{
  "schema_version":"0.1",
  "control_id":"MNT12CP",
  "reviewed_on":"2026-09-16",
  "status":"prepared_not_reviewed",
  "purpose":"Prepare a complete, dependency-ordered MNT12C worklist without recording reviewer identities, decisions, approval, or personal information.",
  "depends_on":["MNT09","MNT12A","MNT12B"],
  "source_evidence":"public/external-network-observations.json",
  "review_batches":[
    {"rank":1,"id":"HR01","registered_group_id":"official_funding_destinations","observation_count":13,"state":"not_started","priority_reason":"Time-sensitive funding guidance plus two observed routing or usefulness findings require authority and currency review first.","required_reviewer_roles":["source_authority","privacy","funding_currency"],"required_checks":["ownership_and_authority","effective_destination","funding_currency","eligibility_boundary","privacy_boundary","replacement_path","expiry"],"finding_ids":["PAMS_INTEGRATION_LOGIN","NSPIRES_EMPTY_UNPARAMETERIZED_SUMMARY"],"reviewed_at":null,"reviewer_roles":[],"decisions_by_url":[],"public_rationale":null,"conditions":[],"limitations":[],"expires_on":null},
    {"rank":2,"id":"HR02","registered_group_id":"student_learning_destinations","observation_count":3,"state":"not_started","priority_reason":"Minor-facing destinations require safeguarding before convenience or program usefulness can be considered.","required_reviewer_roles":["source_authority","privacy","safeguarding","funding_currency"],"required_checks":["ownership_and_authority","age_suitability","minor_privacy","contact_boundary","adult_supervision","funding_currency_where_applicable","replacement_path","expiry"],"finding_ids":[],"reviewed_at":null,"reviewer_roles":[],"decisions_by_url":[],"public_rationale":null,"conditions":[],"limitations":[],"expires_on":null},
    {"rank":3,"id":"HR03","registered_group_id":"citation_resolver","observation_count":11,"state":"not_started","priority_reason":"Resolver targets preserve cited DOI identity but publisher authority, privacy, and continuing citation usefulness remain unapproved.","required_reviewer_roles":["source_authority","privacy"],"required_checks":["doi_identity","publisher_target","source_authority","privacy_boundary","replacement_path","expiry"],"finding_ids":["APS_SECURITY_CHALLENGE_LIMIT"],"reviewed_at":null,"reviewer_roles":[],"decisions_by_url":[],"public_rationale":null,"conditions":[],"limitations":[],"expires_on":null},
    {"rank":4,"id":"HR04","registered_group_id":"project_source","observation_count":2,"state":"not_started","priority_reason":"The project-origin relationship and canonical destination require an explicit authority decision.","required_reviewer_roles":["source_authority","privacy"],"required_checks":["ownership_and_authority","canonical_destination","privacy_boundary","replacement_path","expiry"],"finding_ids":["SAME_ORIGIN_CANONICALIZATION"],"reviewed_at":null,"reviewer_roles":[],"decisions_by_url":[],"public_rationale":null,"conditions":[],"limitations":[],"expires_on":null},
    {"rank":5,"id":"HR05","registered_group_id":"prompt_handoff","observation_count":1,"state":"not_started","priority_reason":"Optional platform handoff remains secondary because prompts are independently copyable without it.","required_reviewer_roles":["source_authority","privacy"],"required_checks":["platform_authority","blank_handoff_boundary","privacy_boundary","replacement_path","expiry"],"finding_ids":[],"reviewed_at":null,"reviewer_roles":[],"decisions_by_url":[],"public_rationale":null,"conditions":[],"limitations":[],"expires_on":null}
  ],
  "decision_record_schema":{"required":["registered_url","reviewed_at","reviewer_roles","decision","public_rationale","conditions","limitations","expires_on"],"allowed_decisions":["approved_with_expiry","approved_with_conditions","remove_or_quarantine","defer_pending_evidence"],"coverage_rule":"Every active registered URL requires exactly one dated decision; a batch cannot pass from a group-level decision alone.","expiry_rule":"Every accepted decision requires expires_on and re-enters review when expired or when a registered hook fires."},
  "findings":[
    {"id":"PAMS_INTEGRATION_LOGIN","registered_group_id":"official_funding_destinations","observation_ref":"NET16","review_question":"Is the observed same-origin login page labeled Integration the intended public production destination?","required_roles":["source_authority","privacy","funding_currency"]},
    {"id":"NSPIRES_EMPTY_UNPARAMETERIZED_SUMMARY","registered_group_id":"official_funding_destinations","observation_ref":"NET15","review_question":"Should the unparameterized summary URL remain when it returned no solicitation details, or be replaced by a reviewed official index?","required_roles":["source_authority","funding_currency"]},
    {"id":"APS_SECURITY_CHALLENGE_LIMIT","registered_group_id":"citation_resolver","observation_ref":"NET07","review_question":"Can the DOI and separately retrieved official publisher target be accepted despite the unresolved intermediary security challenge?","required_roles":["source_authority","privacy"]},
    {"id":"SAME_ORIGIN_CANONICALIZATION","registered_group_id":"project_source","observation_ref":"NET02","review_question":"Is the same-origin canonicalization expected and is the registered project-source relationship current?","required_roles":["source_authority","privacy"]}
  ],
  "privacy_boundary":"Public nonpersonal review evidence only. Do not record reviewer names, contact details, credentials, private deliberations, user data, student data, grant drafts, application data, or browsing histories.",
  "change_authority":"This worklist and its validator are report-only. They cannot appoint reviewers, record a human decision, approve a destination, change access, publish, remove, redirect, or reclassify a destination.",
  "not_claimed":["named reviewer assignment","completed source-authority review","completed privacy review","completed funding-currency review","completed safeguarding review","destination approval"],
  "successor_path":"When named roles become available, copy this schema into a dated evidence artifact, preserve this empty worklist and every prior observation, require one decision per active URL, and run old and new validators together until coverage and authority boundaries match."
}
