{
  "assets": [
    {
      "claim_ids": [
        "API31-C1",
        "API31-C2",
        "API31-C3",
        "API31-C4",
        "HARNESS31-C1",
        "HARNESS31-C2",
        "HARNESS31-C3",
        "HARNESS31-C4",
        "SEO31-C2"
      ],
      "classification": "public-derived",
      "id": "FORGE-SOURCE-RESEARCH-2026-08-04",
      "kind": "architecture-forge31-source-research",
      "owner": "Foundation Architect",
      "path": "README.md",
      "publication_status": "draft-source-bound"
    }
  ],
  "bundle_id": "FORGE-SOURCE-RESEARCH-2026-08-04",
  "claims": [
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "synthesis",
      "classification": "public-derived",
      "id": "API31-C1",
      "inference_boundary": "The selected positive intake covers official AsyncAPI 3.1.0 repository and schema artifacts, not the normative spec/asyncapi.md source of truth. OpenAPI 3.1.2 also remains a candidate not admitted by the v1 fetch policy, so this claim asserts neither AsyncAPI nor OpenAPI conformance. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-API-COVERAGE-CONTRACTS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/asyncapi/spec-json-schemas/tree/e27a97f3e57f9d5f7503419267785458bf7028b6/definitions/3.1.0",
          "commit_sha": "e27a97f3e57f9d5f7503419267785458bf7028b6",
          "content_sha256": "sha256:e9208b2ff568464321efe26e22fa30b41e30380c3977782ccd90a20172e03ad0",
          "independence_group": "asyncapi-initiative",
          "last_updated_at": null,
          "license": "Apache-2.0",
          "published_at": null,
          "publisher": "AsyncAPI Initiative",
          "receipt_digest": "sha256:078d457467dec08825bf552a3edc845f3129f0b7b1b9cdf50815096002463620",
          "receipt_path": "receipts/ASYNCAPI-3.1.0-SCHEMA.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:e27a97f3e57f9d5f7503419267785458bf7028b6:definitions/3.1.0/asyncapi.json",
          "source_class": "official-primary",
          "source_id": "ASYNCAPI-3.1.0-SCHEMA",
          "source_limitations": "The official repository states that its JSON Schemas are tooling artifacts rather than the specification itself. A schema validates document structure; it does not establish normative authority or runtime conformance.",
          "usage_basis": "Apache-2.0 official JSON Schema repository; analysis-only paraphrase",
          "version_tag": "3.1.0"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/asyncapi/spec/tree/v3.1.0",
          "commit_sha": "b3fac5bb522771428ea57b16129b273cd3ea0180",
          "content_sha256": "sha256:7cde018ba784000e52e09297d7f78de200c9d28d7ba388ef52c4c1372e046a8a",
          "independence_group": "asyncapi-initiative",
          "last_updated_at": null,
          "license": "Apache-2.0",
          "published_at": null,
          "publisher": "AsyncAPI Initiative",
          "receipt_digest": "sha256:070b42e6c1b53d6d8ee6b92db270ae2ffe4ce1a332076b85f18bb9aa9ad2d038",
          "receipt_path": "receipts/ASYNCAPI-3.1.0-README.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:b3fac5bb522771428ea57b16129b273cd3ea0180:README.md",
          "source_class": "official-primary",
          "source_id": "ASYNCAPI-3.1.0-README",
          "source_limitations": "The repository overview describes the specification scope but does not prove runtime behavior or implementation conformance.",
          "usage_basis": "Apache-2.0 specification repository; analysis-only paraphrase",
          "version_tag": "v3.1.0"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/oasdiff/oasdiff/blob/v1.27.0/docs/BREAKING-CHANGES.md",
          "commit_sha": "fb8babb92c123991e7cff4500bb35cafe97e5f7b",
          "content_sha256": "sha256:1e3801cbdd12c9377ecc4fb3622f979b5fe79cfd35ad63fa260034e0f1da0997",
          "independence_group": "oasdiff",
          "last_updated_at": null,
          "license": "Apache-2.0",
          "published_at": null,
          "publisher": "oasdiff",
          "receipt_digest": "sha256:51ddff5552ecbcb0df11385e394fe05c3f0cbdf853fcb848b9e1b2f0faca8f2c",
          "receipt_path": "receipts/OASDIFF-BREAKING-CHANGES.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:fb8babb92c123991e7cff4500bb35cafe97e5f7b:docs/BREAKING-CHANGES.md",
          "source_class": "official-primary",
          "source_id": "OASDIFF-BREAKING-CHANGES",
          "source_limitations": "The documented rule set detects listed contract changes; it cannot establish semantic or business compatibility by itself.",
          "usage_basis": "Apache-2.0 official implementation documentation; analysis-only paraphrase",
          "version_tag": "v1.27.0"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/rswag/rswag/tree/2.17.0",
          "commit_sha": "802c6894537513a913a72e546d54b67f54305853",
          "content_sha256": "sha256:59a41ca7dbf9f776d8ab5dd00da07c3cee4fb5e2192f1d70b063ab1ac8c7bcdc",
          "independence_group": "rswag",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "rswag",
          "receipt_digest": "sha256:5c492bda388d3c384f0d37ba0c44e25b51a83ed2a454a6602d23271cf7076700",
          "receipt_path": "receipts/RSWAG-2.17.0.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:802c6894537513a913a72e546d54b67f54305853:README.md",
          "source_class": "official-primary",
          "source_id": "RSWAG-2.17.0",
          "source_limitations": "The consulted release documents OpenAPI 3.0.x and JSON Schema Draft 4 behavior; it is not evidence of OpenAPI 3.1 conformance.",
          "usage_basis": "MIT official implementation documentation; analysis-only paraphrase",
          "version_tag": "2.17.0"
        }
      ],
      "statement": "A versioned API description, a compatibility diff and an executed request specification are separate evidence layers; FORGE should keep them distinct and bind each result to the same contract version.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "source-description",
      "classification": "public-derived",
      "id": "API31-C2",
      "inference_boundary": "This claim describes oasdiff only. Rule coverage can lag a specification or miss domain invariants, and a green diff cannot certify business compatibility. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-API-COVERAGE-CONTRACTS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/oasdiff/oasdiff/blob/v1.27.0/docs/OPENAPI-31.md",
          "commit_sha": "fb8babb92c123991e7cff4500bb35cafe97e5f7b",
          "content_sha256": "sha256:72af800a0b4c587b1a84cb59e628543c59672e283fb699316b2620c70b0f4693",
          "independence_group": "oasdiff",
          "last_updated_at": null,
          "license": "Apache-2.0",
          "published_at": null,
          "publisher": "oasdiff",
          "receipt_digest": "sha256:e72917452871accca9c7f0315864a772f437aeb2e5859191545b45e4ebac8362",
          "receipt_path": "receipts/OASDIFF-OPENAPI31.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:fb8babb92c123991e7cff4500bb35cafe97e5f7b:docs/OPENAPI-31.md",
          "source_class": "official-primary",
          "source_id": "OASDIFF-OPENAPI31",
          "source_limitations": "Tool support for OpenAPI 3.1 is not normative authority for the specification and does not prove business compatibility.",
          "usage_basis": "Apache-2.0 official implementation documentation; analysis-only paraphrase",
          "version_tag": "v1.27.0"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/oasdiff/oasdiff/blob/v1.27.0/docs/BREAKING-CHANGES.md",
          "commit_sha": "fb8babb92c123991e7cff4500bb35cafe97e5f7b",
          "content_sha256": "sha256:1e3801cbdd12c9377ecc4fb3622f979b5fe79cfd35ad63fa260034e0f1da0997",
          "independence_group": "oasdiff",
          "last_updated_at": null,
          "license": "Apache-2.0",
          "published_at": null,
          "publisher": "oasdiff",
          "receipt_digest": "sha256:51ddff5552ecbcb0df11385e394fe05c3f0cbdf853fcb848b9e1b2f0faca8f2c",
          "receipt_path": "receipts/OASDIFF-BREAKING-CHANGES.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:fb8babb92c123991e7cff4500bb35cafe97e5f7b:docs/BREAKING-CHANGES.md",
          "source_class": "official-primary",
          "source_id": "OASDIFF-BREAKING-CHANGES",
          "source_limitations": "The documented rule set detects listed contract changes; it cannot establish semantic or business compatibility by itself.",
          "usage_basis": "Apache-2.0 official implementation documentation; analysis-only paraphrase",
          "version_tag": "v1.27.0"
        }
      ],
      "statement": "oasdiff v1.27.0 documents OpenAPI 3.1 comparison and breaking-change rules; this is a useful CI control, not proof of semantic or business compatibility.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "source-description",
      "classification": "public-derived",
      "id": "API31-C3",
      "inference_boundary": "The observation is version-specific. A product adopting rswag still needs a compatibility suite for its selected OpenAPI version and a runtime conformance gate. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-API-COVERAGE-CONTRACTS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/rspec/rspec-rails/blob/v8.0.4/features/request_specs/request_spec.feature",
          "commit_sha": "222fb5518a7c9c1b9a0a06d950c2dfa2d3fa69e9",
          "content_sha256": "sha256:963999f44e08249ac368566a3a919b85898127c0513c0ea8b9f924d5374f6864",
          "independence_group": "rspec",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "RSpec",
          "receipt_digest": "sha256:a334c98cc3fbd999f702ff75e30fae6765c6c3a7abc3b633862a1ba02455149b",
          "receipt_path": "receipts/RSPEC-RAILS-REQUEST-SPECS.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:222fb5518a7c9c1b9a0a06d950c2dfa2d3fa69e9:features/request_specs/request_spec.feature",
          "source_class": "official-primary",
          "source_id": "RSPEC-RAILS-REQUEST-SPECS",
          "source_limitations": "RSpec request specs exercise application behavior but do not generate a language-neutral API contract or prove coverage sufficiency.",
          "usage_basis": "MIT official request-spec documentation; analysis-only paraphrase",
          "version_tag": "v8.0.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/rswag/rswag/tree/2.17.0",
          "commit_sha": "802c6894537513a913a72e546d54b67f54305853",
          "content_sha256": "sha256:59a41ca7dbf9f776d8ab5dd00da07c3cee4fb5e2192f1d70b063ab1ac8c7bcdc",
          "independence_group": "rswag",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "rswag",
          "receipt_digest": "sha256:5c492bda388d3c384f0d37ba0c44e25b51a83ed2a454a6602d23271cf7076700",
          "receipt_path": "receipts/RSWAG-2.17.0.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:802c6894537513a913a72e546d54b67f54305853:README.md",
          "source_class": "official-primary",
          "source_id": "RSWAG-2.17.0",
          "source_limitations": "The consulted release documents OpenAPI 3.0.x and JSON Schema Draft 4 behavior; it is not evidence of OpenAPI 3.1 conformance.",
          "usage_basis": "MIT official implementation documentation; analysis-only paraphrase",
          "version_tag": "2.17.0"
        }
      ],
      "statement": "rswag 2.17.0 can execute RSpec request specs and generate or validate OpenAPI artifacts, while its consulted documentation demonstrates OpenAPI 3.0.x and JSON Schema Draft 4 behavior; it is therefore an optional Ruby adapter rather than FORGE authority for OpenAPI 3.1.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "synthesis",
      "classification": "public-derived",
      "id": "API31-C4",
      "inference_boundary": "The exact normalized FORGE schema remains a framework decision. Coverage percentage cannot prove test relevance, correctness, risk coverage or absence of defects. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-API-COVERAGE-CONTRACTS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/ruby/ruby/blob/v4.0.6/coverage/README",
          "commit_sha": "03b6d3f8898a28604fe6cb00eae3226b821168f4",
          "content_sha256": "sha256:d2ffcbf8d5ac69ce97b0f8568b6919d5184e168a1dd6ce3e4c7506b03bd67a24",
          "independence_group": "ruby-lang",
          "last_updated_at": null,
          "license": "Ruby-License-or-BSD-2-Clause",
          "published_at": "2026-07-14",
          "publisher": "Ruby",
          "receipt_digest": "sha256:fe0e30aa82f72695639737e1c7d28db3a83fde8edbb4779bc0e943d901f52efc",
          "receipt_path": "receipts/RUBY-COVERAGE-4.0.6.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:03b6d3f8898a28604fe6cb00eae3226b821168f4:coverage/README",
          "source_class": "official-primary",
          "source_id": "RUBY-COVERAGE-4.0.6",
          "source_limitations": "The standard library exposes runtime coverage primitives; it does not define FORGE thresholds, reporting interoperability or test quality.",
          "usage_basis": "Official Ruby source documentation; analysis-only paraphrase",
          "version_tag": "v4.0.6"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/simplecov-ruby/simplecov/tree/v1.0.3",
          "commit_sha": "e9fddf0a0c52e81182dee5a50491ead2ebd7c120",
          "content_sha256": "sha256:4d634c9fe485a6c534b03beac7553167035768382839dbd8a22a795b72f94f26",
          "independence_group": "simplecov",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "SimpleCov",
          "receipt_digest": "sha256:7eddb21684104227a0177ac7cfb16bc8b8f6b645dd380e322659c2a27abecfc9",
          "receipt_path": "receipts/SIMPLECOV-1.0.3.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:e9fddf0a0c52e81182dee5a50491ead2ebd7c120:README.md",
          "source_class": "official-primary",
          "source_id": "SIMPLECOV-1.0.3",
          "source_limitations": "SimpleCov is a Ruby adapter over runtime coverage data; a percentage does not establish test quality or risk sufficiency.",
          "usage_basis": "MIT official implementation documentation; analysis-only paraphrase",
          "version_tag": "v1.0.3"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://coverage.readthedocs.io/en/latest/commands/cmd_xml.html",
          "commit_sha": "b7470d963d3f941e06654f7e8921384ece9588ca",
          "content_sha256": "sha256:407e525606c7af9457c5c1418b1f9b8b10f4edd043ab72829fc3536c458404d0",
          "independence_group": "coveragepy",
          "last_updated_at": null,
          "license": "Apache-2.0",
          "published_at": null,
          "publisher": "coverage.py",
          "receipt_digest": "sha256:7d62ea910925c11ac983b16030eeffd698d02e01c8ea9a688d587e2ef5bddc02",
          "receipt_path": "receipts/COVERAGEPY-7.15.3.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:b7470d963d3f941e06654f7e8921384ece9588ca:doc/commands/cmd_xml.rst",
          "source_class": "official-primary",
          "source_id": "COVERAGEPY-7.15.3",
          "source_limitations": "XML output is an interchange mechanism for coverage observations; it does not define a universal quality model.",
          "usage_basis": "Apache-2.0 official documentation source; analysis-only paraphrase",
          "version_tag": "7.15.3"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://docs.github.com/en/code-security/how-tos/maintain-quality-code/set-up-code-coverage",
          "commit_sha": "f4c887c9d6afbfa295c5dd69ef8e0c98ecc8c119",
          "content_sha256": "sha256:7885351cabfafa34051c4afe5c52e04b40c6062ee02f3b8377952898c935f38d",
          "independence_group": "github",
          "last_updated_at": null,
          "license": "CC-BY-4.0",
          "published_at": null,
          "publisher": "GitHub",
          "receipt_digest": "sha256:4d62e6ec039ffaab8cc3d987bb93763f6670c471c3380bec9f8f7d3e6623180d",
          "receipt_path": "receipts/GITHUB-CODE-COVERAGE.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:f4c887c9d6afbfa295c5dd69ef8e0c98ecc8c119:content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md",
          "source_class": "official-primary",
          "source_id": "GITHUB-CODE-COVERAGE",
          "source_limitations": "Language and format support documented here applies to GitHub Code Quality and is not a universal coverage standard.",
          "usage_basis": "CC-BY-4.0 official documentation; analysis-only paraphrase",
          "version_tag": null
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/cobertura/cobertura/blob/cobertura-2.1.1/cobertura/src/site/htdocs/xml/coverage-04.dtd",
          "commit_sha": "dff61a6ef44b1027c7a8b5800e1d895989453a94",
          "content_sha256": "sha256:e467cb8252e20feb794fc2dedfbea7b4957921669c758f0282d525df88897917",
          "independence_group": "cobertura",
          "last_updated_at": null,
          "license": "GPL-2.0",
          "published_at": null,
          "publisher": "Cobertura",
          "receipt_digest": "sha256:a00b5df525f83356ca58242934422fc3fe5b9b3e3d61a320d39c4db04f6f3053",
          "receipt_path": "receipts/COBERTURA-2.1.1-DTD.json",
          "relation": "qualifies",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:dff61a6ef44b1027c7a8b5800e1d895989453a94:cobertura/src/site/htdocs/xml/coverage-04.dtd",
          "source_class": "official-primary",
          "source_id": "COBERTURA-2.1.1-DTD",
          "source_limitations": "Cobertura is a legacy project and format, not a standards-body authority; consuming compatible XML is different from copying GPL code.",
          "usage_basis": "Official legacy DTD; metadata-only interoperability analysis",
          "version_tag": "cobertura-2.1.1"
        }
      ],
      "statement": "FORGE coverage evidence should be tool-neutral and normalize at least line, branch, scope, delta and threshold fields; SimpleCov and coverage.py remain language adapters, while an interchange report is not a quality verdict.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "source-description",
      "classification": "public-derived",
      "id": "HARNESS31-C1",
      "inference_boundary": "The project is pre-1.0 and the selected public material provides no independent production reliability, security or adoption study. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-MULTIPLAYER-HARNESS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/docs/getting-started.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:8e99e5fdcb66dc49f3a38367ef913f37f8ad558dec7a7c69c50f2eb73904f851",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:d6740abeb0ff639be82838c80b62801c2b3afcb2ee0160d3e3b82230dc7de1cf",
          "receipt_path": "receipts/QM-GETTING-STARTED.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:docs/getting-started.md",
          "source_class": "official-primary",
          "source_id": "QM-GETTING-STARTED",
          "source_limitations": "Getting-started documentation proves an available project workflow, not operational maturity or suitability for every organization.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/plugins/admin/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:c48902e51935c886df93e9dee78ee8a554199b903363e40268533670594f103e",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:198572373122ad789fd5bdd9c4c99d0df655664952847269ca8fbe6287dd6adc",
          "receipt_path": "receipts/QM-ADMIN.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:plugins/admin/README.md",
          "source_class": "official-primary",
          "source_id": "QM-ADMIN",
          "source_limitations": "An admin plugin is an implementation surface, not proof that every policy is independently enforced or production hardened.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/plugins/portal/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:40d43f2e5531ded0fc31dc56a4a7062b1f4bf96376348df28de4c95305f4f804",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:041b20072ed0305976b506e799372856f8224067ac9c370d68245ffb287f3193",
          "receipt_path": "receipts/QM-PORTAL.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:plugins/portal/README.md",
          "source_class": "official-primary",
          "source_id": "QM-PORTAL",
          "source_limitations": "A portal surface demonstrates a product boundary, not independently measured collaboration outcomes.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/src/slack/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:2ff9dcca85ea089a48832d432b90de8434fa3880144fa189264a3a5c45e2e8bd",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:2af2a153ae4bd611c6ec3fdc9d8a34ce33ae5aa62d544b479a9f09bee93230d2",
          "receipt_path": "receipts/QM-SLACK.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:src/slack/README.md",
          "source_class": "official-primary",
          "source_id": "QM-SLACK",
          "source_limitations": "The integration documentation demonstrates a channel adapter, not universal identity parity or security assurance.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/plugins/web-ui/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:a191fe86dd1a69537d7957b7dd13af9ea3d065694dedb70c04bdf615b121a111",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:cd7dbc05f1fe5d450062884ffe74ec75783865fa31c19b1b336a0d01fea01549",
          "receipt_path": "receipts/QM-WEB-UI.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:plugins/web-ui/README.md",
          "source_class": "official-primary",
          "source_id": "QM-WEB-UI",
          "source_limitations": "A web interface demonstrates a collaboration surface but does not establish organization-wide adoption or reliability.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        }
      ],
      "statement": "QM v0.1.4 exposes a multiplayer agent product through setup, admin, portal, Slack and web surfaces; FORGE can treat these as verified inspiration for scoped collaboration, not as a normative or production-maturity baseline.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "synthesis",
      "classification": "public-derived",
      "id": "HARNESS31-C2",
      "inference_boundary": "The sources show two implementations, not a neutral interoperability standard. Actual permissions must be independently enforced and tested outside model choice. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-MULTIPLAYER-HARNESS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://www.anthropic.com/engineering/managed-agents",
          "commit_sha": null,
          "content_sha256": "sha256:66dc98fa5a5a9adbe97b3276778ff0cd5f9dee52e73bd2b7dee6d95a67ab159f",
          "independence_group": "anthropic",
          "last_updated_at": null,
          "license": "proprietary-site-terms",
          "published_at": "2026-04-08",
          "publisher": "Anthropic",
          "receipt_digest": "sha256:793e175316d6620f88b8c13e20e18f94dec2aeb182c4e23792c1eaaab9a18673",
          "receipt_path": "receipts/ANTHROPIC-MANAGED-AGENTS.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "retrieved:2026-08-04",
          "source_class": "empirical-primary",
          "source_id": "ANTHROPIC-MANAGED-AGENTS",
          "source_limitations": "The architecture reflects one provider implementation and should be treated as empirical guidance rather than a neutral standard.",
          "usage_basis": "Public official engineering article; citation and analysis-only paraphrase",
          "version_tag": null
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/package.json",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:9f81b3ae2887c30d627d6f5ffea9d80fd549f9f8a1233857ab7060330a2e845c",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:4f783632931a9e2e0dd459cd5db481e016c41ad94e147cb847522fbf1cbf651d",
          "receipt_path": "receipts/QM-PACKAGE.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:package.json",
          "source_class": "official-primary",
          "source_id": "QM-PACKAGE",
          "source_limitations": "Package metadata identifies implementation dependencies and adapters but does not prove runtime interchangeability or policy enforcement.",
          "usage_basis": "MIT official package metadata; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/plugins/admin/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:c48902e51935c886df93e9dee78ee8a554199b903363e40268533670594f103e",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:198572373122ad789fd5bdd9c4c99d0df655664952847269ca8fbe6287dd6adc",
          "receipt_path": "receipts/QM-ADMIN.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:plugins/admin/README.md",
          "source_class": "official-primary",
          "source_id": "QM-ADMIN",
          "source_limitations": "An admin plugin is an implementation surface, not proof that every policy is independently enforced or production hardened.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        }
      ],
      "statement": "A durable harness should keep session history, orchestration policy and execution isolation as explicit boundaries, while adapters and plugins prevent model or channel choice from becoming the security boundary.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "source-description",
      "classification": "public-derived",
      "id": "HARNESS31-C3",
      "inference_boundary": "This is a provider experiment tied to a selected model, benchmark and application task; it cannot prove universal superiority of multi-agent or evaluator layers. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-MULTIPLAYER-HARNESS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://www.anthropic.com/engineering/harness-design-long-running-apps",
          "commit_sha": null,
          "content_sha256": "sha256:fd59d8ff642b2404ab621cca067923eaaefc68a36d78652a2a9257fdbadf9fb9",
          "independence_group": "anthropic",
          "last_updated_at": null,
          "license": "proprietary-site-terms",
          "published_at": "2026-03-24",
          "publisher": "Anthropic",
          "receipt_digest": "sha256:273c15f91163ed37a469c2ed52750a6ba67ca49baed28e6fbd937e2d6f444a37",
          "receipt_path": "receipts/ANTHROPIC-HARNESS-DESIGN.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "retrieved:2026-08-04",
          "source_class": "empirical-primary",
          "source_id": "ANTHROPIC-HARNESS-DESIGN",
          "source_limitations": "The reported experiment is model and task dependent and does not establish that a layered harness is always cost effective.",
          "usage_basis": "Public official engineering article; citation and analysis-only paraphrase",
          "version_tag": null
        }
      ],
      "statement": "Anthropic reports that planner, generator and evaluator layers improved a long-running application result while materially increasing cost and latency; FORGE should require task-specific evals and ablation before making such layers mandatory.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "synthesis",
      "classification": "public-derived",
      "id": "HARNESS31-C4",
      "inference_boundary": "The sources do not define a universal authorization model. FORGE still needs deny-by-default grants, tenant tests and revocation evidence before enforcement. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-MULTIPLAYER-HARNESS",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/plugins/admin/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:c48902e51935c886df93e9dee78ee8a554199b903363e40268533670594f103e",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:198572373122ad789fd5bdd9c4c99d0df655664952847269ca8fbe6287dd6adc",
          "receipt_path": "receipts/QM-ADMIN.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:plugins/admin/README.md",
          "source_class": "official-primary",
          "source_id": "QM-ADMIN",
          "source_limitations": "An admin plugin is an implementation surface, not proof that every policy is independently enforced or production hardened.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/plugins/portal/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:40d43f2e5531ded0fc31dc56a4a7062b1f4bf96376348df28de4c95305f4f804",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:041b20072ed0305976b506e799372856f8224067ac9c370d68245ffb287f3193",
          "receipt_path": "receipts/QM-PORTAL.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:plugins/portal/README.md",
          "source_class": "official-primary",
          "source_id": "QM-PORTAL",
          "source_limitations": "A portal surface demonstrates a product boundary, not independently measured collaboration outcomes.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://github.com/yc-software/qm/blob/v0.1.4/src/slack/README.md",
          "commit_sha": "7f2c916360f1797a8ff2a77ce2ce40c5fabab087",
          "content_sha256": "sha256:2ff9dcca85ea089a48832d432b90de8434fa3880144fa189264a3a5c45e2e8bd",
          "independence_group": "yc-software",
          "last_updated_at": null,
          "license": "MIT",
          "published_at": null,
          "publisher": "YC Software",
          "receipt_digest": "sha256:2af2a153ae4bd611c6ec3fdc9d8a34ce33ae5aa62d544b479a9f09bee93230d2",
          "receipt_path": "receipts/QM-SLACK.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:7f2c916360f1797a8ff2a77ce2ce40c5fabab087:src/slack/README.md",
          "source_class": "official-primary",
          "source_id": "QM-SLACK",
          "source_limitations": "The integration documentation demonstrates a channel adapter, not universal identity parity or security assurance.",
          "usage_basis": "MIT official project documentation; analysis-only paraphrase",
          "version_tag": "v0.1.4"
        },
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://www.anthropic.com/engineering/managed-agents",
          "commit_sha": null,
          "content_sha256": "sha256:66dc98fa5a5a9adbe97b3276778ff0cd5f9dee52e73bd2b7dee6d95a67ab159f",
          "independence_group": "anthropic",
          "last_updated_at": null,
          "license": "proprietary-site-terms",
          "published_at": "2026-04-08",
          "publisher": "Anthropic",
          "receipt_digest": "sha256:793e175316d6620f88b8c13e20e18f94dec2aeb182c4e23792c1eaaab9a18673",
          "receipt_path": "receipts/ANTHROPIC-MANAGED-AGENTS.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "retrieved:2026-08-04",
          "source_class": "empirical-primary",
          "source_id": "ANTHROPIC-MANAGED-AGENTS",
          "source_limitations": "The architecture reflects one provider implementation and should be treated as empirical guidance rather than a neutral standard.",
          "usage_basis": "Public official engineering article; citation and analysis-only paraphrase",
          "version_tag": null
        }
      ],
      "statement": "Shared agent capabilities should be scoped and administered explicitly, while web, Slack and future channels remain replaceable integration surfaces rather than implicit organization-wide authority.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    },
    {
      "asset_ids": [
        "FORGE-SOURCE-RESEARCH-2026-08-04"
      ],
      "claim_kind": "source-description",
      "classification": "public-derived",
      "id": "SEO31-C2",
      "inference_boundary": "This claim describes the vocabulary only. It makes no claim about Google eligibility, ranking, rich-result display, AI citation or the truth of marked-up content. This is a source-bound design input; it does not prove product adoption, operational maturity, independent attestation, search ranking, AI citation or outcome.",
      "owner": "Foundation Architect",
      "research_id": "R31-PUBLIC-KNOWLEDGE-DISCOVERY",
      "source_bindings": [
        {
          "accessed_at": "2026-08-04",
          "canonical_url": "https://schema.org/version/30.0/",
          "commit_sha": "420231f6bfac8372fc564abb121fae57ccb36a0c",
          "content_sha256": "sha256:06227db49dd4674227727176c9cd1e5bbd4174c1cef9391c7ed4dfcef865f2a8",
          "independence_group": "schemaorg",
          "last_updated_at": null,
          "license": "CC-BY-SA-3.0-vocabulary; Apache-2.0-repository-software",
          "published_at": null,
          "publisher": "Schema.org",
          "receipt_digest": "sha256:0418847824a4d2489f2ee0d69b5399a50c45e4b6e7b97e0424c62cafe379e2f1",
          "receipt_path": "receipts/SCHEMAORG-30.0.json",
          "relation": "supports",
          "reviewed_by": "codex-SQ3",
          "snapshot_ref": "git:420231f6bfac8372fc564abb121fae57ccb36a0c:data/releases/30.0/schemaorg-all-https.jsonld",
          "source_class": "vocabulary-official",
          "source_id": "SCHEMAORG-30.0",
          "source_limitations": "The vocabulary supplies shared terms; using them does not validate visible content or guarantee search features.",
          "usage_basis": "Official versioned vocabulary; citation and analysis-only metadata use",
          "version_tag": "v30.0"
        }
      ],
      "statement": "Schema.org 30.0 provides a versioned shared vocabulary that can represent Article and BreadcrumbList metadata in JSON-LD; vocabulary use alone does not validate visible content or guarantee discovery features.",
      "validity": {
        "observed_at": "2026-08-04T03:27:53Z",
        "republication_requires_review_after": "2027-08-04T03:27:53Z",
        "scope": "pinned or point-in-time source snapshots plus human-reviewed structural synthesis"
      }
    }
  ],
  "cut_at": "2026-08-04T03:27:53Z",
  "policy": {
    "claim_status": "draft-source-bound",
    "forbidden": [
      "unreceipted-source",
      "raw-external-content",
      "unbounded-inference",
      "operational-or-attested-claim-without-product-evidence",
      "ranking-or-ai-citation-guarantee"
    ],
    "raw_external_content_persisted": false,
    "republication_requires": [
      "approved-source-receipt",
      "explicit-claim-boundary",
      "asset-owner",
      "validity-window",
      "human-publication-review"
    ]
  },
  "research_pack": {
    "methodology": "zero-copy-human-synthesis",
    "path": "research-pack-v1.json",
    "schema_version": "forge.source-research-pack/v1"
  },
  "schema_version": "forge.source-claim-asset-projection/v2",
  "source_catalog": {
    "cut_at": "2026-08-04T03:27:53Z",
    "path": "source-catalog-v1.json",
    "reviewed_by": "codex-SQ3",
    "schema_version": "forge.source-research-sources/v1"
  }
}
