Receipt semantics guard回执语义守卫
Generate an immutable snapshot, then attach receipt evidence.先生成不可变快照,再附加回执证据。
The workflow keeps submitted_payload_snapshot distinct from PortalReceiptEvidence and keeps source limitations visible after success.工作流区分 submitted_payload_snapshot 与 PortalReceiptEvidence,并在成功后持续展示来源限制。
Scenario 0 next stepScenario 0 下一步
Dashboard readiness becomes final only after PortalReceiptEvidence is attached.只有附加 PortalReceiptEvidence 后,Dashboard 准备度才进入最终态。
submitted_payload_snapshot
Created only after ShareTable v2 validation passes.仅在 ShareTable v2 校验通过后生成。
Guard: prepare the reporting package on P02 first.
PortalReceiptEvidence
Attach as audit-only receipt evidence, never acceptance.作为 audit-only 回执证据附加,绝不作为接受证明。
Guard: submitted_payload_snapshot must be generated first.
Persistent compliance risks持续合规风险
Success states never hide source limitation or timestamp uncertainty.成功状态绝不隐藏来源限制或时间戳不确定性。
Evidence timeline证据时间线
Generated and attached events append from local state.生成与附加事件从本地状态追加。
VulnerabilitySignal SIG-001 createdVulnerabilitySignal SIG-001 已创建
Threat-intel source, CVSS 9.1; raw attachment stored but hidden from demo_observer.威胁情报来源,CVSS 9.1;原始附件已存储但对 demo_observer 隐藏。
ReportabilityDecision DEC-001 decidedReportabilityDecision DEC-001 已判定
L2 met; L1 unknown; L3 not_met. decision_rule_trace stored with confidence high.L2 满足;L1 未知;L3 不满足。decision_rule_trace 以 high 置信度存储。