K10 · bounded transition and assurance evidence

Facility Workbook Migration and Merge

Direct answer

K10 migrates the reference workbook from schema 1.0 to 2.0, combines non-conflicting revisions, leaves disputed owner decisions unresolved, validates separately held reference custody, verifies a synthetic detached signature, and removes prohibited values from the public projection.

Authority, operation, and disclosure boundary. K10 publishes static tools, deterministic synthetic fixtures, review queues, offline observation records, migration and merge reports, abstract dependency analysis, reference transition plans, audit trails, signed offline receipts, redaction records, and a release-time dashboard. It does not perform live monitoring, deployment, procurement award, facility certification, network reconnaissance, protected-system operation, legal authorization, or factual adjudication.

Schema migration

Workbook schema versions
VersionStatusRequired fields
1.0SUPPORTED MIGRATION SOURCEid, facilityPatternId, status, ownerDecisions, protectedReferences
2.0ACTIVE REFERENCE SCHEMAschemaVersion, id, revision, facilityPatternId, status, ownerDecisions, decisionRecords, protectedReferences

Deterministic migration steps

  1. 1.0 → 2.0: add schemaVersion=2.0
  2. 1.0 → 2.0: add revision=1 when absent
  3. 1.0 → 2.0: convert ownerDecisions into decisionRecords with unsigned reference status
  4. 1.0 → 2.0: preserve protectedReferences as identifiers only

Three-way merge

The reference tool compares a base workbook with two revisions, combines non-conflicting field changes, and returns UNRESOLVED when both sides make incompatible changes. No owner decision is silently selected.

Non-conflicting merge result · Deliberate conflict result · Public redaction report.

Protected-reference custody

Custody receipts
ReceiptProtected referenceStateHolder classContent included
PCR-K10-001PROTECTED-FACILITY-REFERENCE-001REFERENCE_HELD_SEPARATELYOWNER-DESIGNATED CUSTODIANFalse
PCR-K10-002PROTECTED-FACILITY-REFERENCE-002REFERENCE_UNAVAILABLEUNASSIGNEDFalse

Decision signatures and redaction

The signed reference decision validates payload integrity and signer relationship only. Public redaction reports identify field paths and reason codes without reproducing removed values.

Workbook tooling is not a facility finding, owner authorization, protected repository, or production access-control system.