K09 · bounded executable evidence infrastructure
Facility Workbook Tools
Direct answer
K09 implements offline workbook tooling that preserves conflicts and rejects secrets and protected topology instead of allowing them into public fixtures.
Safe import policy
The importer accepts owner decisions, evidence requests, stop conditions, applicability disputes, outputs, and opaque protected-reference IDs. It rejects credential, secret, private-key, IP-address, coordinate, topology, exact-setting, exploit, and target-package fields.
Conflict report
| Field | Change state | Resolution state |
|---|---|---|
| applicabilityConflicts | UNCHANGED | UNCHANGED |
| assumptions | MODIFIED | UNRESOLVED |
| facilityPatternId | UNCHANGED | UNCHANGED |
| id | UNCHANGED | UNCHANGED |
| outputs | UNCHANGED | UNCHANGED |
| ownerDecisions | MODIFIED | UNRESOLVED |
| protectedReferences | UNCHANGED | UNCHANGED |
| requiredEvidence | UNCHANGED | UNCHANGED |
| slug | UNCHANGED | UNCHANGED |
| status | UNCHANGED | UNCHANGED |
| stopConditions | UNCHANGED | UNCHANGED |
| unresolvedQuestions | MODIFIED | UNRESOLVED |
Explicit resolution
Every modified field requires a caller choice of base, incoming, merged, or unresolved. The reference tool refuses unresolved modified fields and validates the normalized result after resolution. It does not select a facility fact or authority position on the owner’s behalf.
Negative fixtures
The K09 test suite confirms that a workbook containing a password field and a workbook containing networkTopology and ipAddress fields are rejected.