K10 · bounded transition and assurance evidence
Facility Workbook Migration and Merge
Direct answer
K10 migrates the reference workbook from schema 1.0 to 2.0, combines non-conflicting revisions, leaves disputed owner decisions unresolved, validates separately held reference custody, verifies a synthetic detached signature, and removes prohibited values from the public projection.
Schema migration
| Version | Status | Required fields |
|---|---|---|
| 1.0 | SUPPORTED MIGRATION SOURCE | id, facilityPatternId, status, ownerDecisions, protectedReferences |
| 2.0 | ACTIVE REFERENCE SCHEMA | schemaVersion, id, revision, facilityPatternId, status, ownerDecisions, decisionRecords, protectedReferences |
Deterministic migration steps
- 1.0 → 2.0: add schemaVersion=2.0
- 1.0 → 2.0: add revision=1 when absent
- 1.0 → 2.0: convert ownerDecisions into decisionRecords with unsigned reference status
- 1.0 → 2.0: preserve protectedReferences as identifiers only
Three-way merge
The reference tool compares a base workbook with two revisions, combines non-conflicting field changes, and returns UNRESOLVED when both sides make incompatible changes. No owner decision is silently selected.
Non-conflicting merge result · Deliberate conflict result · Public redaction report.
Protected-reference custody
| Receipt | Protected reference | State | Holder class | Content included |
|---|---|---|---|---|
| PCR-K10-001 | PROTECTED-FACILITY-REFERENCE-001 | REFERENCE_HELD_SEPARATELY | OWNER-DESIGNATED CUSTODIAN | False |
| PCR-K10-002 | PROTECTED-FACILITY-REFERENCE-002 | REFERENCE_UNAVAILABLE | UNASSIGNED | False |
Decision signatures and redaction
The signed reference decision validates payload integrity and signer relationship only. Public redaction reports identify field paths and reason codes without reproducing removed values.
Workbook tooling is not a facility finding, owner authorization, protected repository, or production access-control system.