# EM-0022 execution plan

- Object ID: `em:documentation:sha256:f71a6829a4af6a24aff634b16850257f941926e6477b1f626d53f098ff1771a4`
- Kind: `documentation`
- Repository path: [`docs/execution-plans/EM-0022.md`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/docs/execution-plans/EM-0022.md)
- Content digest: `693afcfc31eb4a78417957659812e0936b8e2e0ea7b87ed84e5b5efb2f27d25e`

**Also filed under:** [Disclosure and Public Projection](https://epistemedia.org/topics/disclosure/), [Epistemedia](https://epistemedia.org/topics/epistemedia/), [Epistemic Mesh Protocol](https://epistemedia.org/topics/epistemic-mesh/), [Sovereign Realm Federation](https://epistemedia.org/topics/federation/), [Autonomous Governance](https://epistemedia.org/topics/governance/), [Knowledge Objects](https://epistemedia.org/topics/knowledge-objects/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/), [Research Program](https://epistemedia.org/topics/research-program/), [Security and Adversarial Robustness](https://epistemedia.org/topics/security/)

## Source content

# EM-0022 execution plan

Status: candidate validation complete; awaiting exact-head independent review on
`codex/em-0022-case-entry-trust-agent-parity`.

## Objective

Make every primary human and agent entrance lead coherently into the accepted Case 001 evidence
experience. Replace the unlinked review badge with a sanitized, exact-head public receipt; turn
How We Know into a section index; label the existing repository corpus as Substrate; provide a
first-screen path into the unresolved lineage; and fail closed on agent-discovery or release-skew
regressions.

## Change surface

1. Compile a public review-receipt projection from the already accepted, byte-bound independent
   receipt without exposing reviewer temporary paths or unneeded raw review material.
2. Replace the duplicated How We Know homepage with a compact one-case section index that says
   explicitly that no second case has yet been admitted.
3. Preserve `/explore/` and its corpus, while naming that destination Substrate in navigation and
   page copy so its role is legible.
4. Link the first-screen `4 + 1?` evidence cell directly to the unresolved 2007 lineage.
5. Add deterministic cold-start agent discovery and whole-release identity-parity checks, then
   exercise the same checks against the accepted Pages deployment.

## Hard boundaries

- The accepted dossier, review receipt, feature manifest, research packet, counts, relations,
  policy evaluations, and evidence conclusions remain byte-identical.
- No new case, lens, research claim, workflow, DNS, API/MCP deployment, package, or release work.
- The public review view is a sanitized projection of the accepted receipt, not a new review or a
  claim that synthetic tests establish universal agent comprehension.
- Publication requires independent exact-head review and the normal protected squash path.

## Verification

- targeted feature/interface/identity tests;
- cold-start discovery from generated `llms.txt` into stable Markdown and JSON twins;
- deliberate mixed-version mutation rejected by the release-identity verifier;
- no-script semantic HTML and native keyboard path into the unresolved lineage;
- desktop and mobile inspection;
- full `make check` with disclosure audit and deterministic rebuild;
- exact-head independent review, protected merge, Pages deployment, and live human/bot read-back.

## Candidate verification

- the generated How We Know index contains one compact case row, explicitly says no second case
  has been admitted, and no longer includes the homepage case hero;
- the primary navigation and `/explore/` presentation use Substrate while preserving the route and
  all self-describing corpus content;
- the sanitized review HTML, Markdown, and JSON expose the accepted reviewer, exact head/tree,
  receipt digest, independence conditions, checked scope, counts, and limitations without the
  receipt's temporary local paths;
- the first-screen `4 + 1?` cell is a native link to `#unresolved-lineage`, and the target exists on
  the case page with the existing visible focus treatment and no JavaScript;
- a cold-start fixture follows only `llms.txt` links into the stable Markdown and JSON twins and
  recovers the exact question, verdict, 10 / 4 + 1? / 12 counts, and unresolved 2007 lineage;
- a whole-release verifier checks every generated HTML route and every JSON object that declares
  release fields, recomputes the release-manifest identity, verifies every inventory path/digest/
  byte binding and complete file closure, and rejects mixed-commit, forged-identity, and inventory
  mutations;
- targeted feature/interface tests passed; the full suite now collects 75 tests;
- browser inspection at `1440 x 900` and `390 x 844` found one `h1`, zero scripts, no horizontal
  overflow, responsive section and review layouts, exact reviewer/head display, and no private
  temporary path disclosure;
- the browser driver did not dispatch Enter activation on the new native evidence link during the
  local check; semantic link structure, destination, focus CSS, and click target are verified, and
  exact keystroke activation remains an explicit post-deployment read-back;
- `make check PYTHON=.venv/bin/python` passed all 75 tests, disclosure audit returned no findings,
  deterministic comparison build verified, and source state remained unchanged;
- immutable local receipt `em0022-local-20260822T224248Z` records the full check command.

External bot-user-agent, route, content-type, canonical, release-skew, and keyboard read-back remain
post-merge Pages acceptance checks. No hosted API or MCP runtime is asserted.
