K09 · bounded executable evidence infrastructure

Facility Workbook Tools

Direct answer

K09 implements offline workbook tooling that preserves conflicts and rejects secrets and protected topology instead of allowing them into public fixtures.

Authority and disclosure boundary. K09 publishes static tools, synthetic fixtures, source-derived event records, signed offline imports, non-certifying traces, redacted procurement structures, and public/protected partition schemas. It does not perform live monitoring, reveal protected topology or credentials, decide awards, certify facilities, authorize operations, or prove factual truth from a signature.

Safe import policy

The importer accepts owner decisions, evidence requests, stop conditions, applicability disputes, outputs, and opaque protected-reference IDs. It rejects credential, secret, private-key, IP-address, coordinate, topology, exact-setting, exploit, and target-package fields.

PASSreference workbook validation
3modified fields requiring decision

Conflict report

Base versus incoming workbook
FieldChange stateResolution state
applicabilityConflictsUNCHANGEDUNCHANGED
assumptionsMODIFIEDUNRESOLVED
facilityPatternIdUNCHANGEDUNCHANGED
idUNCHANGEDUNCHANGED
outputsUNCHANGEDUNCHANGED
ownerDecisionsMODIFIEDUNRESOLVED
protectedReferencesUNCHANGEDUNCHANGED
requiredEvidenceUNCHANGEDUNCHANGED
slugUNCHANGEDUNCHANGED
statusUNCHANGEDUNCHANGED
stopConditionsUNCHANGEDUNCHANGED
unresolvedQuestionsMODIFIEDUNRESOLVED

Explicit resolution

Every modified field requires a caller choice of base, incoming, merged, or unresolved. The reference tool refuses unresolved modified fields and validates the normalized result after resolution. It does not select a facility fact or authority position on the owner’s behalf.

Negative fixtures

The K09 test suite confirms that a workbook containing a password field and a workbook containing networkTopology and ipAddress fields are rejected.