{
  "title": "CrewOS external-participant build",
  "slug": "crewos-external-participant",
  "claim_ids": ["E6-C001", "E6-C002", "E6-C003", "E6-C004", "E6-C005", "E6-C006"],
  "evidence_level": "outcome",
  "access": "sanitized_public_excerpt",
  "source_date": "2026-07-24",
  "build_date": "2026-08-02",
  "source_commit": "24ec65306",
  "original_internal_locations": [
    "system/caster/runs/cast-run-61-2026-07-25/root-refresh.md",
    "system/cure/docs/EPP_T3_SWEEP_RESULTS.md",
    ".postexec-attestations/2026-07-24-cure-v3-epp-portal-coverage.postexec-clean.json",
    "CrewOS commits d20a60ea (un-designation) / 93255817 (CLEAN attestation) — apps/crewos submodule",
    "FoundryOS commit 0eb96a25c (lifecycle halt)",
    "apps/crewos/docs/plans/2026-07-24-epp-designation-clear.md — INTERNAL ONLY"
  ],
  "published_artifacts": [
    "artifacts/build-trace.md",
    "artifacts/source-ambiguity-halt.md",
    "artifacts/clean-attestation.md",
    "artifacts/epp-clear-path-finding.md"
  ],
  "redactions": [
    {
      "item": "a second, unrelated finding the sweep surfaced",
      "action": "omitted entirely",
      "reason": "SECURITY-SENSITIVE — it concerns an unpatched issue still live on the client's production portal, and it is NOT the claim being evidenced (the claim is the resolved EPP-01 clear-path finding). Publishing a live unpatched issue, or its class, is a disclosure risk."
    },
    {
      "item": "synthetic test-tenant UUID",
      "action": "replaced with <synthetic-test-tenant>",
      "reason": "production identifier; redacted on principle even though it is a synthetic test tenant, not a customer."
    },
    {
      "item": "CrewOS production hostname",
      "action": "replaced with 'the deployed CrewOS production surface'",
      "reason": "operational endpoint / private URL of a client-deployed product."
    },
    {
      "item": "seven internal-only CrewOS implementation shas",
      "action": "generalized / omitted",
      "reason": "not needed to evaluate the claim; only the identifiers the article publishes (d20a60ea, 93255817) plus the halt commit (0eb96a25c) are retained as provenance."
    },
    {
      "item": "the un-designation mechanism (durable rung-3 designation, clear_participant_designation_atomic SECDEF/service-role/account-fenced, GET+DELETE endpoint contract) and the two-cycle audit flow",
      "action": "retained",
      "reason": "load-bearing evidence and non-sensitive architecture; no exploit is disclosed (the security boundary described is the FIX, moving an authorization check into the database)."
    }
  ],
  "limitations": [
    "The '146 commits' figure is attributed to the Cast Run 61 operating record; it is NOT reconstructable from a single git range and is not presented as such.",
    "The specific consumer profile is not named; the evidence supports 'durable planned execution on Chassis', the article's wording.",
    "The follow-on sweep used a synthetic test tenant only — this package makes no claim about production customer data.",
    "The CrewOS plan and per-run ledgers remain Internal evidence only; this package publishes their sanitized shape and outcomes."
  ],
  "reproduction_method": "git cat-file -t d20a60ea / 93255817 (CrewOS repo) and git show -s 0eb96a25c (FoundryOS) to confirm the commit objects; reaudit_surface_ambiguous in system/_operator/scripts/codex-postexec-audit.mjs + system/_operator/lib/resolve-lifecycle-position.mjs for the halt mechanism; system/caster/runs/cast-run-61-2026-07-25/root-refresh.md for the 146-commit attribution; system/cure/docs/EPP_T3_SWEEP_RESULTS.md for the follow-on finding.",
  "reviewer": "FoundryOS operator",
  "review_date": "2026-08-02"
}
