{
  "schema_version":"0.1",
  "control_id":"MNT07",
  "reviewed_on":"2026-09-16",
  "status":"implemented_dependency_ordered_verification_inventory",
  "controls":[
    {"id":"SITE01","script":"scripts/check-site-integrity.mjs","depends_on":[],"scope":"routes, internal links, public assets, core registries, simulation fixtures, visualization contract, and protected maintenance boundaries","evidence_class":"source_and_contract","failure_policy":"stop_release","hooks":["navigation.inventory.changed","research.term.changed","simulation.schema.changed"],"limitations":"Source and contract validation does not prove external availability or representative-user success.","successor_path":"Keep this control active until a replacement verifies every protected invariant and historical failure case."},
    {"id":"P18RT","script":"scripts/check-forum-runtime.mjs","depends_on":["SITE01"],"scope":"forum schema, migrations, authenticated pending writes, adult boundary, personal-information and link screening, rate limits, reporting, owner moderation, withdrawal, public export, popularity isolation, and closed student interaction","evidence_class":"source_schema_contract","failure_policy":"stop_release","hooks":["storage.schema.changed","identity.provider.changed","forum.thread.schema.changed","moderation.capacity.changed","privacy.expectation.changed","abuse.pattern.changed","minor.safeguard.changed"],"limitations":"Source verification does not test live sign-in, production migrations, moderation staffing, independent appeal, legal or privacy compliance, backup expiry, or adversarial abuse resistance.","successor_path":"Run old and new forum controls in parallel; preserve pending-by-default writes, stable record IDs, ownership, moderation history, reports, withdrawal, filters, exports, and the stricter student boundary until migration parity is reviewed."},
    {"id":"P18F2","script":"scripts/check-forum-introductions.mjs","depends_on":["SITE01"],"scope":"independent effort snapshots, work-based matching, required divergence, reinforcement labels, mutual opt-in, comparison charters, branch preservation, rotation, neglected-area protection, recognition and funding separation, minor boundaries, and blocked interaction capabilities","evidence_class":"contract_and_synthetic_fixture","failure_policy":"stop_release","hooks":["forum.thread.schema.changed","popularity.signal.changed","privacy.expectation.changed","minor.safeguard.changed"],"limitations":"Synthetic cases do not perform matching, verify identity or age, authorize introductions, or replace human safeguarding and forum readiness review.","successor_path":"Run every acceptance and rejection case beside any replacement while preserving immutable snapshots, consent states, branches, contact boundaries, and the stricter blocked-interaction state."},
    {"id":"UX06B1","script":"scripts/check-user-journeys.mjs","depends_on":["SITE01"],"scope":"journey source contracts, recorded supervised cases, stage accuracy, and evidence-class separation","evidence_class":"mixed_source_contract_and_recorded_runtime","failure_policy":"stop_release","hooks":["journey.inventory.changed","usability.evidence.changed","usability.interaction.changed"],"limitations":"Recorded runtime cases do not complete enlargement, device, assistive-technology, or representative-user review.","successor_path":"Preserve journey identifiers, failure signals, privacy boundaries, and historical runtime evidence during replacement."},
    {"id":"EDU01S2A","script":"scripts/check-minor-safety-fixtures.mjs","depends_on":["SITE01"],"scope":"synthetic personal-information, link, file, contact, reporting, and ambiguity safety cases","evidence_class":"synthetic_fixture","failure_policy":"stop_release","hooks":["minor.safeguard.changed","student.interaction.changed","student.external_link.changed"],"limitations":"Synthetic fixtures are not a production filter and do not authorize student interaction.","successor_path":"Keep interaction disabled and retain every fixture until a reviewed production control passes equivalent and adversarial cases."},
    {"id":"P20A","script":"scripts/check-significant-contributors.mjs","depends_on":["SITE01"],"scope":"empty opt-in contributor registry, evidence and review gates, privacy exclusions, name-order policy, CV examples, five-opportunity official-source grant-search snapshots, documented shortfalls, grant-evidence limits, synthetic accept/reject cases, and successor path","evidence_class":"registry_contract_and_synthetic_fixture","failure_policy":"stop_release","hooks":["contribution.form.changed","research.parent.changed","privacy.expectation.changed","funding.opportunity.changed","development.priority.changed"],"limitations":"Passing the validator does not verify identity, perform scientific or funding review, prove live availability, certify competence, establish grant eligibility, or authorize a person’s publication.","successor_path":"Run the complete synthetic rejection set beside any replacement validator and preserve stable identifiers, consent, citations, corrections, withdrawals, dated grant searches, official notice references, and shortfalls."},
    {"id":"EXP03","script":"scripts/check-experimental-claim-packets.mjs","depends_on":["SITE01"],"scope":"experimental development order, portable claim-packet structure, synthetic maturity, preregistration, execution-authority, raw-evidence, privacy, minor, popularity, AI self-approval, provenance, limitation, and successor-path decisions","evidence_class":"contract_and_synthetic_fixture","failure_policy":"stop_release","hooks":["experiment.claim.schema.changed","experiment.ai.provenance.changed","experiment.protocol.changed","experiment.safety.changed","experiment.run.schema.changed","experiment.replication.changed","experiment.claim.status.changed","experiment.exchange.changed"],"limitations":"Passing synthetic fixtures does not review a live protocol, verify a person institution laboratory or instrument, authorize execution, validate evidence, or support a scientific claim.","successor_path":"Run all accepted and rejected synthetic packets beside any replacement and preserve the stricter decision whenever results differ until parity and migration are independently reviewed."},
    {"id":"UX06B2B2V","script":"scripts/check-enlargement-evidence.mjs","depends_on":["UX06B1"],"scope":"portable 200% enlargement evidence format, measurement gate, journey coverage, and privacy boundary","evidence_class":"synthetic_fixture_and_evidence_contract","failure_policy":"stop_release","hooks":["accessibility.expectation.changed","usability.evidence.changed","usability.interaction.changed"],"limitations":"Passing the validator does not demonstrate actual 200% enlargement or complete UX06B2B2.","successor_path":"Preserve measurement fields, journey cases, rejected examples, and the environment gate when the evidence format evolves."},
    {"id":"MNT02","script":"scripts/check-platform-compatibility.mjs","depends_on":["SITE01"],"scope":"runtime, framework, package manager, hosting, storage, access, compute limits, and replacement assumptions","evidence_class":"compatibility_contract","failure_policy":"stop_release","hooks":["platform.hosting.changed","platform.access.changed","dependency.major.changed","limit.compute.changed"],"limitations":"Pinned declarations detect source drift but do not prove vendor availability or approve automatic upgrades.","successor_path":"Update the compatibility register, migration plan, rollback plan, fixtures, and dependent controls in one release."},
    {"id":"MNT03","script":"scripts/check-feature-interconnections.mjs","depends_on":["MNT02"],"scope":"major features, routes, source surfaces, artifacts, dependencies, hooks, checks, limitations, and successor paths","evidence_class":"structural_inventory","failure_policy":"stop_release","hooks":["feature.deprecated","development.priority.changed","platform.hosting.changed"],"limitations":"Declared connections do not prove external access state or scientific validity.","successor_path":"Preserve stable feature identifiers and compatibility mappings until every route and artifact consumer migrates."},
    {"id":"MNT04","script":"scripts/check-maintenance-hooks.mjs","depends_on":["MNT03"],"scope":"hook identifiers, prerequisites, cycles, required responses, stage gates, stop conditions, and successor path","evidence_class":"dependency_graph","failure_policy":"stop_release","hooks":["prompt.registry.changed","development.priority.changed","feature.deprecated"],"limitations":"A valid hook graph does not prove external conditions or reviewer capacity.","successor_path":"Preserve hook aliases and a compatibility checker while dependent features migrate to revised stage semantics."},
    {"id":"MNT05","script":"scripts/check-artifact-lifecycle.mjs","depends_on":["MNT04"],"scope":"complete public JSON inventory, domains, lifecycle classes, hooks, schema versions, retention, and successor paths","evidence_class":"structural_inventory","failure_policy":"stop_release","hooks":["research.parent.changed","storage.schema.changed","feature.deprecated"],"limitations":"Artifact presence and schema shape do not validate scientific content or permit personal-data collection.","successor_path":"Retain aliases or readers for renamed artifacts and preserve recoverable prior releases until consumers migrate."},
    {"id":"MNT06","script":"scripts/check-route-lifecycle.mjs","depends_on":["MNT03","MNT05"],"scope":"complete page and API inventory, dependency domains, access boundaries, interaction boundaries, hooks, and successor paths","evidence_class":"structural_inventory","failure_policy":"stop_release","hooks":["navigation.inventory.changed","platform.access.changed","privacy.expectation.changed"],"limitations":"Route presence does not prove external availability or authorize a blocked interaction stage.","successor_path":"Preserve redirects, stable route identifiers, search and breadcrumb mappings, access boundaries, and prior releases during migration."},
    {"id":"MNT07","script":"scripts/check-verification-controls.mjs","depends_on":["UX06B1","EDU01S2A","EXP03","UX06B2B2V","MNT06"],"scope":"complete checker inventory, standard-command wiring, dependency order, evidence classes, failure policy, hooks, limitations, and successor paths","evidence_class":"verification_meta_control","failure_policy":"stop_release","hooks":["development.priority.changed","limit.compute.changed","feature.deprecated"],"limitations":"A passing automated suite does not replace external runtime, device, assistive-technology, legal, safeguarding, operational, or scientific review.","successor_path":"Run old and new verification paths together until parity is demonstrated, record known differences, and preserve the last release checked by the old path."},
    {"id":"MNT08","script":"scripts/check-change-impact.mjs","depends_on":["MNT07"],"scope":"tracked-source coverage, change-to-hook routing, required controls, update surfaces, stage gates, fixtures, limitations, and stop conditions","evidence_class":"change_impact_meta_control","failure_policy":"stop_release","hooks":["development.priority.changed","feature.deprecated","limit.compute.changed"],"limitations":"Impact routing identifies required review; it does not prove that external or human-gated work has been completed.","successor_path":"Run old and new impact rules together until every tracked source and historical change fixture has an equivalent or stricter route."},
    {"id":"MNT09","script":"scripts/check-external-dependencies.mjs","depends_on":["EDU01S2A","MNT08"],"scope":"literal HTTPS destination inventory, use classes, exposure states, authority, audiences, privacy boundaries, review hooks, replacement paths, and test-only quarantine","evidence_class":"source_inventory_and_review_contract","failure_policy":"stop_release","hooks":["student.external_link.changed","funding.opportunity.changed","research.parent.changed","platform.access.changed"],"limitations":"Source inventory does not make network requests, prove live availability, validate external policy, or replace safeguarding and funding review.","successor_path":"Run old and new destination inventories together until every literal URL, audience boundary, fixture, hook, and replacement path has equivalent or stricter coverage."},
    {"id":"MNT10","script":"scripts/check-maintenance-cadence.mjs","depends_on":["MNT09"],"scope":"release and recurring review cadence, evidence freshness, owner classes, authority boundaries, missed-run responses, and dependency-ordered maintenance priorities","evidence_class":"schedule_and_freshness_contract","failure_policy":"stop_release","hooks":["development.priority.changed","feature.deprecated","dependency.major.changed","platform.hosting.changed"],"limitations":"Schedule validation cannot prove an external automation ran, human review occurred, or evidence remains accurate after its review date.","successor_path":"Run old and new schedules through one complete interval, preserve prior evidence and deferrals, and retain the stricter authority boundary during migration."},
    {"id":"MNT11","script":"scripts/check-recoverability-evidence.mjs","depends_on":["MNT10"],"scope":"registered-source recovery, pinned setup, complete control suite, production build, nonproduction package integrity, findings, non-claims, evidence freshness, and production isolation","evidence_class":"recorded_clean_room_recovery_evidence","failure_policy":"stop_release","hooks":["platform.hosting.changed","feature.deprecated","dependency.major.changed"],"limitations":"One managed-environment drill does not prove provider, access, credential, data, secret, uploaded-file, production rollback, or independent-platform recovery.","successor_path":"Repeat from a fresh registered-source checkout by the review date and preserve failures while replacement instructions run in parallel."},
    {"id":"MNT12A","script":"scripts/check-external-review-evidence.mjs","depends_on":["MNT09","MNT10","MNT11"],"scope":"portable external-observation handoff, synthetic redirect and failure cases, privacy rejection, nonpublic quarantine, audience-specific reviewer gates, non-approval boundary, and successor path","evidence_class":"synthetic_fixture_and_external_review_contract","failure_policy":"stop_release","hooks":["funding.opportunity.changed","student.external_link.changed","privacy.expectation.changed","research.parent.changed","platform.access.changed"],"limitations":"Passing the validator does not make a network request, approve a destination, establish authority or currency, or complete safeguarding or funding review.","successor_path":"Run old and new protocols together against the complete synthetic decision set and a privacy-safe evidence package while preserving the stricter quarantine and reviewer gates."},
    {"id":"MNT12B","script":"scripts/check-external-network-observations.mjs","depends_on":["MNT12A"],"scope":"complete active-destination observation coverage, nonpersonal records, declared transport limits, narrow DOI-resolver handling, audience-specific named-review handoff, expiry, and non-approval boundary","evidence_class":"recorded_public_network_observation","failure_policy":"stop_release","hooks":["funding.opportunity.changed","student.external_link.changed","privacy.expectation.changed","research.parent.changed","platform.access.changed"],"limitations":"The recorded channels do not expose independent DNS answers, TLS certificate chains, or reliable HTTP status codes; reachability and redirect observations do not approve authority, currency, safety, or suitability.","successor_path":"Repeat the complete active-URL inventory by expiry, retain prior failures, and run old and new observation methods together until transport detail and decision parity are demonstrated."},
    {"id":"MNT12CP","script":"scripts/check-external-human-review-readiness.mjs","depends_on":["MNT12B"],"scope":"complete priority-ordered named-review preparation, reviewer-role mapping, one-decision-per-URL schema, observation-finding handoff, privacy boundary, empty-state integrity, expiry, and preserved human authority","evidence_class":"human_review_worklist_contract","failure_policy":"stop_release","hooks":["funding.opportunity.changed","student.external_link.changed","privacy.expectation.changed","minor.safeguard.changed","research.parent.changed"],"limitations":"A complete worklist does not appoint a reviewer, perform a review, establish authority or currency, approve a destination, or satisfy MNT12C.","successor_path":"Preserve the empty preparation artifact, create dated decision evidence only from named roles, and run old and new validators together until per-URL coverage and authority boundaries match."},
    {"id":"MNT12CV","script":"scripts/check-external-human-review-evidence.mjs","depends_on":["MNT12CP"],"scope":"synthetic per-destination human-decision evidence, complete fields, required roles, privacy rejection, expiry, active-destination identity, decision vocabulary, group-level rejection, non-approval boundary, and successor path","evidence_class":"synthetic_human_review_fixture","failure_policy":"stop_release","hooks":["funding.opportunity.changed","student.external_link.changed","privacy.expectation.changed","minor.safeguard.changed","research.parent.changed"],"limitations":"Passing synthetic cases does not appoint a reviewer, complete a live review, validate an external policy, or approve any destination.","successor_path":"Run the full synthetic rejection set alongside any replacement validator and validate a separate nonpersonal candidate package before accepting named-review evidence."}
  ],
  "change_rule":"Adding, removing, renaming, replacing, reordering, or disabling a release checker requires this registry, its dependencies, evidence limits, package command, and change register to change in the same bounded release.",
  "global_limit":"Passing source, contract, fixture, inventory, and recorded-evidence checks does not prove external runtime behavior or satisfy blocked human-review gates.",
  "verification":{"checker":"scripts/check-verification-controls.mjs","command":"pnpm check:site"}
}
