K09 · bounded executable evidence infrastructure

Protected source-selection annex

Direct answer

Protected source-selection annex permits 7 declared field classes and explicitly prohibits 2 sensitive classes in the reference projection.

Authority and disclosure boundary. K09 publishes static tools, synthetic fixtures, source-derived event records, signed offline imports, non-certifying traces, redacted procurement structures, and public/protected partition schemas. It does not perform live monitoring, reveal protected topology or credentials, decide awards, certify facilities, authorize operations, or prove factual truth from a signature.

Schema boundary

Evidence partition profile
IDPART-K09-SELECTION
ClassificationSOURCE_SELECTION_SENSITIVE
NameProtected source-selection annex

Allowed fields

  • recordId
  • protectedReferenceId
  • decisionAuthority
  • evaluatorRecord
  • priceRecord
  • challengeRecord
  • publicSummaryRecord

Prohibited fields

  • privateKeys
  • publicReleaseWithoutAuthority

Required public links

  • publicSummaryRecord
  • challengeRoute

Projection rule

The reference projector fails when prohibited fields are present or required public links are absent. It outputs only declared allowed fields and a count of omitted fields.

Boundary

This static schema is not a production authorization system, encrypted repository, classification guide, or access-control enforcement point. A competent owner must operate the protected store and approve disclosure.