [Epistemedia](https://epistemedia.org/topics/epistemedia/), [Epistemic Mesh Protocol](https://epistemedia.org/topics/epistemic-mesh/), [Sovereign Realm Federation](https://epistemedia.org/topics/federation/), [Autonomous Governance](https://epistemedia.org/topics/governance/), [Knowledge Objects](https://epistemedia.org/topics/knowledge-objects/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/), [Research Program](https://epistemedia.org/topics/research-program/), [Security and Adversarial Robustness](https://epistemedia.org/topics/security/)

## Source content

# EM-0021 execution plan

Status: candidate validation complete; awaiting exact-head independent review on
`codex/em-0021-feature-backfire-case`.

## Objective

Compile the independently reviewed familiarity-backfire dossier into the first public **How We
Know** experience without copying or weakening its evidence model, while ensuring every compiled
current-state document accurately distinguishes the application-level dossier pilot from the
self-describing repository corpus and the still-unimplemented normative replay architecture. The
accepted feature manifest is the editorial-selection input; the reviewed dossier and receipt
remain the evidence authority.

## Succession record

EM-0021 supersedes EM-0020 because independent review of the exact EM-0020 candidate at
`07713131e57b662230acffe4fd48f56fa3d91502` found two stale README descriptions in the compiled
public corpus. EM-0020 did not authorize `README.md`; the earlier EM-0016 maintenance task had
already been completed. The owner merged the narrow EM-0021 authority registration in PR #35 at
`998f5dfed308e36f8f83ba166f3c680c582af128`. No EM-0020 implementation commit was merged.

## Change surface

1. Add a strict application-level feature loader that binds the selection manifest to the exact
   dossier bytes, dossier identity, independent pass receipt, reviewed Git head, claim family,
   policy evaluations, relations, spans, editions, and source works.
2. Derive raw assertion and participant-data-lineage counts from modeled relations rather than
   storing display totals.
3. Compile the same disclosure-safe policy projection into human HTML, Markdown, JSON, API, MCP,
   and CLI adapters with one envelope identity and content digest per view.
4. Replace the project-self homepage lead with the accepted external finding, while retaining the
   self-describing repository corpus under Explore and Documentation.
5. Correct README and launch-facing current-state prose without claiming that the dossier is the
   normative event graph or that an unverified hosted interface is live.
6. Test source-span closure, real shared-ancestor collapse, policy divergence, interface parity,
   current-state copy, no-JavaScript and keyboard structure, disclosure noninterference, and
   deterministic rebuilds.
7. Inspect desktop and mobile rendering, record a run receipt, obtain exact-head independent
   review, merge through the protected owner-gated path, deploy Pages, and verify canonical routes
   and content types.

## Hard boundaries

- No changes to `constitution/**`, `policies/**`, `schemas/**`, `governance/events/**`,
  `.github/**`, `tasks/contracts/**`, or the reviewed research packet.
- The application views do not become protocol semantics or universal truth policies.
- Hosted API and MCP endpoints remain described as reserved until separately deployed and read
  back; static and local adapters must not be described as hosted production runtimes.
- Correct source and layout behavior establish implementation behavior, not human comprehension.
- Merge, publication, deployment, DNS, credentials, and spend remain explicit owner gates.

## Candidate verification

- strict feature-manifest binding to the exact independently reviewed dossier and receipt bytes,
  dossier ID, receipt format and independence attestations, reviewed head, claim family,
  evaluations, relations, spans, editions, and source works;
- deterministic relation-derived counts plus a real shared-ancestor adversarial check;
- exact HTML, Markdown, JSON, local REST, MCP resource/tool, and CLI envelope parity;
- encyclopedia/skeptical source-object parity with materially different evaluations and selected
  relations;
- README and launch-document assertions that preserve the application/normative/deployment
  boundaries and reject the superseded current-state wording;
- fail-closed byte-drift mutation test and public disclosure audit;
- no-script semantic HTML, one `h1`, named navigation regions, native disclosure controls, visible
  skip-link focus, and no horizontal overflow;
- browser inspection at `1440 x 900` and `390 x 844`, including homepage, both policy views, and
  an expanded exact-source x-ray;
- `.venv/bin/ruff check src/epistemedia/featured.py tests/test_featured.py`;
- `.venv/bin/python -m pytest tests/test_featured.py tests/test_interfaces.py -q` — 37 tests
  passed;
- `make check PYTHON=.venv/bin/python` — 71 tests passed, disclosure audit returned no findings,
  deterministic comparison build verified, and source state remained unchanged;
- immutable local receipt `em0021-local-20260822T2042Z` records the full check command.

External route, canonical URL, content-type, keyboard, and provider-manifest read-back remain
post-merge Pages acceptance checks; no hosted API/MCP runtime is asserted.
