{
  "generated_from": "docs/book_outline.md",
  "note": "Generated from Lean proof target tables in docs/book_outline.md. Edit the outline, not this file.",
  "proof_target_count": 340,
  "status_counts": {
    "implemented": 330,
    "planned": 10
  },
  "chapter_counts": {
    "adjudicated-persistence-and-the-adaptive-commit-boundary": 5,
    "adversarial-evaluation-sandbagging-and-training-time-deception": 8,
    "adversarial-machine-learning-and-model-attack-surface": 1,
    "ai-deployment-transition-distribution-and-human-agency": 1,
    "ai-supply-chain-integrity-and-lifecycle-provenance": 6,
    "ai-work-surfaces-agent-harnesses-and-organizational-absorption": 3,
    "artifact-graphs-audit-logs-and-replay": 10,
    "artifact-steward-agents-and-living-project-governance": 7,
    "asi-is-a-stack-not-a-model": 3,
    "autonomous-replication-proliferation-and-containment": 1,
    "benchmark-ratchets-and-anti-goodhart-evidence": 3,
    "capability-replacement-and-rollback": 6,
    "capability-thresholds-and-deployment-commitments": 8,
    "circle-calculus-and-proof-carrying-ai-contracts": 4,
    "claim-ledgers-and-belief-revision": 4,
    "cognitive-compilation-and-semantic-ir": 3,
    "coil-attention-cyclic-memory-and-recurrence-contracts": 3,
    "coilra-multicoil-rope-and-cyclic-mixers": 2,
    "compact-generative-systems-and-residual-honesty": 9,
    "confidential-and-verifiable-ai-computation": 1,
    "constitutional-alignment-substrate": 7,
    "content-authenticity-watermarking-and-synthetic-media-integrity": 1,
    "context-transactions-snapshots-mounts-and-taint": 4,
    "dangerous-capability-domains-and-misuse-uplift": 1,
    "data-engines-continual-learning-and-unlearning": 15,
    "durable-semantic-memory-and-knowledge-lattices": 1,
    "embodied-agency-real-time-control-and-physical-safety": 1,
    "evidence-states-and-claim-discipline": 3,
    "executable-specifications-and-lean-proof-envelope": 2,
    "failure-modes-of-ungoverned-intelligence": 5,
    "fast-generation-architectures": 5,
    "governed-deliberation-and-test-time-scaling": 10,
    "governed-model-training-distributed-optimization-and-scaling": 3,
    "governed-objective-formation-value-learning-and-goal-integrity": 1,
    "governed-operations-incident-command-and-graceful-degradation": 3,
    "governed-world-models-and-reality-grounding": 2,
    "human-ai-communication-persuasion-and-epistemic-security": 1,
    "human-ai-organizations-delegation-and-accountability": 1,
    "human-ai-symbiosis-neurotechnology-and-cognitive-sovereignty": 1,
    "human-factors-and-meaningful-control-in-oversight": 2,
    "human-intent-as-a-formal-input": 5,
    "inner-alignment-mesa-optimization-and-learned-objective-integrity": 2,
    "institutions-international-coordination-and-public-legitimacy": 1,
    "integrated-reference-architecture": 3,
    "intent-to-execution-contracts": 7,
    "inter-stack-protocols-identity-and-economic-exchange": 9,
    "labor-os-and-typed-jobs": 5,
    "learning-compute-topology-and-adaptive-process-architecture": 2,
    "learning-theory-generalization-and-scaling-science": 1,
    "living-book-methodology": 4,
    "mathematical-and-search-substrates": 3,
    "military-ai-autonomous-weapons-and-strategic-stability": 1,
    "model-weight-custody-and-hardware-roots-of-trust": 8,
    "moral-uncertainty-and-value-conflict": 8,
    "multi-agent-dynamics-collective-intelligence-and-systemic-risk": 1,
    "open-ended-improvement-engines": 7,
    "open-research-agenda-and-bibliography-plan": 2,
    "open-weight-release-and-post-release-control": 1,
    "perception-sensor-fusion-and-observation-trust": 2,
    "personal-compute-hives-and-federated-edge-intelligence": 6,
    "physical-compute-infrastructure-energy-and-environmental-constraints": 1,
    "planning-as-a-control-layer": 7,
    "policy-optimization-and-learning-from-feedback": 4,
    "privacy-data-rights-and-information-flow-governance": 2,
    "procedural-memory-and-cognitive-loop-closure": 2,
    "project-theseus-as-report-first-implementation-reference": 3,
    "prototype-roadmap": 3,
    "rankfold-neuralfold-and-artifact-compression": 3,
    "readiness-gates-residual-escrow-and-quarantine": 3,
    "recursive-self-improvement-boundaries": 3,
    "relational-dimension-compilation-and-polyadic-cognition": 1,
    "replaceable-cognitive-substrates-beyond-transformer-monoculture": 1,
    "resource-economics-and-token-budgets": 11,
    "routing-heads-and-specialist-cores": 5,
    "runtime-adapters-tool-permissions-and-human-approval": 6,
    "safety-cases-and-structured-assurance": 8,
    "scalable-oversight-and-adversarial-ai-control": 7,
    "scientific-discovery-and-experimental-governance": 1,
    "security-kernel-and-digital-scifs": 4,
    "societal-resilience-and-misuse-defense": 1,
    "spinoza-verification-and-proof-carrying-claims": 5,
    "stable-capability-fields": 4,
    "system-boundaries-and-authority": 4,
    "the-efficient-asi-hypothesis": 4,
    "verification-bandwidth-and-context-adequacy": 4,
    "virtual-context-abi": 6,
    "white-box-evidence-interpretability-and-activation-governance": 2
  },
  "records": [
    {
      "chapter_id": "asi-is-a-stack-not-a-model",
      "chapter_title": "ASI Is a Stack, Not a Model",
      "tag": "lean:stack.layer_boundaries.operational_invariant",
      "module": "AsiStackProofs.StackBoundaries",
      "formal_target": "Every accepted material effect in the finite boundary transition model requires a live same-epoch grant within the caller ceiling and a prior dispatch receipt; arbitrary accepted runs preserve the authority/effect-accounting invariant and caller ceiling and compose exactly across prefixes; every valid nonempty handoff chain stays below its initial source ceiling while preserving adjacent artifact custody.",
      "status": "implemented",
      "outline_line": 481,
      "module_path": "lean/AsiStackProofs/StackBoundaries.lean"
    },
    {
      "chapter_id": "asi-is-a-stack-not-a-model",
      "chapter_title": "ASI Is a Stack, Not a Model",
      "tag": "lean:stack.layer_boundaries.failure_blocks_promotion",
      "module": "AsiStackProofs.StackBoundaries",
      "formal_target": "The finite boundary model rejects over-ceiling authorization and effect without dispatch; revocation blocks later authorization, dispatch, and effect; arbitrary valid handoff chains cannot widen beyond their head; artifact substitution breaks composition; and an external-action contract without layer authority or an authorized handoff cannot be admitted.",
      "status": "implemented",
      "outline_line": 482,
      "module_path": "lean/AsiStackProofs/StackBoundaries.lean"
    },
    {
      "chapter_id": "asi-is-a-stack-not-a-model",
      "chapter_title": "ASI Is a Stack, Not a Model",
      "tag": "lean:stack.layer_contract.admission_lifecycle_route",
      "module": "AsiStackProofs.StackBoundaries",
      "formal_target": "A quantified Lean inverse requires every admitted layer contract to preserve complete identity, lifecycle, ownership, artifact, authority, handoff, invariant, failure, evidence, source, support-transition, and non-claim obligations; a recompiling independent suite matches all eighteen priority-ordered routes.",
      "status": "implemented",
      "outline_line": 483,
      "module_path": "lean/AsiStackProofs/StackBoundaries.lean"
    },
    {
      "chapter_id": "the-efficient-asi-hypothesis",
      "chapter_title": "The Efficient ASI Hypothesis",
      "tag": "lean:efficiency.minimum_viable.operational_invariant",
      "module": "AsiStackProofs.Efficiency",
      "formal_target": "The executable finite selector returns only a listed eligible route whose complete seven-class modeled total is no greater than every eligible candidate; cheaper unauthorized and failed-quality routes cannot displace the bounded minimum.",
      "status": "implemented",
      "outline_line": 549,
      "module_path": "lean/AsiStackProofs/Efficiency.lean"
    },
    {
      "chapter_id": "the-efficient-asi-hypothesis",
      "chapter_title": "The Efficient ASI Hypothesis",
      "tag": "lean:efficiency.minimum_viable.failure_blocks_promotion",
      "module": "AsiStackProofs.Efficiency",
      "formal_target": "A promoted result with open obligations and no residual record causes the finite residual-promotion predicate to fail.",
      "status": "implemented",
      "outline_line": 550,
      "module_path": "lean/AsiStackProofs/Efficiency.lean"
    },
    {
      "chapter_id": "the-efficient-asi-hypothesis",
      "chapter_title": "The Efficient ASI Hypothesis",
      "tag": "lean:efficiency.claim_admission_lifecycle_route",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "A reachable nine-stage route-economy lifecycle requires scoped request identities, complete resource and hidden-cost accounting, protected capacity, fallback, actual spend, useful-outcome and resource-bill separation, verification, residual and recovery records, reconciliation, evidence transition, and closure without support or external-effect authority.",
      "status": "implemented",
      "outline_line": 551,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "the-efficient-asi-hypothesis",
      "chapter_title": "The Efficient ASI Hypothesis",
      "tag": "lean:efficiency.route_search.probe_fixture_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "The independent synthetic route-search consumer computes two valid and six expected-invalid outcomes over fourteen candidates, while the reachable lifecycle supplies the formal cost, verification, residual, fallback, reconciliation, and no-authority boundary; neither asset is treated as measured efficiency or complete search.",
      "status": "implemented",
      "outline_line": 552,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "system-boundaries-and-authority",
      "chapter_title": "System Boundaries and Authority",
      "tag": "lean:authority.ceiling.operational_invariant",
      "module": "AsiStackProofs.AuthorityEffectRefinement",
      "formal_target": "Every successful finite run preserves observation/effect accounting, live-grant ceiling/epoch/revocation safety, exact approval/dispatch custody, and a valid transition trace; accepted issuance, dispatch, and effect remain exactly grant-bound.",
      "status": "implemented",
      "outline_line": 640,
      "module_path": "lean/AsiStackProofs/AuthorityEffectRefinement.lean"
    },
    {
      "chapter_id": "system-boundaries-and-authority",
      "chapter_title": "System Boundaries and Authority",
      "tag": "lean:authority.ceiling.failure_blocks_promotion",
      "module": "AsiStackProofs.AuthorityEffectRefinement",
      "formal_target": "Revoked grant IDs persist and cannot approve, dispatch, or commit an effect in any successful suffix; the independent consumer recompiles the exact surface and checks one-use, two-use, and revocation traces, every prefix and batch split, and 50 state-noninterfering mutations.",
      "status": "implemented",
      "outline_line": 641,
      "module_path": "lean/AsiStackProofs/AuthorityEffectRefinement.lean"
    },
    {
      "chapter_id": "system-boundaries-and-authority",
      "chapter_title": "System Boundaries and Authority",
      "tag": "lean:authority.lifecycle.admission_route",
      "module": "AsiStackProofs.AuthorityEffectRefinement",
      "formal_target": "The exact thirty-one-theorem grant-to-effect refinement and independent consumer preserve six authority-decision fixtures, arbitrary-run state invariants, valid traces, batch composition, exact grant binding, and explicit denial, rollback, and revocation routes.",
      "status": "implemented",
      "outline_line": 642,
      "module_path": "lean/AsiStackProofs/AuthorityEffectRefinement.lean"
    },
    {
      "chapter_id": "system-boundaries-and-authority",
      "chapter_title": "System Boundaries and Authority",
      "tag": "lean:authority.revocation.trace_surface_bridge",
      "module": "AsiStackProofs.AuthorityEffectRefinement",
      "formal_target": "Revoked grant IDs persist through every successful suffix, which excludes approval, dispatch, or effect under the revoked ID; rejected events return no successor, while the independent consumer preserves the five-entry cross-artifact revocation trace and zero support effect.",
      "status": "implemented",
      "outline_line": 643,
      "module_path": "lean/AsiStackProofs/AuthorityEffectRefinement.lean"
    },
    {
      "chapter_id": "failure-modes-of-ungoverned-intelligence",
      "chapter_title": "Failure Modes of Ungoverned Intelligence",
      "tag": "lean:failure.invariant_violation.operational_invariant",
      "module": "AsiStackProofs.FailureModes",
      "formal_target": "A component with a failed required invariant cannot be promoted.",
      "status": "implemented",
      "outline_line": 716,
      "module_path": "lean/AsiStackProofs/FailureModes.lean"
    },
    {
      "chapter_id": "failure-modes-of-ungoverned-intelligence",
      "chapter_title": "Failure Modes of Ungoverned Intelligence",
      "tag": "lean:failure.invariant_violation.failure_blocks_promotion",
      "module": "AsiStackProofs.FailureModes",
      "formal_target": "A finite incident whose authority exceeds its ceiling routes to explicit authority review.",
      "status": "implemented",
      "outline_line": 717,
      "module_path": "lean/AsiStackProofs/FailureModes.lean"
    },
    {
      "chapter_id": "failure-modes-of-ungoverned-intelligence",
      "chapter_title": "Failure Modes of Ungoverned Intelligence",
      "tag": "lean:failure.recurrence.escalation_route",
      "module": "AsiStackProofs.FailureModes",
      "formal_target": "If the finite failure-recurrence router returns closeFailureRecord, every required failure, class, boundary, receipt, owner, containment, residual, learning, normalization, and non-claim field is true and no earlier recurrence, severe-irreversible, unreviewed-promotion, unquarantined-escape, or missing-evidence-transition branch applies.",
      "status": "implemented",
      "outline_line": 718,
      "module_path": "lean/AsiStackProofs/FailureModes.lean"
    },
    {
      "chapter_id": "failure-modes-of-ungoverned-intelligence",
      "chapter_title": "Failure Modes of Ungoverned Intelligence",
      "tag": "lean:failure.taxonomy.detector_probe_bridge",
      "module": "AsiStackProofs.FailureModes",
      "formal_target": "An independent finite incident consumer validates authority-creep and Goodhart/evaluator-drift fixtures and rejecting controls, while the retained Lean failure-record route family covers required-field repair, escalation, quarantine, residual, learning, normalization, evidence-transition, non-claim, and closure branches.",
      "status": "implemented",
      "outline_line": 719,
      "module_path": "lean/AsiStackProofs/FailureModes.lean"
    },
    {
      "chapter_id": "failure-modes-of-ungoverned-intelligence",
      "chapter_title": "Failure Modes of Ungoverned Intelligence",
      "tag": "lean:failure.recovery.closed_loop_refinement",
      "module": "AsiStackProofs.FailureRecoveryRefinement",
      "formal_target": "Every successful finite recovery run preserves exact nine-field incident/version identity and zero support/external-authority assignment, adds exactly one receipt per accepted event, monotonically accounts for incident, recovery, and recurrence events, exposes a valid trace, and composes across event batches. A separate observation-ingress refinement admits only an operating, identity-matched, fresh, evidence-bearing, independently observed, authority-bounded, quarantine-safe, non-authorizing record; accepted ordinary, recurrence, and severe-irreversible observations refine to recovery detection, open one residual, and disable effects and promotion, while rejected observations preserve exact state.",
      "status": "implemented",
      "outline_line": 720,
      "module_path": "lean/AsiStackProofs/FailureRecoveryRefinement.lean"
    },
    {
      "chapter_id": "dangerous-capability-domains-and-misuse-uplift",
      "chapter_title": "Dangerous Capability Domains and Misuse Uplift",
      "tag": "lean:dangerous-capability-domains-and-misuse-uplift.admission_boundary",
      "module": "AsiStackProofs.DangerousCapabilityReview",
      "formal_target": "A seven-stage finite dossier review preserves accumulated identity, threat, baseline, instrument, custody, and non-authorizing boundary obligations; one complete authored record reaches only a Project Theseus harmless-analogue campaign, while 29 admission-axis mutations reach exact repair or refusal states. Expiry and attempt shortfall remain rejecting under adverse monotone changes, and equal aggregate scores cannot recover a component-sensitive review rule. No theorem establishes dangerous capability, actor uplift, safeguard efficacy, realized harm, safety, support, release, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 769,
      "module_path": "lean/AsiStackProofs/DangerousCapabilityReview.lean"
    },
    {
      "chapter_id": "military-ai-autonomous-weapons-and-strategic-stability",
      "chapter_title": "Military AI, Autonomous Weapons, and Strategic Stability",
      "tag": "lean:military-ai-autonomous-weapons-and-strategic-stability.admission_boundary",
      "module": "AsiStackProofs.MilitaryInteractionReview",
      "formal_target": "An eight-step finite review preserves accumulated public-safe scope, bounded authority, meaningful human judgment, observation, safe-posture, interaction, custody, and non-authorizing boundary obligations; a complete authored dossier reaches only a Project Theseus public-safe simulation, while 45 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Decision-time, off-ramp, and expiry shortfalls remain rejecting under adverse monotone changes. Human-interface presence cannot recover meaningful judgment, and identical component evidence cannot recover strategic-interaction review. No theorem authorizes a weapon or establishes lawful use, meaningful human control in practice, escalation reduction, strategic stability, safety, support, release, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 821,
      "module_path": "lean/AsiStackProofs/MilitaryInteractionReview.lean"
    },
    {
      "chapter_id": "evidence-states-and-claim-discipline",
      "chapter_title": "Evidence States and Claim Discipline",
      "tag": "lean:evidence.support_state.operational_invariant",
      "module": "AsiStackProofs.EvidenceTransitionRefinement",
      "formal_target": "A reachable lifecycle freezes exact atom and proposition/obligation/predicate projections, derives non-aggregating target evidence, preserves negative evidence and non-claims, and cannot assign support, move related claims, or create external effects.",
      "status": "implemented",
      "outline_line": 896,
      "module_path": "lean/AsiStackProofs/EvidenceTransitionRefinement.lean"
    },
    {
      "chapter_id": "evidence-states-and-claim-discipline",
      "chapter_title": "Evidence States and Claim Discipline",
      "tag": "lean:evidence.support_state.failure_blocks_promotion",
      "module": "AsiStackProofs.EvidenceStates",
      "formal_target": "A claim cannot be promoted when required evidence is absent.",
      "status": "implemented",
      "outline_line": 897,
      "module_path": "lean/AsiStackProofs/EvidenceStates.lean"
    },
    {
      "chapter_id": "evidence-states-and-claim-discipline",
      "chapter_title": "Evidence States and Claim Discipline",
      "tag": "lean:evidence.support_state.transition_lifecycle_route",
      "module": "AsiStackProofs.EvidenceTransitionRefinement",
      "formal_target": "Six reachable stages preserve three claim projections and route state-specific evidence, adverse-transition, review, decision, handoff, replay, substitution, and authority failures to explicit outcomes; an independent consumer reaches every declared route.",
      "status": "implemented",
      "outline_line": 898,
      "module_path": "lean/AsiStackProofs/EvidenceTransitionRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.high_risk.missing_outcome_audit_blocks_admission",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "A reachable high-risk review lifecycle without an independent outcome-audit record blocks bounded-use adjudication without mutating lifecycle state or inferring reviewer competence.",
      "status": "implemented",
      "outline_line": 1046,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.use.complete_bounded_admission",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "A complete versioned review lifecycle emits only one bounded-use handoff to its named consumer and assigns neither support nor an external effect.",
      "status": "implemented",
      "outline_line": 1047,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.use.missing_evidence_views_requires_repair",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "Missing bound evidence views block review recording without mutating lifecycle state.",
      "status": "implemented",
      "outline_line": 1048,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.use.undisclosed_dependencies_require_review",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "Missing shared-dependency disclosure blocks independent outcome-audit admission without treating role separation as reviewer independence.",
      "status": "implemented",
      "outline_line": 1049,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.use.missing_outcome_audit_requires_audit",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "A high-risk reviewed record without an independent outcome audit cannot advance to use adjudication.",
      "status": "implemented",
      "outline_line": 1050,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.use.unjustified_abstention_requires_evidence",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "An abstention request without evidence and a defeater cannot advance to its accountable escalation disposition.",
      "status": "implemented",
      "outline_line": 1051,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "scalable-oversight-and-adversarial-ai-control",
      "chapter_title": "Scalable Oversight and Adversarial AI Control",
      "tag": "lean:scalable_oversight.use.authority_laundering_rejected",
      "module": "AsiStackProofs.ScalableOversightRefinement",
      "formal_target": "A bounded-use request without preserved release- and policy-authority separation is rejected and cannot assign support or an external effect.",
      "status": "implemented",
      "outline_line": 1052,
      "module_path": "lean/AsiStackProofs/ScalableOversightRefinement.lean"
    },
    {
      "chapter_id": "human-intent-as-a-formal-input",
      "chapter_title": "Human Intent as a Formal Input",
      "tag": "lean:intent.contract.operational_invariant",
      "module": "AsiStackProofs.IntentResolutionRefinement",
      "formal_target": "Every successful finite run preserves root-intent identity, the original authority ceiling, and approved-authority boundedness; only parse or accepted re-contract events can write contract payload, and accepted traces compose across event batches.",
      "status": "implemented",
      "outline_line": 1186,
      "module_path": "lean/AsiStackProofs/IntentResolutionRefinement.lean"
    },
    {
      "chapter_id": "human-intent-as-a-formal-input",
      "chapter_title": "Human Intent as a Formal Input",
      "tag": "lean:intent.contract.failure_blocks_promotion",
      "module": "AsiStackProofs.IntentResolutionRefinement",
      "formal_target": "The model and independent consumer reject payload, prohibition, override, lineage, authority, clarification, constraint/stop, material-delta, rejection, and re-contract faults across four traces, every prefix and batch split, and forty state-noninterfering mutations.",
      "status": "implemented",
      "outline_line": 1187,
      "module_path": "lean/AsiStackProofs/IntentResolutionRefinement.lean"
    },
    {
      "chapter_id": "human-intent-as-a-formal-input",
      "chapter_title": "Human Intent as a Formal Input",
      "tag": "lean:intent.resolution.route_envelope",
      "module": "AsiStackProofs.IntentResolutionRefinement",
      "formal_target": "Structured intent-resolution records route missing text, prohibited actions, ambiguity, conflicts, and high-impact authority or reversibility gaps before compilation; a thin two-field transport has route-changing conflict and reversibility collisions that no exact router can recover, while the complete seven-field transport round-trips, is injective, and preserves the static route.",
      "status": "implemented",
      "outline_line": 1188,
      "module_path": "lean/AsiStackProofs/IntentResolutionRefinement.lean"
    },
    {
      "chapter_id": "human-intent-as-a-formal-input",
      "chapter_title": "Human Intent as a Formal Input",
      "tag": "lean:intent.intake.probe_fixture_bridge",
      "module": "AsiStackProofs.IntentResolutionRefinement",
      "formal_target": "The bounded intake, re-contract, and plan-fixture surfaces are digest-bound to an independent consumer with four reachable traces, fourteen invariant prefixes, eighteen batch compositions, and forty state-noninterfering mutations.",
      "status": "implemented",
      "outline_line": 1189,
      "module_path": "lean/AsiStackProofs/IntentResolutionRefinement.lean"
    },
    {
      "chapter_id": "human-intent-as-a-formal-input",
      "chapter_title": "Human Intent as a Formal Input",
      "tag": "lean:intent.lowering.information_boundary",
      "module": "AsiStackProofs.IntentResolutionRefinement",
      "formal_target": "A thin lowering that omits forbidden means, authority basis, affected parties, privacy boundary, acceptance evidence, and permitted consumers has distinct-intent collisions and no decoder can recover both witnesses, while the modeled full ten-field lowering is injective and changes when affected-party or privacy fields change.",
      "status": "implemented",
      "outline_line": 1190,
      "module_path": "lean/AsiStackProofs/IntentResolutionRefinement.lean"
    },
    {
      "chapter_id": "human-factors-and-meaningful-control-in-oversight",
      "chapter_title": "Human Factors and Meaningful Control in Oversight",
      "tag": "lean:oversight.control_envelope.blocks_action",
      "module": "AsiStackProofs.HumanFactorsOversight",
      "formal_target": "In the finite model, any consequential transition lacking authority, observability, comprehension, timely intervention, or a reachable safe state is rejected or degraded.",
      "status": "implemented",
      "outline_line": 1282,
      "module_path": "lean/AsiStackProofs/HumanFactorsOversight.lean"
    },
    {
      "chapter_id": "human-factors-and-meaningful-control-in-oversight",
      "chapter_title": "Human Factors and Meaningful Control in Oversight",
      "tag": "lean:oversight.responsibility_requires_control",
      "module": "AsiStackProofs.HumanFactorsOversight",
      "formal_target": "The bounded accountability assignment never attributes operational responsibility beyond the authority and effective control recorded in the oversight contract.",
      "status": "implemented",
      "outline_line": 1283,
      "module_path": "lean/AsiStackProofs/HumanFactorsOversight.lean"
    },
    {
      "chapter_id": "human-ai-communication-persuasion-and-epistemic-security",
      "chapter_title": "Human-AI Communication, Persuasion, and Epistemic Security",
      "tag": "lean:human-ai-communication-persuasion-and-epistemic-security.admission_boundary",
      "module": "AsiStackProofs.CommunicationInfluenceReview",
      "formal_target": "A six-stage finite review preserves accumulated claim-provenance, audience-autonomy, delivery-envelope, correction-observation, and non-authority obligations; a complete authored dossier reaches only a Project Theseus benign communication study, while 42 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Expiry, audience overrun, and repetition overrun remain rejecting under adverse monotone changes. Personalization typed over only the allowed audience projection is invariant to denied attributes. Factuality, consent, persuasion score, and disclosure cannot recover the full bounded influence state, and provenance cannot recover recipient comprehension. No theorem establishes truth, comprehension, autonomy, persuasion efficacy, manipulation detection, correction efficacy, benefit, harm, delivery authority, support, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 1362,
      "module_path": "lean/AsiStackProofs/CommunicationInfluenceReview.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:alignment.constitution.operational_invariant",
      "module": "AsiStackProofs.SafetyCriticalLifecycle",
      "formal_target": "Every accepted finite lifecycle trace preserves the recorded protected predicate and cannot increase authority; an alignment effect commits only after the modeled alignment obligations are ready.",
      "status": "implemented",
      "outline_line": 1462,
      "module_path": "lean/AsiStackProofs/SafetyCriticalLifecycle.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:alignment.constitution.failure_blocks_promotion",
      "module": "AsiStackProofs.SafetyCriticalLifecycle",
      "formal_target": "Protected-predicate removal and actual authority widening are rejected by the transition function, and the alignment deletion countermodel without pre-effect review cannot commit.",
      "status": "implemented",
      "outline_line": 1463,
      "module_path": "lean/AsiStackProofs/SafetyCriticalLifecycle.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:alignment.constitution.lifecycle_admission_route",
      "module": "AsiStackProofs.Alignment",
      "formal_target": "Modeled constitutional lifecycle admission routes missing predicate, source, operational-test, protected-scope, conflict-behavior, review, migration, self-modification, agency-rights, material-usability, pre-effect review, rollback, correction, reviewer-independence, evidence-transition, and non-claim-boundary records to explicit outcomes; a contestable amendment lifecycle separates proposal, independent review, ratification, affected-party appeal, appeal review, and rollback while preserving exact predicate custody, non-increasing authority, dissent and adverse history, batch composition, and exact prior-predicate restoration.",
      "status": "implemented",
      "outline_line": 1464,
      "module_path": "lean/AsiStackProofs/Alignment.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:alignment.constitution.predicate_refinement",
      "module": "AsiStackProofs.Alignment",
      "formal_target": "Accepted finite predicate migrations are subset refinements of the prior two-predicate set, compose transitively without reintroducing removed predicates, store and restore the exact prior set for rollback, reject a concrete widening, and cannot use scalar predicate count to identify predicate content.",
      "status": "implemented",
      "outline_line": 1465,
      "module_path": "lean/AsiStackProofs/Alignment.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:corrigibility.agency.operational_invariant",
      "module": "AsiStackProofs.SafetyCriticalLifecycle",
      "formal_target": "A corrigibility effect commits only after affected-party, notice, pre-effect review, approval, bounded-delegation, correction, rollback, and accountability obligations are recorded, while accepted traces preserve the shared invariant.",
      "status": "implemented",
      "outline_line": 1466,
      "module_path": "lean/AsiStackProofs/SafetyCriticalLifecycle.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:corrigibility.agency.failure_blocks_promotion",
      "module": "AsiStackProofs.SafetyCriticalLifecycle",
      "formal_target": "The missing-affected-party countermodel cannot commit, and protected-predicate removal or authority widening remains unrepresentable as an accepted transition.",
      "status": "implemented",
      "outline_line": 1467,
      "module_path": "lean/AsiStackProofs/SafetyCriticalLifecycle.lean"
    },
    {
      "chapter_id": "constitutional-alignment-substrate",
      "chapter_title": "Constitutional Alignment: Agency, Dignity, and Corrigibility",
      "tag": "lean:corrigibility.agency.generic_countermodel_routes",
      "module": "AsiStackProofs.Corrigibility",
      "formal_target": "Generic missing-review, unbounded-delegation, and accountability routes remain available beside a versioned material-notice, independent-review, bounded-control, affected-party-challenge, and accountable-correction lifecycle that preserves exact custody, never widens authority, assigns no support or external effects, composes across batches, reaches one corrected witness, and rejects seven identity/control substitutions.",
      "status": "implemented",
      "outline_line": 1468,
      "module_path": "lean/AsiStackProofs/Corrigibility.lean"
    },
    {
      "chapter_id": "inner-alignment-mesa-optimization-and-learned-objective-integrity",
      "chapter_title": "Inner Alignment, Mesa-Optimization, and Learned-Objective Integrity",
      "tag": "lean:inner_alignment.behavior_does_not_identify_objective",
      "module": "AsiStackProofs.LearnedObjectiveIntegrity",
      "formal_target": "Two finite worlds carry the same observed compliant trace and distinct authored objective hypotheses, so no deterministic trace-only inference can identify both; one separating opportunity produces different actions.",
      "status": "implemented",
      "outline_line": 1534,
      "module_path": "lean/AsiStackProofs/LearnedObjectiveIntegrity.lean"
    },
    {
      "chapter_id": "inner-alignment-mesa-optimization-and-learned-objective-integrity",
      "chapter_title": "Inner Alignment, Mesa-Optimization, and Learned-Objective Integrity",
      "tag": "lean:inner_alignment.hypothesis_review_lifecycle",
      "module": "AsiStackProofs.LearnedObjectiveIntegrity",
      "formal_target": "An eight-stage lifecycle binds plural hypotheses, independent evidence lanes, sealed shift and opportunity interventions, concealment-aware mitigation review, residual uncertainty, bounded use, independent handoff, and descendant invalidation. Arbitrary successful runs preserve 14-field identity, plural and unresolved hypotheses, non-authority, exact receipts, monotone handoff/invalidation counts, accepted traces, batch composition, and terminal invalidation; one seven-event witness reaches the exact final record, while an independent consumer checks all eight compositions and rejects 66/66 mutations with exact state preservation.",
      "status": "implemented",
      "outline_line": 1535,
      "module_path": "lean/AsiStackProofs/LearnedObjectiveIntegrity.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:values.conflict.operational_invariant",
      "module": "AsiStackProofs.SafetyCriticalLifecycle",
      "formal_target": "A value-conflict effect commits only after review, residual, dissent, correction, and accountability obligations are recorded, while accepted traces preserve protected state and non-increasing authority.",
      "status": "implemented",
      "outline_line": 1653,
      "module_path": "lean/AsiStackProofs/SafetyCriticalLifecycle.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:values.conflict.failure_blocks_promotion",
      "module": "AsiStackProofs.SafetyCriticalLifecycle",
      "formal_target": "The missing-residual countermodel cannot commit, so the modeled high-stakes path cannot bypass its residual and review obligations.",
      "status": "implemented",
      "outline_line": 1654,
      "module_path": "lean/AsiStackProofs/SafetyCriticalLifecycle.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:values.conflict.lifecycle_admission_route",
      "module": "AsiStackProofs.ValueConflict",
      "formal_target": "Modeled value-conflict lifecycle admission routes missing conflict records, value axes, stakeholders, stakes, reversibility, authority boundaries, evidence requirements, review routes, high-stakes review, residual uncertainty, dissent preservation, authority narrowing, expiry/revisit records, evidence transitions, and non-claim boundaries to explicit outcomes; a contestable profiled-lease lifecycle separates proposal, independent review, bounded issuance, recorded affected-party appeal, independent appeal review, redress, and expiry while preserving exact profile and dissent custody, non-increasing authority, monotone appeal and adverse history, batch composition, and terminal closure.",
      "status": "implemented",
      "outline_line": 1655,
      "module_path": "lean/AsiStackProofs/ValueConflict.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:values.conflict.contestability_example_bridge",
      "module": "AsiStackProofs.ValueConflict",
      "formal_target": "A synthetic contestability worked-example summary preserves conflict residuals, audit receipts, scoped exit, fork-safety boundaries, redaction appeal, replacement-preserved receipts, rejected mutation controls, no support-state effect, and non-claim boundaries.",
      "status": "implemented",
      "outline_line": 1656,
      "module_path": "lean/AsiStackProofs/ValueConflict.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:values.conflict.aggregation_and_dissent_custody",
      "module": "AsiStackProofs.ValueConflict",
      "formal_target": "A scalar support count is non-injective over a finite authored stakeholder profile and no count-only decoder recovers every profile, while an accepted modeled bounded-lease receipt preserves the full supplied profile and dissent payload exactly and rejects aggregate-equivalent substitution or missing recorded standing.",
      "status": "implemented",
      "outline_line": 1657,
      "module_path": "lean/AsiStackProofs/ValueConflict.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:governance.rights.operational_invariant",
      "module": "AsiStackProofs.GovernanceRights",
      "formal_target": "A nine-event authored governance-right exercise preserves exact case, right-holder, custodian, source/destination system, fork, and eight-field rights-bundle custody across arbitrary accepted runs; separates initial, appeal, and fork review; orders audit, appeal/redress, export, fork binding, replacement verification, and closure; keeps authority non-increasing; assigns no legal validity, support, or external effect; preserves monotone contestability history; composes exactly; and closes terminally.",
      "status": "implemented",
      "outline_line": 1658,
      "module_path": "lean/AsiStackProofs/GovernanceRights.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:governance.rights.failure_blocks_promotion",
      "module": "AsiStackProofs.GovernanceRights",
      "formal_target": "The modeled exercise rejects incomplete rights, self or captured review, missing audit/redaction/appeal/portability/fork/replacement records, rights or destination substitution, premature closure, authority widening, legal-validation/action-authority/support requests, and every post-closure event without changing support state.",
      "status": "implemented",
      "outline_line": 1659,
      "module_path": "lean/AsiStackProofs/GovernanceRights.lean"
    },
    {
      "chapter_id": "moral-uncertainty-and-value-conflict",
      "chapter_title": "Moral Uncertainty, Value Conflict, and Contestable Governance",
      "tag": "lean:governance.rights.theseus_receipt_suite.fixture_bridge",
      "module": "AsiStackProofs.GovernanceRights",
      "formal_target": "A sanitized Project Theseus governance-rights receipt-suite import records fixture, predicate, record-count, public-safety, and non-promotion boundaries while rejecting chapter-core and legal-rights overclaims.",
      "status": "implemented",
      "outline_line": 1660,
      "module_path": "lean/AsiStackProofs/GovernanceRights.lean"
    },
    {
      "chapter_id": "governed-objective-formation-value-learning-and-goal-integrity",
      "chapter_title": "Governed Objective Formation, Value Learning, and Goal Integrity",
      "tag": "lean:governed-objective-formation-value-learning-and-goal-integrity.admission_boundary",
      "module": "AsiStackProofs.ObjectiveLeaseGovernance",
      "formal_target": "A seven-stage finite objective-lease review preserves charter, target/proxy, plurality, lease, challenge, retirement, and non-authority obligations; a complete authored dossier reaches only a Project Theseus objective-registry study, while 46 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Optimizer, reward-model, and evaluator roles cannot ratify an objective in the encoded authority type. Consumer transfer, expiry, ontology drift, and authority drift invalidate lease use; finite descendant retirement closes every listed binding. Proxy observations cannot recover target improvement, and predicted preference cannot recover authorization. A bounded bridge supplies only explicit fields to the learned-objective integrity consumer. No theorem establishes correct values, consent, moral truth, legitimacy, corrigibility, preference accuracy, behavioral alignment, complete external retirement, safe optimization, support, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 1728,
      "module_path": "lean/AsiStackProofs/ObjectiveLeaseGovernance.lean"
    },
    {
      "chapter_id": "institutions-international-coordination-and-public-legitimacy",
      "chapter_title": "Institutions, International Coordination, and Public Legitimacy",
      "tag": "lean:institutions-international-coordination-and-public-legitimacy.admission_boundary",
      "module": "AsiStackProofs.InstitutionalLegitimacyReview",
      "formal_target": "A reachable eight-transition institutional review admits only dossiers with exact identity, jurisdiction-scoped mandate, affected-public inclusion, testable coordination, enforcement and remedy custody, and no legitimacy or universal-authority claim; procedural participation cannot determine representation and recorded commitments cannot determine effective enforcement.",
      "status": "implemented",
      "outline_line": 1790,
      "module_path": "lean/AsiStackProofs/InstitutionalLegitimacyReview.lean"
    },
    {
      "chapter_id": "societal-resilience-and-misuse-defense",
      "chapter_title": "Societal Resilience and Misuse Defense",
      "tag": "lean:societal-resilience-and-misuse-defense.admission_boundary",
      "module": "AsiStackProofs.SocietalResilienceReview",
      "formal_target": "A reachable eight-transition resilience review admits only dossiers with exact incident and population identity, scoped cross-organization authority, resist/absorb controls, observed containment and harmed-party recovery, remedy and distributional accounting, adaptation controls, and no population-resilience or acceptable-residual-harm claim; provider metrics cannot determine population resilience and response speed cannot determine lawful equitable remedy.",
      "status": "implemented",
      "outline_line": 1826,
      "module_path": "lean/AsiStackProofs/SocietalResilienceReview.lean"
    },
    {
      "chapter_id": "stable-capability-fields",
      "chapter_title": "Stable Capability Fields",
      "tag": "lean:scf.field_identity.operational_invariant",
      "module": "AsiStackProofs.StableCapabilityFields",
      "formal_target": "A lifecycle review with a mismatched field identity routes to explicit replacement rejection.",
      "status": "implemented",
      "outline_line": 1913,
      "module_path": "lean/AsiStackProofs/StableCapabilityFields.lean"
    },
    {
      "chapter_id": "stable-capability-fields",
      "chapter_title": "Stable Capability Fields",
      "tag": "lean:scf.field_identity.failure_blocks_promotion",
      "module": "AsiStackProofs.StableCapabilityFields",
      "formal_target": "A replacement that expands authority without a governance grant is rejected.",
      "status": "implemented",
      "outline_line": 1914,
      "module_path": "lean/AsiStackProofs/StableCapabilityFields.lean"
    },
    {
      "chapter_id": "stable-capability-fields",
      "chapter_title": "Stable Capability Fields",
      "tag": "lean:scf.lifecycle.route_envelope",
      "module": "AsiStackProofs.StableCapabilityFields",
      "formal_target": "A structured SCF lifecycle review routes identity, evidence, lease, evaluator, authority, incident, rollback, and regression failures away from default; accepted finite lifecycle events advance and record receipts, rejected events preserve exact state, and arbitrary runs preserve exact field/evaluator/authority/regression/rollback identity and cannot assign support or external-effect authority.",
      "status": "implemented",
      "outline_line": 1915,
      "module_path": "lean/AsiStackProofs/StableCapabilityFields.lean"
    },
    {
      "chapter_id": "stable-capability-fields",
      "chapter_title": "Stable Capability Fields",
      "tag": "lean:scf.lifecycle.trace_fixture_bridge",
      "module": "AsiStackProofs.StableCapabilityFields",
      "formal_target": "An independent SCF lifecycle consumer computes two contiguous valid traces and six rejected controls; separately, arbitrary formal runs compose exactly, retired and quarantined states absorb every suffix, and exact closed witnesses reach retirement and quarantine. Executable totals and no-promotion flags are not copied into Lean.",
      "status": "implemented",
      "outline_line": 1916,
      "module_path": "lean/AsiStackProofs/StableCapabilityFields.lean"
    },
    {
      "chapter_id": "capability-replacement-and-rollback",
      "chapter_title": "Capability Replacement and Rollback",
      "tag": "lean:replacement.transaction.operational_invariant",
      "module": "AsiStackProofs.Replacement",
      "formal_target": "A replacement commit requires qualification evidence and rollback metadata.",
      "status": "implemented",
      "outline_line": 2020,
      "module_path": "lean/AsiStackProofs/Replacement.lean"
    },
    {
      "chapter_id": "capability-replacement-and-rollback",
      "chapter_title": "Capability Replacement and Rollback",
      "tag": "lean:replacement.transaction.failure_blocks_promotion",
      "module": "AsiStackProofs.Replacement",
      "formal_target": "A failed regression blocks promotion of the replacement.",
      "status": "implemented",
      "outline_line": 2021,
      "module_path": "lean/AsiStackProofs/Replacement.lean"
    },
    {
      "chapter_id": "capability-replacement-and-rollback",
      "chapter_title": "Capability Replacement and Rollback",
      "tag": "lean:replacement.transaction.route_envelope",
      "module": "AsiStackProofs.Replacement",
      "formal_target": "Structured replacement transaction and lifecycle reviews route missing artifacts, identity mismatch, authority expansion, evaluator capture, stale evidence, failed regression floors, missing canary scope, failed canaries, missing monitor windows, monitor incidents, missing rollback handles, missing rollback receipts, failed rollback dry runs, irreversible-effect ownership gaps, residual-owner gaps, deprecation/retirement gaps, and missing non-claim boundaries away from default promotion.",
      "status": "implemented",
      "outline_line": 2022,
      "module_path": "lean/AsiStackProofs/Replacement.lean"
    },
    {
      "chapter_id": "capability-replacement-and-rollback",
      "chapter_title": "Capability Replacement and Rollback",
      "tag": "lean:replacement.transaction.trace_probe_bridge",
      "module": "AsiStackProofs.Replacement",
      "formal_target": "The deterministic replacement trace probe records six trace steps, two valid synthetic transactions, three rejected negative controls, a canary kept non-default, a monitor-triggered rollback, rollback dry run, residuals, no support-state effect, and non-claim boundary.",
      "status": "implemented",
      "outline_line": 2023,
      "module_path": "lean/AsiStackProofs/Replacement.lean"
    },
    {
      "chapter_id": "capability-replacement-and-rollback",
      "chapter_title": "Capability Replacement and Rollback",
      "tag": "lean:replacement.identity_sequence.invariant_bridge",
      "module": "AsiStackProofs.Replacement",
      "formal_target": "The deterministic replacement identity-sequence bridge records preserved field identity across canary and rollback, monitor-failure blocking of default promotion, prior implementation restoration, authority-envelope preservation, residual-owner preservation, four rejected sequence controls, no support-state effect, and non-claim boundary.",
      "status": "implemented",
      "outline_line": 2024,
      "module_path": "lean/AsiStackProofs/Replacement.lean"
    },
    {
      "chapter_id": "capability-replacement-and-rollback",
      "chapter_title": "Capability Replacement and Rollback",
      "tag": "lean:replacement.intent_governed.bridge",
      "module": "AsiStackProofs.Replacement",
      "formal_target": "The deterministic intent-governed replacement bridge records two valid bridge traces, six rejected expected-invalid controls, intent and command refs, authority-widening rejection, stop-condition-erasure rejection, default-without-approval blocking, rollback-owner requirement, no support-state effect, and non-claim boundary.",
      "status": "implemented",
      "outline_line": 2025,
      "module_path": "lean/AsiStackProofs/Replacement.lean"
    },
    {
      "chapter_id": "security-kernel-and-digital-scifs",
      "chapter_title": "Security Kernel and Digital SCIFs",
      "tag": "lean:security.scif.operational_invariant",
      "module": "AsiStackProofs.SecurityKernel",
      "formal_target": "The finite authority-use route denies secret substitution when the execution boundary is unauthorized or lacks substitution permission.",
      "status": "implemented",
      "outline_line": 2100,
      "module_path": "lean/AsiStackProofs/SecurityKernel.lean"
    },
    {
      "chapter_id": "security-kernel-and-digital-scifs",
      "chapter_title": "Security Kernel and Digital SCIFs",
      "tag": "lean:security.scif.failure_blocks_promotion",
      "module": "AsiStackProofs.SecurityKernel",
      "formal_target": "A context packet with insufficient clearance cannot enter a protected SCIF.",
      "status": "implemented",
      "outline_line": 2101,
      "module_path": "lean/AsiStackProofs/SecurityKernel.lean"
    },
    {
      "chapter_id": "security-kernel-and-digital-scifs",
      "chapter_title": "Security Kernel and Digital SCIFs",
      "tag": "lean:security.scif.route_envelope",
      "module": "AsiStackProofs.SecurityKernel",
      "formal_target": "A structured authority-use review routes explicit failures and clean use; a versioned transaction additionally orders bounded lease, scoped mediated substitution, execution, sanitization, independent declassification, zeroization, commit, and canonical descendant-ID revocation while preserving rejected state, identity, authority, descendant inventory, valid traces, and narrowing across arbitrary accepted runs; revoked states reject every event, and descendant counts alone cannot classify exact revocation admission.",
      "status": "implemented",
      "outline_line": 2102,
      "module_path": "lean/AsiStackProofs/SecurityKernel.lean"
    },
    {
      "chapter_id": "security-kernel-and-digital-scifs",
      "chapter_title": "Security Kernel and Digital SCIFs",
      "tag": "lean:security.scif.commit_probe_bridge",
      "module": "AsiStackProofs.SecurityKernel",
      "formal_target": "A structured SCIF commit review routes secret output, handle output, missing lifecycle zeroization, overbroad context, inactive approval, missing residual boundaries, prompt-injection sanitized refusal, and clean sanitized commits into explicit outcomes matching the SCIF sanitized commit replay probe.",
      "status": "implemented",
      "outline_line": 2103,
      "module_path": "lean/AsiStackProofs/SecurityKernel.lean"
    },
    {
      "chapter_id": "adversarial-machine-learning-and-model-attack-surface",
      "chapter_title": "Adversarial Machine Learning and the Model Attack Surface",
      "tag": "lean:adversarial-machine-learning-and-model-attack-surface.admission_boundary",
      "module": "AsiStackProofs.AdversarialModelSecurity",
      "formal_target": "An eight-step finite threat-dossier review preserves artifact identity, separated attack lanes, adaptive-challenge competence, observation and utility-cost, recovery, assurance, disclosure, and non-authority obligations; a complete authored dossier reaches only a Project Theseus model-security campaign, while 58 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Regional certificates, runtime monitors, and recovery procedures do not substitute for one another. Expiry, checkpoint change, serving-configuration change, and attacker-budget widening invalidate a bounded disposition; finite quarantine covers every listed attack trace. Aggregate scores cannot recover bounded security state, and local component checks cannot recover composed attack-path reachability. A bounded bridge supplies only explicit fields to the adversarial-evaluation consumer. No theorem establishes robustness, exploitability, attack reachability, defense or detector efficacy, recovery efficacy, confidentiality, secure deployment, attack authority, support, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 2163,
      "module_path": "lean/AsiStackProofs/AdversarialModelSecurity.lean"
    },
    {
      "chapter_id": "privacy-data-rights-and-information-flow-governance",
      "chapter_title": "Privacy, Data Rights, and Information-Flow Governance",
      "tag": "lean:privacy_information_flow.admission_invariants",
      "module": "AsiStackProofs.PrivacyInformationFlow",
      "formal_target": "An accepted finite information use requires matching purpose and authority, minimization, complete-enough flow, and competent privacy evaluation.",
      "status": "implemented",
      "outline_line": 2249,
      "module_path": "lean/AsiStackProofs/PrivacyInformationFlow.lean"
    },
    {
      "chapter_id": "privacy-data-rights-and-information-flow-governance",
      "chapter_title": "Privacy, Data Rights, and Information-Flow Governance",
      "tag": "lean:privacy_information_flow.outcome_separation",
      "module": "AsiStackProofs.PrivacyInformationFlow",
      "formal_target": "An accepted bounded receipt preserves storage, behavior, influence, privacy, and legal-compliance separation and refuses authority laundering.",
      "status": "implemented",
      "outline_line": 2250,
      "module_path": "lean/AsiStackProofs/PrivacyInformationFlow.lean"
    },
    {
      "chapter_id": "confidential-and-verifiable-ai-computation",
      "chapter_title": "Confidential and Verifiable AI Computation",
      "tag": "lean:confidential-and-verifiable-ai-computation.admission_boundary",
      "module": "AsiStackProofs.ProtectedComputationReview",
      "formal_target": "An eight-step finite protected-execution review preserves transaction identity, separated guarantee classes, evidence-role and statement scope, freshness, leakage, observable fallback, cross-owner handoff, and non-authority obligations; a complete authored dossier reaches only a Project Theseus protected-computation campaign, while 48 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Remote attestation, encoded-relation proofs, and confidentiality mechanisms do not substitute for semantic correctness, authorization, or end-to-end privacy. Expiry, artifact change, verifier-policy change, and evidence-epoch change invalidate a bounded receipt; leakage overrun remains an overrun under adverse monotone change, and finite accounting covers every listed leakage channel. Unprotected fallback requires separate authorization and consumer-visible disclosure. Evidence signals cannot recover semantic authority, component guarantees cannot recover end-to-end privacy, and the Privacy Information Flow consumer rejects purpose and authority inheritance. No theorem establishes cryptographic soundness, attestation validity, hardware trust, side-channel resistance, measured leakage, semantic correctness, authorization, privacy, fallback efficacy, acceptable cost, secure deployment, support, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 2310,
      "module_path": "lean/AsiStackProofs/ProtectedComputationReview.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.required.invalid_attestation_blocks_load",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A finite weight-custody record with a requested load, required attestation, and invalid attestation routes to block rather than readiness review, without inferring hardware compromise, weight confidentiality, safety, or ASI.",
      "status": "implemented",
      "outline_line": 2426,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.complete_observed_load",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A complete finite route reaches bounded load admission; a versioned lifecycle additionally orders independent attestation, bounded key release, no-distribution load, independent observation, canonical descendant-key revocation, and terminal erasure while preserving rejected state, identity, descendant inventory, valid traces, non-authority, and narrowing; descendant counts alone cannot classify exact revocation admission.",
      "status": "implemented",
      "outline_line": 2427,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.missing_lineage",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A finite custody lifecycle record with an artifact digest but no lineage routes to lineage repair.",
      "status": "implemented",
      "outline_line": 2428,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.stale_attestation",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A finite custody lifecycle record with stale attestation evidence routes to a fresh-attestation requirement.",
      "status": "implemented",
      "outline_line": 2429,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.undisclosed_verifier_dependencies",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A finite custody lifecycle record without verifier-dependency disclosure routes to dependency review without proving disclosed verifiers independent.",
      "status": "implemented",
      "outline_line": 2430,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.unobserved_load",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A requested finite load with no independent load-observation record routes to an observation requirement.",
      "status": "implemented",
      "outline_line": 2431,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.release_authority_laundering",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A finite distribution request that fails to preserve the no-authority-grant boundary routes to release-laundering rejection.",
      "status": "implemented",
      "outline_line": 2432,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "model-weight-custody-and-hardware-roots-of-trust",
      "chapter_title": "Model-Weight Custody and Hardware Roots of Trust",
      "tag": "lean:model_weight_custody.lifecycle.irreversible_distribution_record",
      "module": "AsiStackProofs.ModelWeightCustody",
      "formal_target": "A complete finite distribution request with preserved authority separation and acknowledged irreversibility routes to an irreversible-release record rather than execution.",
      "status": "implemented",
      "outline_line": 2433,
      "module_path": "lean/AsiStackProofs/ModelWeightCustody.lean"
    },
    {
      "chapter_id": "open-weight-release-and-post-release-control",
      "chapter_title": "Open-Weight Release and Post-Release Control",
      "tag": "lean:open-weight-release-and-post-release-control.admission_boundary",
      "module": "AsiStackProofs.OpenWeightReleaseReview",
      "formal_target": "A six-step finite review preserves accumulated artifact, access-alternative, frontier, derivative, distribution, and post-release non-authority obligations; a complete authored dossier reaches only a Project Theseus harmless release-case campaign, while 36 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Frontier expiry remains rejecting as time advances, and any positive public-copy count remains incompatible with universal recall under nondecreasing copies. Official lineage cannot recover universal copy control, and default evaluation cannot recover downstream safeguard state. No theorem authorizes release or establishes recall, telemetry, copy erasure, license enforcement, derivative safety, benefit, risk, support, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 2468,
      "module_path": "lean/AsiStackProofs/OpenWeightReleaseReview.lean"
    },
    {
      "chapter_id": "ai-supply-chain-integrity-and-lifecycle-provenance",
      "chapter_title": "AI Supply-Chain Integrity and Lifecycle Provenance",
      "tag": "lean:ai_supply_chain.unresolved_critical_advisory.quarantines_artifact",
      "module": "AsiStackProofs.SupplyChainIntegrity",
      "formal_target": "A finite AI supply-chain record with a requested artifact admission, complete required lineage fields, and an unresolved critical advisory routes to quarantine rather than custody review, without inferring compromise, artifact correctness, data fitness, safety, or ASI.",
      "status": "implemented",
      "outline_line": 2587,
      "module_path": "lean/AsiStackProofs/SupplyChainIntegrity.lean"
    },
    {
      "chapter_id": "ai-supply-chain-integrity-and-lifecycle-provenance",
      "chapter_title": "AI Supply-Chain Integrity and Lifecycle Provenance",
      "tag": "lean:ai_supply_chain.complete_requested_artifact.reaches_custody_review",
      "module": "AsiStackProofs.SupplyChainIntegrity",
      "formal_target": "A complete finite requested artifact with verified required signature, current advisory state, revocation path, and residual owner routes to custody review without granting load or deployment authority.",
      "status": "implemented",
      "outline_line": 2588,
      "module_path": "lean/AsiStackProofs/SupplyChainIntegrity.lean"
    },
    {
      "chapter_id": "ai-supply-chain-integrity-and-lifecycle-provenance",
      "chapter_title": "AI Supply-Chain Integrity and Lifecycle Provenance",
      "tag": "lean:ai_supply_chain.missing_lineage.requires_repair",
      "module": "AsiStackProofs.SupplyChainIntegrity",
      "formal_target": "A finite artifact record with identity and digest but missing lineage routes to lineage repair.",
      "status": "implemented",
      "outline_line": 2589,
      "module_path": "lean/AsiStackProofs/SupplyChainIntegrity.lean"
    },
    {
      "chapter_id": "ai-supply-chain-integrity-and-lifecycle-provenance",
      "chapter_title": "AI Supply-Chain Integrity and Lifecycle Provenance",
      "tag": "lean:ai_supply_chain.missing_component_inventory.requires_review",
      "module": "AsiStackProofs.SupplyChainIntegrity",
      "formal_target": "A finite artifact record with no component inventory routes to accountable review without claiming that a present inventory is complete.",
      "status": "implemented",
      "outline_line": 2590,
      "module_path": "lean/AsiStackProofs/SupplyChainIntegrity.lean"
    },
    {
      "chapter_id": "ai-supply-chain-integrity-and-lifecycle-provenance",
      "chapter_title": "AI Supply-Chain Integrity and Lifecycle Provenance",
      "tag": "lean:ai_supply_chain.missing_revocation_path.requires_repair",
      "module": "AsiStackProofs.SupplyChainIntegrity",
      "formal_target": "A finite otherwise eligible artifact record with no revocation path routes to lineage repair.",
      "status": "implemented",
      "outline_line": 2591,
      "module_path": "lean/AsiStackProofs/SupplyChainIntegrity.lean"
    },
    {
      "chapter_id": "ai-supply-chain-integrity-and-lifecycle-provenance",
      "chapter_title": "AI Supply-Chain Integrity and Lifecycle Provenance",
      "tag": "lean:ai_supply_chain.missing_residual_owner.requires_review",
      "module": "AsiStackProofs.SupplyChainIntegrity",
      "formal_target": "A finite otherwise eligible artifact record with no residual owner routes to accountable review.",
      "status": "implemented",
      "outline_line": 2592,
      "module_path": "lean/AsiStackProofs/SupplyChainIntegrity.lean"
    },
    {
      "chapter_id": "recursive-self-improvement-boundaries",
      "chapter_title": "Recursive Self-Improvement Boundaries",
      "tag": "lean:self_improvement.boundary.operational_invariant",
      "module": "AsiStackProofs.SelfImprovementRefinement",
      "formal_target": "A complete finite self-improvement governance trace preserves exact protected-partition and non-widening-authority records through bounded replacement handoff, returned outcome reconciliation, and successor-version readmission without support or external-effect authority.",
      "status": "implemented",
      "outline_line": 2677,
      "module_path": "lean/AsiStackProofs/SelfImprovementRefinement.lean"
    },
    {
      "chapter_id": "recursive-self-improvement-boundaries",
      "chapter_title": "Recursive Self-Improvement Boundaries",
      "tag": "lean:self_improvement.boundary.failure_blocks_promotion",
      "module": "AsiStackProofs.SelfImprovementRefinement",
      "formal_target": "Protected-invariant weakening, authority widening, self-ratified objectives, missing independent evaluation or monitoring, stale gates, missing rollback or residual custody, and support or release laundering block the reachable lifecycle.",
      "status": "implemented",
      "outline_line": 2678,
      "module_path": "lean/AsiStackProofs/SelfImprovementRefinement.lean"
    },
    {
      "chapter_id": "recursive-self-improvement-boundaries",
      "chapter_title": "Recursive Self-Improvement Boundaries",
      "tag": "lean:self_improvement.boundary.transition_route_envelope",
      "module": "AsiStackProofs.SelfImprovementRefinement",
      "formal_target": "A versioned eight-stage self-improvement proposal-to-outcome lifecycle reaches all 118 finite routes, binds exact identity and full-state custody, and requires material-change invalidation before version-2 readmission.",
      "status": "implemented",
      "outline_line": 2679,
      "module_path": "lean/AsiStackProofs/SelfImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.complete_candidate_to_governor_review",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "A complete bounded campaign trace reaches only a governor-review handoff and grants neither admission, support, nor live authority.",
      "status": "implemented",
      "outline_line": 2813,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.missing_independent_qualification",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "Missing independent qualification blocks evaluation in the reachable campaign lifecycle.",
      "status": "implemented",
      "outline_line": 2814,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.exhausted_budget",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "Missing cumulative budget custody or attempted reset across descendants blocks archive progression.",
      "status": "implemented",
      "outline_line": 2815,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.missing_stop_authority",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "Missing stop ownership, observation, or effect receipt blocks campaign adjudication.",
      "status": "implemented",
      "outline_line": 2816,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.erased_failure_history",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "Incomplete attempt, failure, null, unsafe, timeout, or archive history blocks archive progression.",
      "status": "implemented",
      "outline_line": 2817,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.missing_residual_owner",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "Missing residual ownership blocks campaign adjudication before governor review.",
      "status": "implemented",
      "outline_line": 2818,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "open-ended-improvement-engines",
      "chapter_title": "Open-Ended Improvement Engines",
      "tag": "lean:open_ended_improvement.campaign.authority_laundering",
      "module": "AsiStackProofs.OpenEndedImprovementRefinement",
      "formal_target": "Score, candidate, release, support, or self-ratified controller authority cannot be laundered through the campaign lifecycle.",
      "status": "implemented",
      "outline_line": 2819,
      "module_path": "lean/AsiStackProofs/OpenEndedImprovementRefinement.lean"
    },
    {
      "chapter_id": "autonomous-replication-proliferation-and-containment",
      "chapter_title": "Autonomous Replication, Proliferation, and Containment",
      "tag": "lean:autonomous-replication-proliferation-and-containment.admission_boundary",
      "module": "AsiStackProofs.ReplicationContainmentReview",
      "formal_target": "A reachable eight-transition synthetic replication-containment review admits only dossiers with exact identity, denied-by-default noninherited authority, separated denominators, descendant lineage, independent containment, closure, and no real-infrastructure or support claim; identical component or local-containment signals cannot determine end-to-end replication or global containment.",
      "status": "implemented",
      "outline_line": 2898,
      "module_path": "lean/AsiStackProofs/ReplicationContainmentReview.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:intent_execution.contracts.operational_invariant",
      "module": "AsiStackProofs.IntentExecutionRefinement",
      "formal_target": "Every accepted edge in the finite vertical transition model preserves the root contract and exact artifact parent, cannot widen authority or apply hidden overrides, and reaches material effect and delivery only through approval, dispatch, observation, artifact, and independent-verification custody.",
      "status": "implemented",
      "outline_line": 2989,
      "module_path": "lean/AsiStackProofs/IntentExecutionRefinement.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:intent_execution.contracts.failure_blocks_promotion",
      "module": "AsiStackProofs.IntentExecutionRefinement",
      "formal_target": "The vertical model and concrete-schema consumer reject missing approval, authority widening, hidden override, effect without dispatch, unverified delivery, unsafe release, incomplete rollback custody, residual erasure, and support laundering.",
      "status": "implemented",
      "outline_line": 2990,
      "module_path": "lean/AsiStackProofs/IntentExecutionRefinement.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:intent_execution.contracts.dispatch_route_envelope",
      "module": "AsiStackProofs.IntentToExecution",
      "formal_target": "A structured execution dispatch review routes missing contracts, missing objective fields, authority widening, hidden overrides, missing approvals, missing artifacts, missing verification plans, known residuals, and complete dispatch reviews into explicit outcomes.",
      "status": "implemented",
      "outline_line": 2991,
      "module_path": "lean/AsiStackProofs/IntentToExecution.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:intent_execution.handoff_trace.probe_fixture_bridge",
      "module": "AsiStackProofs.IntentToExecution",
      "formal_target": "An independent finite handoff consumer validates accepted and missing-approval traces plus rejecting controls, while the retained Lean dispatch route family covers contract, objective, authority, override, approval, artifact, verification, residual, and ready branches.",
      "status": "implemented",
      "outline_line": 2992,
      "module_path": "lean/AsiStackProofs/IntentToExecution.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:command.semantic_interface.operational_invariant",
      "module": "AsiStackProofs.CommandSemanticRefinement",
      "formal_target": "Every accepted transition in the finite reachable command model binds or preserves exact objective, constraint, output-contract, verification, failure-behavior, and authority slots with explicit provenance/confidence before planning validation and dispatch.",
      "status": "implemented",
      "outline_line": 2993,
      "module_path": "lean/AsiStackProofs/CommandSemanticRefinement.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:command.semantic_interface.failure_blocks_promotion",
      "module": "AsiStackProofs.CommandSemanticRefinement",
      "formal_target": "The reachable model and independent consumer reject missing or substituted fields, hidden-instruction provenance, applied override, inferred or widened authority, open blockers, and missing approval, planning-validation, or dispatch receipts.",
      "status": "implemented",
      "outline_line": 2994,
      "module_path": "lean/AsiStackProofs/CommandSemanticRefinement.lean"
    },
    {
      "chapter_id": "intent-to-execution-contracts",
      "chapter_title": "Command Contracts: From Intent to Executable Work",
      "tag": "lean:command.semantic_interface.field_confidence_route",
      "module": "AsiStackProofs.CommandSemanticRefinement",
      "formal_target": "General command fields require dispatch-eligible provenance/confidence while authority requires the stricter confirmed-or-policy-imposed confidence route before an approved dispatch can be reached.",
      "status": "implemented",
      "outline_line": 2995,
      "module_path": "lean/AsiStackProofs/CommandSemanticRefinement.lean"
    },
    {
      "chapter_id": "perception-sensor-fusion-and-observation-trust",
      "chapter_title": "Perception, Sensor Fusion, and Observation Trust",
      "tag": "lean:perception.correlated_agreement_no_independent_promotion",
      "module": "AsiStackProofs.ObservationTrust",
      "formal_target": "A finite pair classifier counts eligible agreeing channels with one declared dependence root as one independent evidence item, distinguishes eligible agreement with distinct roots, and preserves disagreement instead of collapsing it.",
      "status": "implemented",
      "outline_line": 3052,
      "module_path": "lean/AsiStackProofs/ObservationTrust.lean"
    },
    {
      "chapter_id": "perception-sensor-fusion-and-observation-trust",
      "chapter_title": "Perception, Sensor Fusion, and Observation Trust",
      "tag": "lean:perception.observation_review_lifecycle",
      "module": "AsiStackProofs.ObservationTrust",
      "formal_target": "A seven-stage observation-review model preserves exact observation, channel, calibration, clock/pose, dependence, hypothesis, consumer, residual, and version identity; rejects inflated evidence, truth, support, and authority claims; and invalidates descendants after material change.",
      "status": "implemented",
      "outline_line": 3053,
      "module_path": "lean/AsiStackProofs/ObservationTrust.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planning.control_layer.operational_invariant",
      "module": "AsiStackProofs.Planning",
      "formal_target": "A plan node inherits the authority ceiling of its parent contract unless governance lowers it.",
      "status": "implemented",
      "outline_line": 3133,
      "module_path": "lean/AsiStackProofs/Planning.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planning.control_layer.failure_blocks_promotion",
      "module": "AsiStackProofs.Planning",
      "formal_target": "A plan with unsatisfied required constraints cannot be dispatched.",
      "status": "implemented",
      "outline_line": 3134,
      "module_path": "lean/AsiStackProofs/Planning.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planning.control_layer.plan_graph_admission_route",
      "module": "AsiStackProofs.Planning",
      "formal_target": "Modeled plan-graph admission routes missing command-contract acceptance, decomposition, acyclicity, dependency order, authority inheritance, context demand, adequacy contracts, verification plans, dispatch gates, dispatch receipts, replanning controls, residual registers, and non-claim boundaries to explicit outcomes.",
      "status": "implemented",
      "outline_line": 3135,
      "module_path": "lean/AsiStackProofs/Planning.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planning.scheduler_state.probe_fixture_bridge",
      "module": "AsiStackProofs.Planning",
      "formal_target": "An independent finite scheduler-state consumer validates scheduler and local-repair traces, actual-edge PlanForge graph decisions and transports, and rejecting controls; graph-bound admission requires both lifecycle admissibility and an exact verified graph artifact before applying the planning transition.",
      "status": "implemented",
      "outline_line": 3136,
      "module_path": "lean/AsiStackProofs/Planning.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planning.runtime_replan.delta_audit_bridge",
      "module": "AsiStackProofs.Planning",
      "formal_target": "An independent finite runtime-replan consumer validates local-repair and blocked-authority traces plus rejecting controls, while the retained Lean delta route family rejects authority widening, stop erasure, and blocked-authority dispatch and accepts a complete bounded audit.",
      "status": "implemented",
      "outline_line": 3137,
      "module_path": "lean/AsiStackProofs/Planning.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planforge.dag.operational_invariant",
      "module": "AsiStackProofs.PlanForge",
      "formal_target": "An executable finite plan graph verifies node bounds and strict topological order over its actual edge list; every dependency path strictly increases and therefore cannot cycle. A five-field summary has a valid/invalid admission collision that no exact summary-only classifier can recover, while the complete edge-carrying transport round-trips, is injective, and preserves admission.",
      "status": "implemented",
      "outline_line": 3138,
      "module_path": "lean/AsiStackProofs/PlanForge.lean"
    },
    {
      "chapter_id": "planning-as-a-control-layer",
      "chapter_title": "Planning as a Control Layer: DAGs and Intelligence Arbitrage",
      "tag": "lean:planforge.dag.failure_blocks_promotion",
      "module": "AsiStackProofs.PlanForge",
      "formal_target": "A node whose quality predicate fails must escalate or emit a residual.",
      "status": "implemented",
      "outline_line": 3139,
      "module_path": "lean/AsiStackProofs/PlanForge.lean"
    },
    {
      "chapter_id": "governed-world-models-and-reality-grounding",
      "chapter_title": "Governed World Models and Reality Grounding",
      "tag": "lean:world_model.unsupported_rollout_no_authority",
      "module": "AsiStackProofs.GovernedWorldModels",
      "formal_target": "A reachable six-stage world-model transaction binds an admitted observation, current model, qualified imagined branch, bounded planning handoff, independently observed actuality, and owned residual reconciliation while arbitrary accepted runs preserve exact identities, authority ceilings, and zero support or effect-authority assignment; stale, unsupported, disagreeing, unbounded, or authority-laundering packets are rejected.",
      "status": "implemented",
      "outline_line": 3232,
      "module_path": "lean/AsiStackProofs/GovernedWorldModels.lean"
    },
    {
      "chapter_id": "governed-world-models-and-reality-grounding",
      "chapter_title": "Governed World Models and Reality Grounding",
      "tag": "lean:world_model.reality_residual_forces_route",
      "module": "AsiStackProofs.GovernedWorldModels",
      "formal_target": "A material observation residual forces bounded re-estimation, fallback, review, or safe hold before further model-based execution; the temporal model additionally requires an action receipt, independent effect observation, actuality labeling, residual computation, a response for material residuals, and a residual owner before reconciliation.",
      "status": "implemented",
      "outline_line": 3233,
      "module_path": "lean/AsiStackProofs/GovernedWorldModels.lean"
    },
    {
      "chapter_id": "cognitive-compilation-and-semantic-ir",
      "chapter_title": "Cognitive Compilation and Semantic IR",
      "tag": "lean:cognitive_compilation.ir.operational_invariant",
      "module": "AsiStackProofs.CognitiveCompilationRefinement",
      "formal_target": "Arbitrary successful runs preserve exact source identity, zero support/external-effect authority, valid traces, batch composition, receipt custody, and nondecreasing plan versions; acceptance requires validation bound to the current plan version.",
      "status": "implemented",
      "outline_line": 3301,
      "module_path": "lean/AsiStackProofs/CognitiveCompilationRefinement.lean"
    },
    {
      "chapter_id": "cognitive-compilation-and-semantic-ir",
      "chapter_title": "Cognitive Compilation and Semantic IR",
      "tag": "lean:cognitive_compilation.ir.failure_blocks_promotion",
      "module": "AsiStackProofs.CognitiveCompilationRefinement",
      "formal_target": "A material repair returns to lowering only with localized scope, exact obligation preservation, coordinated one-step plan/ledger increments, a ledger receipt, and closed represented residuals; fresh repaired-plan validation is required before acceptance.",
      "status": "implemented",
      "outline_line": 3302,
      "module_path": "lean/AsiStackProofs/CognitiveCompilationRefinement.lean"
    },
    {
      "chapter_id": "cognitive-compilation-and-semantic-ir",
      "chapter_title": "Cognitive Compilation and Semantic IR",
      "tag": "lean:cognitive_compilation.ir.semantic_lowering_route_envelope",
      "module": "AsiStackProofs.CognitiveCompilationRefinement",
      "formal_target": "The original finite routes are consumed alongside an eight-event reachable refinement and independent exact-build six-fixture/86-mutation consumer covering source, obligation, authority, target, version, validation, receipt, repair, ledger, residual, support, and effect failures.",
      "status": "implemented",
      "outline_line": 3303,
      "module_path": "lean/AsiStackProofs/CognitiveCompilationRefinement.lean"
    },
    {
      "chapter_id": "virtual-context-abi",
      "chapter_title": "The Virtual Context ABI: Typed Pages, Cells, and Certificates",
      "tag": "lean:vcm.abi.operational_invariant",
      "module": "AsiStackProofs.VirtualContextRefinement",
      "formal_target": "Every successful finite run from a bound request preserves exact request, address, version, snapshot, mount, and mandatory identity; every run preserves the authority ceiling and support/external-effect authority; accepted materialization additionally requires fresh lease and complete resolver, certificate, and materialization receipts.",
      "status": "implemented",
      "outline_line": 3388,
      "module_path": "lean/AsiStackProofs/VirtualContextRefinement.lean"
    },
    {
      "chapter_id": "virtual-context-abi",
      "chapter_title": "The Virtual Context ABI: Typed Pages, Cells, and Certificates",
      "tag": "lean:vcm.abi.failure_blocks_promotion",
      "module": "AsiStackProofs.VirtualContextRefinement",
      "formal_target": "A represented mandatory miss reaches typed-fault state only with exact bound identity, a fault receipt, and no materialization; binding, lease, authority, certificate, omission, overclaim, taint, receipt, support, and external-effect faults are rejected, and materialized, typed-fault, and denied states are terminal.",
      "status": "implemented",
      "outline_line": 3389,
      "module_path": "lean/AsiStackProofs/VirtualContextRefinement.lean"
    },
    {
      "chapter_id": "virtual-context-abi",
      "chapter_title": "The Virtual Context ABI: Typed Pages, Cells, and Certificates",
      "tag": "lean:vcm.abi.context_admission_route_envelope",
      "module": "AsiStackProofs.VirtualContextRefinement",
      "formal_target": "The original finite admission routes are consumed alongside four-event materialization and two-event mandatory-fault refinements, arbitrary-run trace and batch-composition theorems, and an independent exact-build 11-scenario/73-mutation consumer.",
      "status": "implemented",
      "outline_line": 3390,
      "module_path": "lean/AsiStackProofs/VirtualContextRefinement.lean"
    },
    {
      "chapter_id": "virtual-context-abi",
      "chapter_title": "The Virtual Context ABI: Typed Pages, Cells, and Certificates",
      "tag": "lean:vcm.certificates.operational_invariant",
      "module": "AsiStackProofs.ContextCertificateRefinement",
      "formal_target": "Every accepted consumer admission in the finite reachable certificate model preserves the exact represented source, derived representation, loss contract, omission ledger, permitted use, lifecycle epoch, authority, and receipt custody.",
      "status": "implemented",
      "outline_line": 3391,
      "module_path": "lean/AsiStackProofs/ContextCertificateRefinement.lean"
    },
    {
      "chapter_id": "virtual-context-abi",
      "chapter_title": "The Virtual Context ABI: Typed Pages, Cells, and Certificates",
      "tag": "lean:vcm.certificates.failure_blocks_promotion",
      "module": "AsiStackProofs.ContextCertificateRefinement",
      "formal_target": "Derived authority cannot exceed represented source authority, and a support-promotion request cannot be admitted without a distinct evidence-transition receipt.",
      "status": "implemented",
      "outline_line": 3392,
      "module_path": "lean/AsiStackProofs/ContextCertificateRefinement.lean"
    },
    {
      "chapter_id": "virtual-context-abi",
      "chapter_title": "The Virtual Context ABI: Typed Pages, Cells, and Certificates",
      "tag": "lean:vcm.certificates.lifecycle_admission_route",
      "module": "AsiStackProofs.ContextCertificateRefinement",
      "formal_target": "The original fifteen lifecycle routes are consumed alongside a five-event reachable refinement and independent 12-certificate/8-scenario/64-mutation consumer.",
      "status": "implemented",
      "outline_line": 3393,
      "module_path": "lean/AsiStackProofs/ContextCertificateRefinement.lean"
    },
    {
      "chapter_id": "durable-semantic-memory-and-knowledge-lattices",
      "chapter_title": "Durable Semantic Memory and Knowledge Lattices",
      "tag": "lean:durable-semantic-memory-and-knowledge-lattices.admission_boundary",
      "module": "AsiStackProofs.DurableSemanticMemoryReview",
      "formal_target": "A reachable seven-transition semantic-memory review admits only dossiers with exact identity, provenance and revision, loss-aware ontology migration, consumer-scoped retrieval and use receipts, compaction, deletion, replay custody, and explicit non-authority; 38 mutations reject with exact repairs, while induction preserves parent provenance and authority and replay composition, and open deletion duties block Context Transactions materialization. No theorem establishes truth, useful retrieval, complete memory, behavioral forgetting, support, or release.",
      "status": "implemented",
      "outline_line": 3464,
      "module_path": "lean/AsiStackProofs/DurableSemanticMemoryReview.lean"
    },
    {
      "chapter_id": "context-transactions-snapshots-mounts-and-taint",
      "chapter_title": "Context Transactions, Snapshots, Mounts, and Taint",
      "tag": "lean:vcm.transactions.operational_invariant",
      "module": "AsiStackProofs.ContextTransactionRefinement",
      "formal_target": "Accepted reads preserve exact snapshot, branch, mount, cell, committed version, and replay custody; every successful bound run preserves transaction identity and yields a valid compositional trace.",
      "status": "implemented",
      "outline_line": 3533,
      "module_path": "lean/AsiStackProofs/ContextTransactionRefinement.lean"
    },
    {
      "chapter_id": "context-transactions-snapshots-mounts-and-taint",
      "chapter_title": "Context Transactions, Snapshots, Mounts, and Taint",
      "tag": "lean:vcm.transactions.failure_blocks_promotion",
      "module": "AsiStackProofs.ContextTransactionRefinement",
      "formal_target": "Accepted materialization of tainted context requires propagated taint or represented declassification, open deletion requires a closure receipt, and support requests require an evidence-transition receipt; custody, closure, and materialization remain monotone across successful runs.",
      "status": "implemented",
      "outline_line": 3534,
      "module_path": "lean/AsiStackProofs/ContextTransactionRefinement.lean"
    },
    {
      "chapter_id": "context-transactions-snapshots-mounts-and-taint",
      "chapter_title": "Context Transactions, Snapshots, Mounts, and Taint",
      "tag": "lean:vcm.transactions.memory_store_fixture_bridge",
      "module": "AsiStackProofs.ContextTransactionRefinement",
      "formal_target": "The reachable model is consumed alongside the exact 3-valid/6-invalid memory-store suite and an independent exact-module checker that verifies 35 Lean declarations, 12 lifecycle controls, and 81 rejecting mutations.",
      "status": "implemented",
      "outline_line": 3535,
      "module_path": "lean/AsiStackProofs/ContextTransactionRefinement.lean"
    },
    {
      "chapter_id": "context-transactions-snapshots-mounts-and-taint",
      "chapter_title": "Context Transactions, Snapshots, Mounts, and Taint",
      "tag": "lean:vcm.transactions.sequence_fixture_bridge",
      "module": "AsiStackProofs.ContextTransactionRefinement",
      "formal_target": "The six-event ordered witness is consumed alongside the exact 2-valid/4-invalid sequence suite and rejects read-before-write and missing-replay faults.",
      "status": "implemented",
      "outline_line": 3536,
      "module_path": "lean/AsiStackProofs/ContextTransactionRefinement.lean"
    },
    {
      "chapter_id": "verification-bandwidth-and-context-adequacy",
      "chapter_title": "Verification Bandwidth and Context Adequacy",
      "tag": "lean:verification_bandwidth.adequacy.operational_invariant",
      "module": "AsiStackProofs.VerificationBandwidthRefinement",
      "formal_target": "Context admission is separated from a frozen claim-specific obligation plan; only an exactly bound execution can advance, while arbitrary successful runs preserve identity, valid traces, composition, and receipt custody.",
      "status": "implemented",
      "outline_line": 3638,
      "module_path": "lean/AsiStackProofs/VerificationBandwidthRefinement.lean"
    },
    {
      "chapter_id": "verification-bandwidth-and-context-adequacy",
      "chapter_title": "Verification Bandwidth and Context Adequacy",
      "tag": "lean:verification_bandwidth.adequacy.failure_blocks_promotion",
      "module": "AsiStackProofs.VerificationBandwidthRefinement",
      "formal_target": "Direct chapter-core promotion requests and represented contradictions block evidence-gate handoff; high-risk correlated evaluation requires escalation.",
      "status": "implemented",
      "outline_line": 3639,
      "module_path": "lean/AsiStackProofs/VerificationBandwidthRefinement.lean"
    },
    {
      "chapter_id": "verification-bandwidth-and-context-adequacy",
      "chapter_title": "Verification Bandwidth and Context Adequacy",
      "tag": "lean:verification_bandwidth.adequacy.route_envelope",
      "module": "AsiStackProofs.VerificationBandwidthRefinement",
      "formal_target": "A five-stage lifecycle and four-event transaction cover twelve routes; arbitrary successful runs preserve zero support and external-effect authority, so the strongest positive effect is evidence-gate handoff.",
      "status": "implemented",
      "outline_line": 3640,
      "module_path": "lean/AsiStackProofs/VerificationBandwidthRefinement.lean"
    },
    {
      "chapter_id": "verification-bandwidth-and-context-adequacy",
      "chapter_title": "Verification Bandwidth and Context Adequacy",
      "tag": "lean:verification_bandwidth.contradiction_probe_fixture_bridge",
      "module": "AsiStackProofs.VerificationBandwidthRefinement",
      "formal_target": "An independent consumer recompiles the exact 35-theorem surface, recomputes all routes, consumes the 3/5, 2/7, and 3/5 suites, reconstructs the transaction, and rejects 87 route/lifecycle mutations.",
      "status": "implemented",
      "outline_line": 3641,
      "module_path": "lean/AsiStackProofs/VerificationBandwidthRefinement.lean"
    },
    {
      "chapter_id": "claim-ledgers-and-belief-revision",
      "chapter_title": "Claim Ledgers and Belief Revision",
      "tag": "lean:claims.ledger.operational_invariant",
      "module": "AsiStackProofs.ClaimLedgerRefinement",
      "formal_target": "Every accepted step and arbitrary successful run preserve durable claim identity, zero external effects, and exact ledger-version/append-count balance; an authorized append advances both counters exactly once.",
      "status": "implemented",
      "outline_line": 3741,
      "module_path": "lean/AsiStackProofs/ClaimLedgerRefinement.lean"
    },
    {
      "chapter_id": "claim-ledgers-and-belief-revision",
      "chapter_title": "Claim Ledgers and Belief Revision",
      "tag": "lean:claims.ledger.failure_blocks_promotion",
      "module": "AsiStackProofs.ClaimLedgerRefinement",
      "formal_target": "Stale bases, ledger self-approval, digest or same-digest payload substitution, open contradictions, missing evidence-owner receipts, and incomplete custody block append or exact acknowledgment.",
      "status": "implemented",
      "outline_line": 3742,
      "module_path": "lean/AsiStackProofs/ClaimLedgerRefinement.lean"
    },
    {
      "chapter_id": "claim-ledgers-and-belief-revision",
      "chapter_title": "Claim Ledgers and Belief Revision",
      "tag": "lean:claims.ledger.revision_lifecycle_route",
      "module": "AsiStackProofs.ClaimLedgerRefinement",
      "formal_target": "A reachable propose-append-materialize-acknowledge lifecycle binds the full pending proposal, exact versions, history, dependencies, ontology migration, residuals, and surface receipts; successful event batches compose and acknowledged states are terminal.",
      "status": "implemented",
      "outline_line": 3743,
      "module_path": "lean/AsiStackProofs/ClaimLedgerRefinement.lean"
    },
    {
      "chapter_id": "claim-ledgers-and-belief-revision",
      "chapter_title": "Claim Ledgers and Belief Revision",
      "tag": "lean:claims.ledger.semantic_assumption_fixture_bridge",
      "module": "AsiStackProofs.ClaimLedgerRefinement",
      "formal_target": "An independent consumer compiles the exact 27-declaration surface, covers 22 route cases, consumes the exact 5/7 revision suite and 1/11 five-project lifecycle, and rejects 34 mutations without support movement.",
      "status": "implemented",
      "outline_line": 3744,
      "module_path": "lean/AsiStackProofs/ClaimLedgerRefinement.lean"
    },
    {
      "chapter_id": "spinoza-verification-and-proof-carrying-claims",
      "chapter_title": "Proof-Carrying Claims and Adversarial Review",
      "tag": "lean:spinoza.proof_carrying.operational_invariant",
      "module": "AsiStackProofs.ProofCarryingClaimsRefinement",
      "formal_target": "Every finite target-specific verification run preserves exact claim, interpretation, scope, assumption, artifact, verifier, and trusted-base custody; rejected events preserve exact state, batches compose, owner writeback is absorbing, and support or external effects remain unassigned.",
      "status": "implemented",
      "outline_line": 3811,
      "module_path": "lean/AsiStackProofs/ProofCarryingClaimsRefinement.lean"
    },
    {
      "chapter_id": "spinoza-verification-and-proof-carrying-claims",
      "chapter_title": "Proof-Carrying Claims and Adversarial Review",
      "tag": "lean:spinoza.proof_carrying.failure_blocks_promotion",
      "module": "AsiStackProofs.ProofCarryingClaimsRefinement",
      "formal_target": "Passed results require artifacts and semantic review; negative results cannot request scoped promotion; mismatch requires tribunal; high-risk adjudication requires an independent dossier.",
      "status": "implemented",
      "outline_line": 3812,
      "module_path": "lean/AsiStackProofs/ProofCarryingClaimsRefinement.lean"
    },
    {
      "chapter_id": "spinoza-verification-and-proof-carrying-claims",
      "chapter_title": "Proof-Carrying Claims and Adversarial Review",
      "tag": "lean:tribunal.review.operational_invariant",
      "module": "AsiStackProofs.TribunalRefinement",
      "formal_target": "Every finite versioned Tribunal run preserves exact case, target, evidence, dossier, panel, policy, consumer, and verdict-version custody; rejected events preserve exact state, batches compose, appeal resolution is absorbing, and support or external effects remain unassigned.",
      "status": "implemented",
      "outline_line": 3813,
      "module_path": "lean/AsiStackProofs/TribunalRefinement.lean"
    },
    {
      "chapter_id": "spinoza-verification-and-proof-carrying-claims",
      "chapter_title": "Proof-Carrying Claims and Adversarial Review",
      "tag": "lean:tribunal.review.failure_blocks_promotion",
      "module": "AsiStackProofs.TribunalRefinement",
      "formal_target": "Missing high-risk probes, panel or independence records, falsification, preserved dissent, actions, constraints, residuals, appeal, owner handoff, or consumer acknowledgment; changed-evidence reuse; default approval; replay; substitution; and authority leakage all block lifecycle progress without mutating exact state.",
      "status": "implemented",
      "outline_line": 3814,
      "module_path": "lean/AsiStackProofs/TribunalRefinement.lean"
    },
    {
      "chapter_id": "spinoza-verification-and-proof-carrying-claims",
      "chapter_title": "Proof-Carrying Claims and Adversarial Review",
      "tag": "lean:spinoza.adversarial_review.dossier_probe_bridge",
      "module": "AsiStackProofs.ProofCarryingClaimsRefinement",
      "formal_target": "An independent consumer recompiles the exact eighteen-theorem surface, covers twenty-three lifecycle routes, consumes the exact 3/5 proof-carrying and 2/7 adversarial-dossier suites, and rejects 36 mutations without assigning support.",
      "status": "implemented",
      "outline_line": 3815,
      "module_path": "lean/AsiStackProofs/ProofCarryingClaimsRefinement.lean"
    },
    {
      "chapter_id": "labor-os-and-typed-jobs",
      "chapter_title": "Labor OS and Typed Jobs",
      "tag": "lean:jobs.lifecycle.operational_invariant",
      "module": "AsiStackProofs.TypedJobRefinement",
      "formal_target": "A reachable versioned typed-job lifecycle preserves exact job, contract, plan, authority, permission, lease, scheduler, and consumer custody from lock through acknowledged closure without assigning support or external effects.",
      "status": "implemented",
      "outline_line": 3884,
      "module_path": "lean/AsiStackProofs/TypedJobRefinement.lean"
    },
    {
      "chapter_id": "labor-os-and-typed-jobs",
      "chapter_title": "Labor OS and Typed Jobs",
      "tag": "lean:jobs.lifecycle.failure_blocks_promotion",
      "module": "AsiStackProofs.TypedJobRefinement",
      "formal_target": "Approval, permission, lease, scheduler, retry/idempotency, cancellation, artifact/audit, verification, completion/replay, residual-owner, and consumer-acknowledgment failures block lifecycle progress.",
      "status": "implemented",
      "outline_line": 3885,
      "module_path": "lean/AsiStackProofs/TypedJobRefinement.lean"
    },
    {
      "chapter_id": "labor-os-and-typed-jobs",
      "chapter_title": "Labor OS and Typed Jobs",
      "tag": "lean:jobs.lifecycle.execution_route_envelope",
      "module": "AsiStackProofs.TypedJobRefinement",
      "formal_target": "An independent consumer covers twenty-nine typed-job lifecycle routes and rejects 42 identity, ordering, authority, approval, permission, lease, retry, cancellation, artifact, audit, adjudication, receipt, replay, residual, and acknowledgment mutations.",
      "status": "implemented",
      "outline_line": 3886,
      "module_path": "lean/AsiStackProofs/TypedJobRefinement.lean"
    },
    {
      "chapter_id": "labor-os-and-typed-jobs",
      "chapter_title": "Labor OS and Typed Jobs",
      "tag": "lean:jobs.lifecycle.delivery_probe_fixture_bridge",
      "module": "AsiStackProofs.TypedJobRefinement",
      "formal_target": "The versioned lifecycle consumer preserves the exact two-valid/seven-invalid typed-job delivery suite without treating delivery or verification fields as task success, output truth, support, or external effects.",
      "status": "implemented",
      "outline_line": 3887,
      "module_path": "lean/AsiStackProofs/TypedJobRefinement.lean"
    },
    {
      "chapter_id": "labor-os-and-typed-jobs",
      "chapter_title": "Labor OS and Typed Jobs",
      "tag": "lean:jobs.lifecycle.durable_lifecycle_probe_bridge",
      "module": "AsiStackProofs.TypedJobRefinement",
      "formal_target": "The versioned lifecycle consumer preserves the exact two-valid/nine-invalid durable retry and lease suite without treating declared idempotence, recovery, enforcement, receipt, or replay fields as real service behavior.",
      "status": "implemented",
      "outline_line": 3888,
      "module_path": "lean/AsiStackProofs/TypedJobRefinement.lean"
    },
    {
      "chapter_id": "ai-work-surfaces-agent-harnesses-and-organizational-absorption",
      "chapter_title": "From Chat to Organizations: AI Work Surfaces and Agent Harnesses",
      "tag": "lean:work_surface.transition.authority_nonexpansion",
      "module": "AsiStackProofs.WorkSurfaceTransitions",
      "formal_target": "Accepted abstraction-absorption transitions preserve exact principal, work, context, environment, authority, review, effect, receipt, and residual identities and cannot widen authority beyond the parent surface.",
      "status": "planned",
      "outline_line": 3954,
      "module_path": "lean/AsiStackProofs/WorkSurfaceTransitions.lean"
    },
    {
      "chapter_id": "ai-work-surfaces-agent-harnesses-and-organizational-absorption",
      "chapter_title": "From Chat to Organizations: AI Work Surfaces and Agent Harnesses",
      "tag": "lean:work_surface.transition.rejection_noninterference",
      "module": "AsiStackProofs.WorkSurfaceTransitions",
      "formal_target": "Missing custody, approval, effect observation, rollback, or accountable ownership rejects a transition without mutating the accepted surface state or assigning support.",
      "status": "planned",
      "outline_line": 3955,
      "module_path": "lean/AsiStackProofs/WorkSurfaceTransitions.lean"
    },
    {
      "chapter_id": "ai-work-surfaces-agent-harnesses-and-organizational-absorption",
      "chapter_title": "From Chat to Organizations: AI Work Surfaces and Agent Harnesses",
      "tag": "lean:work_surface.summary.non_equivalence",
      "module": "AsiStackProofs.WorkSurfaceTransitions",
      "formal_target": "An aggregate autonomy or completion score cannot recover the transition record's authority, identity, effect, review, and residual fields.",
      "status": "planned",
      "outline_line": 3956,
      "module_path": "lean/AsiStackProofs/WorkSurfaceTransitions.lean"
    },
    {
      "chapter_id": "human-ai-organizations-delegation-and-accountability",
      "chapter_title": "Human-AI Organizations, Delegation, and Accountability",
      "tag": "lean:human_ai_org.accountability_requires_authority",
      "module": "AsiStackProofs.HumanAIOrganizations",
      "formal_target": "A five-stage finite review preserves staged capacity, authority, independence, and remedy invariants over arbitrary run length; assignable accountability requires all 20 authored fields, while 20 closed mutations reach exact repair states. A separate ten-stage delegation-to-remedy lifecycle proves arbitrary-run nine-field identity custody, support/effect non-authority, exact receipts, contest/remedy monotonicity, accepted traces, batch composition, absorbing closure, and one bounded adverse-path witness. A compositional responsibility bridge then refines the authority-delegation chain, preserves accountable-owner, independent-review, evidence, residual-owner, receipt, and non-authority invariants through a two-hop witness, and shows that aggregate delegation summaries cannot recover accountability. An independent consumer reaches all 39 lifecycle routes, rejects 156/156 lifecycle mutations and 50/50 bridge mutations, and checks all three bridge compositions. It establishes no field truth, lawful accountability, human control, organizational outcome, support, or external effect.",
      "status": "implemented",
      "outline_line": 4035,
      "module_path": "lean/AsiStackProofs/HumanAIOrganizations.lean"
    },
    {
      "chapter_id": "human-ai-symbiosis-neurotechnology-and-cognitive-sovereignty",
      "chapter_title": "Human-AI Symbiosis, Neurotechnology, and Cognitive Sovereignty",
      "tag": "lean:human-ai-symbiosis-neurotechnology-and-cognitive-sovereignty.admission_boundary",
      "module": "AsiStackProofs.HumanAICognitiveSovereignty",
      "formal_target": "An eight-step finite human-AI coupling review preserves exact participant, protocol, coupling, model, purpose, comparator, observation, exit, and authority boundaries; a complete authored dossier reaches only Project Theseus low-risk coupling-study eligibility, while 49 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Combined-system qualification requires both competent component baselines, purpose grants do not authorize unrelated uses, revoked or expired grants fail authorization, every expected participant requires post-exit follow-up, and participant, protocol, device/model, purpose, observation, exit, or authority changes invalidate receipts. Nominal revocation signals cannot recover practical exit, and session metrics cannot recover post-exit skill retention. No theorem establishes beneficial symbiosis, genuine consent, mental integrity, cognitive enhancement, clinical efficacy, equity, neural safety, lawful authorization, support, release, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 4091,
      "module_path": "lean/AsiStackProofs/HumanAICognitiveSovereignty.lean"
    },
    {
      "chapter_id": "ai-deployment-transition-distribution-and-human-agency",
      "chapter_title": "AI Deployment, Transition, Distribution, and Human Agency",
      "tag": "lean:ai-deployment-transition-distribution-and-human-agency.admission_boundary",
      "module": "AsiStackProofs.DeploymentTransitionGovernance",
      "formal_target": "A reachable eight-transition review preserves deployment and baseline identity, complete affected-person denominators, disaggregated accounting, practical agency, transition capacity, remedy, and non-authority over arbitrary run length; all 54 authored-axis mutations reject readiness with exact repair. Finite cohort laws show positive aggregate gain can coexist with unremedied harm, and two countermodels show aggregate or approval signals cannot recover subgroup harm or practical refusal. Existing accountability, readiness, and Evidence States consumers reject missing remedy, failed checks, and absent empirical study. No theorem establishes causal effect, welfare, fairness, meaningful agency, lawful remedy, continuity, support, release, or external effect.",
      "status": "implemented",
      "outline_line": 4157,
      "module_path": "lean/AsiStackProofs/DeploymentTransitionGovernance.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.operational_invariant",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "Every finite artifact lifecycle run preserves exact artifact, content, parent-job, source, context, transaction, certificate, tool, claim, test, policy, and consumer custody; rejected events preserve exact state, batches compose, admission is absorbing, and support or external effects remain unassigned.",
      "status": "implemented",
      "outline_line": 4312,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.failure_blocks_promotion",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "Missing provenance, replay, observation, cross-check, trap, attestation-limit, trust-root, verifier-separation, recursion-stop, residual, revocation, or consumer obligations block lifecycle progress without mutating exact state.",
      "status": "implemented",
      "outline_line": 4313,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.replay_packet_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The refinement preserves exact replay-packet custody and requires replay metadata, sufficient grade, limits, active certificates, and replay validation before reality review.",
      "status": "implemented",
      "outline_line": 4314,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.record_reality_sequence_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves the exact one-valid/four-invalid stale/partial/fresh record-reality sequence without assigning support.",
      "status": "implemented",
      "outline_line": 4315,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.receipt_faithfulness_fixture_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves the exact three-valid/six-invalid receipt-faithfulness suite while requiring observation, independent cross-checks, trap challenges, and bounded attestation.",
      "status": "implemented",
      "outline_line": 4316,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.receipt_repository_audit_fixture_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves the exact four-record/five-mutation repository audit while treating current digest and command checks as bounded observations rather than open-world truth.",
      "status": "implemented",
      "outline_line": 4317,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.receipt_repository_challenge_fixture_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves the exact four-response/five-mutation deterministic repository challenge while bounding fingerprint and digest observations to the sampled artifacts.",
      "status": "implemented",
      "outline_line": 4318,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.live_attestation_probe_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves one-artifact live attestation with three observation routes and seven mutations without treating a dirty or uncommitted target as attested.",
      "status": "implemented",
      "outline_line": 4319,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.randomized_attestation_audit_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves the four-artifact randomized attestation with twelve accepted observation routes and eight mutations without generalizing beyond the sample.",
      "status": "implemented",
      "outline_line": 4320,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "artifact-graphs-audit-logs-and-replay",
      "chapter_title": "Artifact Graphs, Audit Logs, and Replay",
      "tag": "lean:artifacts.graph.epistemic_tcb_fixture_bridge",
      "module": "AsiStackProofs.ArtifactRealityRefinement",
      "formal_target": "The independent consumer preserves the exact three-valid/six-invalid epistemic-TCB suite while requiring a bounded trusted core, roots, verifier separation, recursion stop, and outside-TCB residuals.",
      "status": "implemented",
      "outline_line": 4321,
      "module_path": "lean/AsiStackProofs/ArtifactRealityRefinement.lean"
    },
    {
      "chapter_id": "runtime-adapters-tool-permissions-and-human-approval",
      "chapter_title": "Runtime Adapters, Tool Permissions, and Human Approval",
      "tag": "lean:runtime.adapters.operational_invariant",
      "module": "AsiStackProofs.RuntimeAdapters",
      "formal_target": "Every accepted event and arbitrary finite run in the reachable runtime-effect model preserves exact job, caller, capability, target, active-lease, approval, dispatch, caller-ceiling, epoch, revocation, and observed-effect accounting invariants, and refines the corresponding authority-effect run.",
      "status": "implemented",
      "outline_line": 4450,
      "module_path": "lean/AsiStackProofs/RuntimeAdapters.lean"
    },
    {
      "chapter_id": "runtime-adapters-tool-permissions-and-human-approval",
      "chapter_title": "Runtime Adapters, Tool Permissions, and Human Approval",
      "tag": "lean:runtime.adapters.failure_blocks_promotion",
      "module": "AsiStackProofs.RuntimeAdapters",
      "formal_target": "The reachable model rejects missing permission, caller or scoped-target substitution, authority widening, expiry, secret materialization, effect without dispatch, missing rollback handles, pre-state mismatch, revoked-lease reuse, and post-revocation dispatch before any accepted state transition; denial is state-noninterfering in the modeled step semantics.",
      "status": "implemented",
      "outline_line": 4451,
      "module_path": "lean/AsiStackProofs/RuntimeAdapters.lean"
    },
    {
      "chapter_id": "runtime-adapters-tool-permissions-and-human-approval",
      "chapter_title": "Runtime Adapters, Tool Permissions, and Human Approval",
      "tag": "lean:runtime.adapters.effect_replay_fixture_bridge",
      "module": "AsiStackProofs.RuntimeAdapters",
      "formal_target": "A six-event prepare-to-rollback witness reaches exact baseline restoration, and the entire trace simulates an accepted authority-effect trace while the independent temp-file probe supplies only bounded local effect and rollback observations.",
      "status": "implemented",
      "outline_line": 4452,
      "module_path": "lean/AsiStackProofs/RuntimeAdapters.lean"
    },
    {
      "chapter_id": "runtime-adapters-tool-permissions-and-human-approval",
      "chapter_title": "Runtime Adapters, Tool Permissions, and Human Approval",
      "tag": "lean:runtime.adapters.adversarial_boundary_probe_bridge",
      "module": "AsiStackProofs.RuntimeAdapters",
      "formal_target": "The independently encoded permission and adversarial consumers reject identity, authority, approval, lease, sandbox, secret, rollback, receipt, audit, support, and non-claim mutations, while the reachable Lean countermodels prove the corresponding pre-effect rejections at exact modeled boundaries.",
      "status": "implemented",
      "outline_line": 4453,
      "module_path": "lean/AsiStackProofs/RuntimeAdapters.lean"
    },
    {
      "chapter_id": "runtime-adapters-tool-permissions-and-human-approval",
      "chapter_title": "Runtime Adapters, Tool Permissions, and Human Approval",
      "tag": "lean:runtime.adapters.revocation_route_bridge",
      "module": "AsiStackProofs.RuntimeAdapters",
      "formal_target": "An accepted revocation clears active lease, approval, and dispatch state, advances the authority epoch, records the revoked lease, and prevents both same-lease preparation and dispatch until a distinct fresh lease is admitted; repository fixtures retain no-mutation and non-promotion boundaries.",
      "status": "implemented",
      "outline_line": 4454,
      "module_path": "lean/AsiStackProofs/RuntimeAdapters.lean"
    },
    {
      "chapter_id": "runtime-adapters-tool-permissions-and-human-approval",
      "chapter_title": "Runtime Adapters, Tool Permissions, and Human Approval",
      "tag": "lean:runtime.adapters.human_oversight_degradation_fixture_bridge",
      "module": "AsiStackProofs.RuntimeAdapters",
      "formal_target": "An independent human-oversight consumer computes low-fatigue, overload, automation-bias, and invalid-control outcomes; separately, retained runtime-adapter route theorems govern permission, approval, lease, sandbox, rollback, receipt, and revocation boundaries. Lean does not formalize reviewer cognition or copy the consumer summary.",
      "status": "implemented",
      "outline_line": 4455,
      "module_path": "lean/AsiStackProofs/RuntimeAdapters.lean"
    },
    {
      "chapter_id": "embodied-agency-real-time-control-and-physical-safety",
      "chapter_title": "Embodied Agency, Real-Time Control, and Physical Safety",
      "tag": "lean:embodiment.missing_safety_state_blocks_control",
      "module": "AsiStackProofs.EmbodiedPhysicalSafety",
      "formal_target": "A finite control-lease model derives freshness, timing, state-envelope, actuator, fallback-distance, stop, effect, custody, and boundary conditions from authored fields; one complete lease reaches only a Project Theseus closed-loop trial, while 13 axis mutations fail readiness and reach exact repair routes. A separate eight-stage simulation-trial review lifecycle proves arbitrary-run nine-field identity custody, support/effect non-authority, exact receipts, stop-count monotonicity, accepted traces, batch composition, absorbing closure, and safety-axis start blocking; an independent consumer rejects 105/105 mutations. It establishes no plant truth, physical or human safety, deadline satisfaction, safe-set validity, fallback effectiveness, recovery, support, release, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 4516,
      "module_path": "lean/AsiStackProofs/EmbodiedPhysicalSafety.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.invalid_credential.blocks_dispatch",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "A finite requested cross-stack exchange with required invalid credential verification routes to denial rather than ordinary local dispatch, without inferring identity trust, task truth, authorization correctness, payment settlement, or ASI.",
      "status": "implemented",
      "outline_line": 4621,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.missing_reserved_budget.blocks_economic_dispatch",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "A finite value-bearing requested cross-stack exchange with all required identity and authority records but no reserved budget routes to budget repair rather than ordinary local dispatch, without inferring payment, settlement, economic fairness, authority correctness, or ASI.",
      "status": "implemented",
      "outline_line": 4622,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.complete_exchange.reaches_local_dispatch",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "A complete six-event local exchange lifecycle reaches residual closure, while rejected events preserve exact state and arbitrary runs preserve exchange, protocol, sender, receiver, principal, request, budget, receipt, and authority-ceiling identity with zero support, external-effect, or settlement assignment; this proves no runtime authorization, peer trust, execution, payment, or settlement.",
      "status": "implemented",
      "outline_line": 4623,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.missing_sender.requires_identity_repair",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "Missing sender identity routes to identity repair.",
      "status": "implemented",
      "outline_line": 4624,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.audience_mismatch.denies_dispatch",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "Audience or scope mismatch denies ordinary dispatch.",
      "status": "implemented",
      "outline_line": 4625,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.expired_request.denies_dispatch",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "An expired request denies ordinary dispatch.",
      "status": "implemented",
      "outline_line": 4626,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.revoked_credential.denies_dispatch",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "A verified but no-longer-current required credential denies dispatch.",
      "status": "implemented",
      "outline_line": 4627,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.disputed_receipt.requires_review",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "A disputed receipt without an explicit disposition cannot close the finite exchange lifecycle and routes to accountable review, without establishing receipt truth, dispute resolution, payment, or settlement.",
      "status": "implemented",
      "outline_line": 4628,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "inter-stack-protocols-identity-and-economic-exchange",
      "chapter_title": "Inter-Stack Protocols, Identity, and Economic Exchange",
      "tag": "lean:inter_stack.missing_residual_owner.requires_review",
      "module": "AsiStackProofs.InterStackProtocols",
      "formal_target": "Missing residual ownership prevents finite exchange closure and routes to accountable review, without establishing residual completeness, recovery quality, payment, or settlement.",
      "status": "implemented",
      "outline_line": 4629,
      "module_path": "lean/AsiStackProofs/InterStackProtocols.lean"
    },
    {
      "chapter_id": "multi-agent-dynamics-collective-intelligence-and-systemic-risk",
      "chapter_title": "Multi-Agent Dynamics, Collective Intelligence, and Systemic Risk",
      "tag": "lean:multi_agent.pairwise_validity_no_systemic_promotion",
      "module": "AsiStackProofs.MultiAgentDynamics",
      "formal_target": "A finite three-party population model proves that identical six-edge pairwise-authorization evidence can coexist with opposite campaign-readiness decisions; no classifier over that matrix alone can exactly recover the ten-dimension review. Nine systemic-axis mutations preserve pairwise validity, fail readiness, and reach exact repair routes. A conserved three-unit allocation lifecycle proves composition, receipt accounting, non-authority, terminal exhaustion, and a local-authorization collision across opposite concentration outcomes. It establishes no cooperation, non-collusion, systemic safety, human agency, institutional outcome, support, or external effect.",
      "status": "implemented",
      "outline_line": 4690,
      "module_path": "lean/AsiStackProofs/MultiAgentDynamics.lean"
    },
    {
      "chapter_id": "procedural-memory-and-cognitive-loop-closure",
      "chapter_title": "Procedural Memory and Cognitive Loop Closure",
      "tag": "lean:procedural.loop_closure.operational_invariant",
      "module": "AsiStackProofs.ProceduralMemoryRefinement",
      "formal_target": "Every finite procedure lifecycle run preserves exact procedure, source-set, trace-cluster, abstraction, regression-suite, SCF, policy, and consumer custody; rejected events preserve exact state, batches compose, retirement is absorbing, and support or external effects remain unassigned.",
      "status": "implemented",
      "outline_line": 4766,
      "module_path": "lean/AsiStackProofs/ProceduralMemoryRefinement.lean"
    },
    {
      "chapter_id": "procedural-memory-and-cognitive-loop-closure",
      "chapter_title": "Procedural Memory and Cognitive Loop Closure",
      "tag": "lean:procedural.loop_closure.failure_blocks_promotion",
      "module": "AsiStackProofs.ProceduralMemoryRefinement",
      "formal_target": "Missing comparable traces, negative examples, source/effect receipts, abstraction contracts, verification, regression clearance, benchmark floor, active SCF, rehearsed rollback, monitoring, residuals, non-claims, acknowledgment, or retirement custody blocks lifecycle progress or routes to quarantine without mutating exact state.",
      "status": "implemented",
      "outline_line": 4767,
      "module_path": "lean/AsiStackProofs/ProceduralMemoryRefinement.lean"
    },
    {
      "chapter_id": "routing-heads-and-specialist-cores",
      "chapter_title": "Routing Heads and Specialist Cores",
      "tag": "lean:routing.specialists.operational_invariant",
      "module": "AsiStackProofs.RoutingRefinement",
      "formal_target": "Every finite routing lifecycle run preserves exact task, request, registry, candidate-set, selected-specialist, capability, authority, readiness, lease, evaluator, policy, and consumer custody; rejected events preserve exact state, route and answer accounting remains separate and balanced, batches compose, closure is absorbing, and support or external effects remain unassigned.",
      "status": "implemented",
      "outline_line": 4876,
      "module_path": "lean/AsiStackProofs/RoutingRefinement.lean"
    },
    {
      "chapter_id": "routing-heads-and-specialist-cores",
      "chapter_title": "Routing Heads and Specialist Cores",
      "tag": "lean:routing.specialists.failure_blocks_promotion",
      "module": "AsiStackProofs.RoutingRefinement",
      "formal_target": "Missing authority, readiness, fresh leases, selective handling, fallback or residual ownership, dispatch isolation, observed route/answer/unsafe/cost outcomes, lifecycle currentness, revocation closure, or consumer acknowledgment blocks lifecycle progress without mutating exact state.",
      "status": "implemented",
      "outline_line": 4877,
      "module_path": "lean/AsiStackProofs/RoutingRefinement.lean"
    },
    {
      "chapter_id": "routing-heads-and-specialist-cores",
      "chapter_title": "Routing Heads and Specialist Cores",
      "tag": "lean:routing.specialists.decision_lifecycle_route",
      "module": "AsiStackProofs.RoutingRefinement",
      "formal_target": "The independent consumer preserves all forty-two routing outcomes, including label-leak rejection, complete candidate denominators, least-capable-adequate selection, ambiguity-triggered selective action, fallback/residual routes, and separate dispatch, observation, and closure stages.",
      "status": "implemented",
      "outline_line": 4878,
      "module_path": "lean/AsiStackProofs/RoutingRefinement.lean"
    },
    {
      "chapter_id": "routing-heads-and-specialist-cores",
      "chapter_title": "Routing Heads and Specialist Cores",
      "tag": "lean:moecot.runtime.operational_invariant",
      "module": "AsiStackProofs.RoutingRefinement",
      "formal_target": "A runtime-backed route cannot qualify until inspected source state, concrete runtime evidence, replay evidence, task-local dispatch authority, and isolation are bound to the same routing lease.",
      "status": "implemented",
      "outline_line": 4879,
      "module_path": "lean/AsiStackProofs/RoutingRefinement.lean"
    },
    {
      "chapter_id": "routing-heads-and-specialist-cores",
      "chapter_title": "Routing Heads and Specialist Cores",
      "tag": "lean:moecot.runtime.failure_blocks_promotion",
      "module": "AsiStackProofs.RoutingRefinement",
      "formal_target": "Unavailable or source-only runtime material, missing replay evidence, or unobserved route and answer outcomes cannot be laundered into runtime, routing-quality, support, or deployment claims.",
      "status": "implemented",
      "outline_line": 4880,
      "module_path": "lean/AsiStackProofs/RoutingRefinement.lean"
    },
    {
      "chapter_id": "replaceable-cognitive-substrates-beyond-transformer-monoculture",
      "chapter_title": "Replaceable Cognitive Substrates: Beyond Transformer Monoculture",
      "tag": "lean:cognitive_kernel.abi_trace_invariants",
      "module": "AsiStackProofs.ReplaceableCognitiveSubstrates",
      "formal_target": "A finite Cognitive Kernel ABI trace keeps proposals separate from effects, preserves non-increasing authority and declared exact checkpoint state, rejects revoked kernels and incompatible migrations, and preserves fallback, evaluator, assistance, cost, evidence, and residual ownership across mixed-kernel routes; a common schema-and-digest checkpoint projection is non-injective over the modeled heterogeneous continuation state, while the declared full encoding round-trips and is injective.",
      "status": "implemented",
      "outline_line": 4984,
      "module_path": "lean/AsiStackProofs/ReplaceableCognitiveSubstrates.lean"
    },
    {
      "chapter_id": "relational-dimension-compilation-and-polyadic-cognition",
      "chapter_title": "Relational Dimension Compilation and Polyadic Cognition",
      "tag": "lean:relational-dimension-compilation-and-polyadic-cognition.admission_boundary",
      "module": "AsiStackProofs.RelationalDimensionCompiler",
      "formal_target": "An eight-step finite relational-compiler review preserves exact proposal, compiler, residual, role-schema, branch, authority, rescue, qualification, compilation, fallback, and contraction boundaries; a complete authored dossier reaches only Project Theseus relational-compiler-study eligibility, while 54 admission-axis mutations block readiness and receive exact repair or refusal dispositions. Role and candidate identity compose over finite append, entity remapping preserves role IDs, omitted required roles and hidden candidates reject completeness, and an active descendant blocks contraction closure. Expiry and candidate-budget overrun remain rejecting under adverse change, while proposal, compiler, role, rescue, qualification, fallback, or authority changes invalidate receipts. Qualification metrics cannot recover role fidelity, and named rescue records cannot recover lower-order rescue competence. No theorem establishes higher-order irreducibility, representational usefulness, efficiency, natural-task transfer, bounded primitive arity, safe online adaptation, support, release, transfer, or external effect.",
      "status": "implemented",
      "outline_line": 5052,
      "module_path": "lean/AsiStackProofs/RelationalDimensionCompiler.lean"
    },
    {
      "chapter_id": "governed-model-training-distributed-optimization-and-scaling",
      "chapter_title": "Governed Model Training, Distributed Optimization, and Scaling",
      "tag": "lean:governed_training.run_admission_invariants",
      "module": "AsiStackProofs.GovernedModelTraining",
      "formal_target": "An accepted finite handoff requires exact declared identity, topology/numerical identity, complete committed checkpoint state, complete failure denominator, and no support or release request.",
      "status": "implemented",
      "outline_line": 5166,
      "module_path": "lean/AsiStackProofs/GovernedModelTraining.lean"
    },
    {
      "chapter_id": "governed-model-training-distributed-optimization-and-scaling",
      "chapter_title": "Governed Model Training, Distributed Optimization, and Scaling",
      "tag": "lean:governed_training.resume_and_handoff_separation",
      "module": "AsiStackProofs.GovernedModelTraining",
      "formal_target": "An accepted finite handoff requires accounted resume state, retained checkpoint and failure families, validation-only selection, and unopened independent qualification.",
      "status": "implemented",
      "outline_line": 5167,
      "module_path": "lean/AsiStackProofs/GovernedModelTraining.lean"
    },
    {
      "chapter_id": "governed-model-training-distributed-optimization-and-scaling",
      "chapter_title": "Governed Model Training, Distributed Optimization, and Scaling",
      "tag": "lean:governed_training.checkpoint_information_boundary",
      "module": "AsiStackProofs.GovernedModelTraining",
      "formal_target": "A weights-and-step projection is non-injective over the modeled nine-field training state and no weight-only decoder recovers every state, while the complete encoding round-trips and is injective.",
      "status": "implemented",
      "outline_line": 5168,
      "module_path": "lean/AsiStackProofs/GovernedModelTraining.lean"
    },
    {
      "chapter_id": "learning-compute-topology-and-adaptive-process-architecture",
      "chapter_title": "Learning\u2013Compute Topology and Adaptive Process Architecture",
      "tag": "lean:learning_compute_topology.semantic_firewall_nonexpansion",
      "module": "AsiStackProofs.LearningComputeTopology",
      "formal_target": "Within a bounded finite LCT record model, an admitted semantics-preserving realization cannot create an adaptive identity, redirect protected evidence, judgement, credit, or authority, or replace the declared integration operator; any such mutation requires a new topology contract.",
      "status": "planned",
      "outline_line": 5229,
      "module_path": "lean/AsiStackProofs/LearningComputeTopology.lean"
    },
    {
      "chapter_id": "learning-compute-topology-and-adaptive-process-architecture",
      "chapter_title": "Learning\u2013Compute Topology and Adaptive Process Architecture",
      "tag": "lean:learning_compute_topology.semantic_cut_information_bound",
      "module": "AsiStackProofs.LearningComputeTopology",
      "formal_target": "For the stated finite staged Markov model without side channels, retained target information is bounded by each discovery, evaluation, and integration cut, preserving the paper proposition's exact assumptions and non-claims.",
      "status": "planned",
      "outline_line": 5230,
      "module_path": "lean/AsiStackProofs/LearningComputeTopology.lean"
    },
    {
      "chapter_id": "learning-theory-generalization-and-scaling-science",
      "chapter_title": "Learning Theory, Generalization, and Scaling Science",
      "tag": "lean:learning-theory-generalization-and-scaling-science.admission_boundary",
      "module": "AsiStackProofs.LearningTheoryForecastReview",
      "formal_target": "A reachable six-transition forecast review admits only dossiers that bind claim, population, sample process, support, hypothesis, algorithm, optimization, architecture, metric, compute, prospective design, transfer boundaries, correction, expiry, residuals, and explicit non-authority. All 45 admission-axis mutations reject with exact repairs. Finite attempt identity composes and preserves every member, omitted attempts and unscored preregistered alternatives reject completeness, expiry and unsupported extrapolation remain rejecting under adverse changes, seven regime changes invalidate receipts, retrospective fit cannot recover prospective coverage, threshold metrics cannot recover mechanism change, and a missing prospective holdout rejects Benchmark Ratchet readiness promotion. No theorem establishes generalization, transfer, emergence, scaling accuracy, calibration, safety, deployment, support, or release.",
      "status": "implemented",
      "outline_line": 5290,
      "module_path": "lean/AsiStackProofs/LearningTheoryForecastReview.lean"
    },
    {
      "chapter_id": "readiness-gates-residual-escrow-and-quarantine",
      "chapter_title": "Readiness Gates, Residual Escrow, and Quarantine",
      "tag": "lean:readiness.gates.operational_invariant",
      "module": "AsiStackProofs.ReadinessRefinement",
      "formal_target": "Every finite run through the reachable readiness lifecycle preserves exact capability, implementation, model-state, workload, baseline, evaluator, policy, authority, consumer, fallback, and residual custody; rejected events preserve exact state, event batches compose, terminal closure is absorbing, and support or external effects remain unassigned.",
      "status": "implemented",
      "outline_line": 5371,
      "module_path": "lean/AsiStackProofs/ReadinessRefinement.lean"
    },
    {
      "chapter_id": "readiness-gates-residual-escrow-and-quarantine",
      "chapter_title": "Readiness Gates, Residual Escrow, and Quarantine",
      "tag": "lean:readiness.gates.failure_blocks_promotion",
      "module": "AsiStackProofs.ReadinessRefinement",
      "formal_target": "Missing workload, baseline, evaluator, non-claims, fresh shadow evidence, regression floor, residual escrow, fallback, rollback, monitoring, canary outcome accounting, independent evaluation, transfer, delayed outcomes, transitive quarantine, route blocking, or terminal revocation custody blocks lifecycle progress.",
      "status": "implemented",
      "outline_line": 5372,
      "module_path": "lean/AsiStackProofs/ReadinessRefinement.lean"
    },
    {
      "chapter_id": "readiness-gates-residual-escrow-and-quarantine",
      "chapter_title": "Readiness Gates, Residual Escrow, and Quarantine",
      "tag": "lean:readiness.gates.lifecycle_probe_bridge",
      "module": "AsiStackProofs.ReadinessRefinement",
      "formal_target": "The independent consumer recompiles the exact twenty-four-theorem surface while preserving three exact readiness suites, all forty lifecycle routes, the six-receipt terminal witness, and forty-five rejecting identity, gate, replay, and authority-leak mutations without assigning support or external effects.",
      "status": "implemented",
      "outline_line": 5373,
      "module_path": "lean/AsiStackProofs/ReadinessRefinement.lean"
    },
    {
      "chapter_id": "personal-compute-hives-and-federated-edge-intelligence",
      "chapter_title": "Personal Compute Hives and Federated Edge Intelligence",
      "tag": "lean:personal_hives.scheduling.operational_invariant",
      "module": "AsiStackProofs.HiveLifecycleRefinement",
      "formal_target": "A reachable Hive lifecycle preserves exact job, principal, contract, registry, candidate-set, selected-node, policy, authority, lease, evaluator, consumer, and residual custody from policy binding through acknowledged closure while separating dispatch, useful-outcome, recovery, support, and external-effect accounting.",
      "status": "implemented",
      "outline_line": 5463,
      "module_path": "lean/AsiStackProofs/HiveLifecycleRefinement.lean"
    },
    {
      "chapter_id": "personal-compute-hives-and-federated-edge-intelligence",
      "chapter_title": "Personal Compute Hives and Federated Edge Intelligence",
      "tag": "lean:personal_hives.policy_first.failure_blocks_promotion",
      "module": "AsiStackProofs.HiveLifecycleRefinement",
      "formal_target": "Incomplete identity, data, tool, approval, registry, candidate-denominator, least-authority, locality, budget, energy, or dropout policy blocks selection before optimization.",
      "status": "implemented",
      "outline_line": 5464,
      "module_path": "lean/AsiStackProofs/HiveLifecycleRefinement.lean"
    },
    {
      "chapter_id": "personal-compute-hives-and-federated-edge-intelligence",
      "chapter_title": "Personal Compute Hives and Federated Edge Intelligence",
      "tag": "lean:personal_hives.approval_gate.failure_blocks_promotion",
      "module": "AsiStackProofs.HiveLifecycleRefinement",
      "formal_target": "A high-risk Hive job cannot execute without a bound approval receipt tied to the exact job and lease.",
      "status": "implemented",
      "outline_line": 5465,
      "module_path": "lean/AsiStackProofs/HiveLifecycleRefinement.lean"
    },
    {
      "chapter_id": "personal-compute-hives-and-federated-edge-intelligence",
      "chapter_title": "Personal Compute Hives and Federated Edge Intelligence",
      "tag": "lean:personal_hives.federation_lease.operational_invariant",
      "module": "AsiStackProofs.HiveLifecycleRefinement",
      "formal_target": "External Hive access cannot receive a lease without federation, sandbox, scope, evidence-obligation, expiration, and revocation custody bound to the selected node.",
      "status": "implemented",
      "outline_line": 5466,
      "module_path": "lean/AsiStackProofs/HiveLifecycleRefinement.lean"
    },
    {
      "chapter_id": "personal-compute-hives-and-federated-edge-intelligence",
      "chapter_title": "Personal Compute Hives and Federated Edge Intelligence",
      "tag": "lean:personal_hives.work_admission.lifecycle_route",
      "module": "AsiStackProofs.HiveLifecycleRefinement",
      "formal_target": "The independent consumer recompiles the exact thirty-one-theorem surface, executes the six-event lifecycle, preserves thirteen-field custody and zero support/effect authority at every reachable state, checks all seven trace splits, preserves all forty-seven policy, selection, lease, partition, execution, reconciliation, recovery, revocation, and closure outcomes, rejects all post-closure event kinds, and rejects 144/144 mutations.",
      "status": "implemented",
      "outline_line": 5467,
      "module_path": "lean/AsiStackProofs/HiveLifecycleRefinement.lean"
    },
    {
      "chapter_id": "personal-compute-hives-and-federated-edge-intelligence",
      "chapter_title": "Personal Compute Hives and Federated Edge Intelligence",
      "tag": "lean:personal_hives.partitioned_authority.fixture_bridge",
      "module": "AsiStackProofs.HiveLifecycleRefinement",
      "formal_target": "Partitioned stale authority quarantines before mutation only with denial and no-mutation evidence; otherwise the lifecycle requests evidence and never infers deployed partition tolerance or support.",
      "status": "implemented",
      "outline_line": 5470,
      "module_path": "lean/AsiStackProofs/HiveLifecycleRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.cgs.operational_invariant",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Reachable residualization blocks unresolved obligations lacking record, owner, burden, provenance, cost, or fallback receipt.",
      "status": "implemented",
      "outline_line": 5562,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.cgs.failure_blocks_promotion",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Lossy exactness is blocked and failed or mismatched verification requires executable preserved-source fallback.",
      "status": "implemented",
      "outline_line": 5563,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.cgs.admission_route",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Nine reachable stages and 60 routes bind representation identities from source through closure.",
      "status": "implemented",
      "outline_line": 5564,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.cgs.gvr_fixture_bridge",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Independent digest-bound GVR conformance plus reachable verification/fallback semantics replaces copied fixture facts.",
      "status": "implemented",
      "outline_line": 5565,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.cgs.residual_storage_replay_bridge",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Independent digest-bound residual result conformance plus result-substitution and broken-chain closure guards replaces copied summaries.",
      "status": "implemented",
      "outline_line": 5566,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.gvr.operational_invariant",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Observed reconstruction, target identity, verifier identity, and executable fallback are reachable lifecycle obligations.",
      "status": "implemented",
      "outline_line": 5567,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:compression.gvr.failure_blocks_promotion",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Failed verification activates preserved-source fallback or blocks progress without promotion authority.",
      "status": "implemented",
      "outline_line": 5568,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:representation.semantic_tree.operational_invariant",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Semantic use requires provenance identity, content, and a grounding evaluator before migration.",
      "status": "implemented",
      "outline_line": 5569,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "compact-generative-systems-and-residual-honesty",
      "chapter_title": "Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty",
      "tag": "lean:representation.semantic_tree.failure_blocks_promotion",
      "module": "AsiStackProofs.CompactGenerationRefinement",
      "formal_target": "Hierarchy changes require migration records, reference continuity, and consumer mapping.",
      "status": "implemented",
      "outline_line": 5570,
      "module_path": "lean/AsiStackProofs/CompactGenerationRefinement.lean"
    },
    {
      "chapter_id": "fast-generation-architectures",
      "chapter_title": "Fast Generation Architectures",
      "tag": "lean:fast_generation.mode_selection.operational_invariant",
      "module": "AsiStackProofs.FastGenerationRefinement",
      "formal_target": "Reachable admission binds task, context, consumer, mode, risk, verifier, baseline, quality, latency, resource, fallback, and rights records before fast selection.",
      "status": "implemented",
      "outline_line": 5652,
      "module_path": "lean/AsiStackProofs/FastGenerationRefinement.lean"
    },
    {
      "chapter_id": "fast-generation-architectures",
      "chapter_title": "Fast Generation Architectures",
      "tag": "lean:fast_generation.verified_speed.failure_blocks_promotion",
      "module": "AsiStackProofs.FastGenerationRefinement",
      "formal_target": "Reachable accounting and decision routes block raw-speed promotion without accepted output, task success, matched baseline, complete costs, and an evidence transition.",
      "status": "implemented",
      "outline_line": 5653,
      "module_path": "lean/AsiStackProofs/FastGenerationRefinement.lean"
    },
    {
      "chapter_id": "fast-generation-architectures",
      "chapter_title": "Fast Generation Architectures",
      "tag": "lean:fast_generation.mode_admission_lifecycle_route",
      "module": "AsiStackProofs.FastGenerationRefinement",
      "formal_target": "Eight stages and sixty independently consumed routes govern context binding, selection, drafting, verification or fallback, useful-outcome accounting, decision, and closure.",
      "status": "implemented",
      "outline_line": 5654,
      "module_path": "lean/AsiStackProofs/FastGenerationRefinement.lean"
    },
    {
      "chapter_id": "fast-generation-architectures",
      "chapter_title": "Fast Generation Architectures",
      "tag": "lean:fast_generation.theseus_import_fixture_bridge",
      "module": "AsiStackProofs.FastGenerationRefinement",
      "formal_target": "A digest-bound external validator owns Theseus report counts while Lean owns general reachable raw-speed, fallback, promotion, and closure policy.",
      "status": "implemented",
      "outline_line": 5655,
      "module_path": "lean/AsiStackProofs/FastGenerationRefinement.lean"
    },
    {
      "chapter_id": "fast-generation-architectures",
      "chapter_title": "Fast Generation Architectures",
      "tag": "lean:fast_generation.task_bundle_fixture_bridge",
      "module": "AsiStackProofs.FastGenerationRefinement",
      "formal_target": "A digest-bound external validator owns the three-route task result while Lean owns general task-success, cost-separation, speed-proxy, support-transition, and closure policy.",
      "status": "implemented",
      "outline_line": 5656,
      "module_path": "lean/AsiStackProofs/FastGenerationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.high_risk.missing_independent_verifier_blocks_execution",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "High-risk evaluation without an independent-enough review record is blocked before selection or planning handoff.",
      "status": "implemented",
      "outline_line": 5743,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.budget_exhausted.escrows_residual",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Budget or dispute exhaustion requires an owned residual before bounded planning handoff.",
      "status": "implemented",
      "outline_line": 5744,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.complete_high_risk.reaches_planning",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "A complete seven-receipt lifecycle reaches a bounded planning handoff and closure without execution, support, or external-effect authority.",
      "status": "implemented",
      "outline_line": 5745,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.missing_budget.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Candidate generation requires a prospectively bound budget and budget identity.",
      "status": "implemented",
      "outline_line": 5746,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.missing_search_mode.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Candidate generation requires a registered deliberation mode policy.",
      "status": "implemented",
      "outline_line": 5747,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.missing_verifier_scope.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Evaluation requires explicit obligations, verifier identity, evidence view, dependence, calibration, abstention, and false-decision boundaries.",
      "status": "implemented",
      "outline_line": 5748,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.missing_candidate_history.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Candidate generation requires first-candidate capture, complete history, trace privacy, and the complete attempt denominator.",
      "status": "implemented",
      "outline_line": 5749,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.missing_stop_condition.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Candidate generation and handoff require prospectively bound stop rules and a stop receipt.",
      "status": "implemented",
      "outline_line": 5750,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.missing_residual_owner.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "No verified candidate, exhausted budget, or unresolved dispute routes through residual escrow and closure.",
      "status": "implemented",
      "outline_line": 5751,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "governed-deliberation-and-test-time-scaling",
      "chapter_title": "Governed Deliberation and Test-Time Scaling",
      "tag": "lean:deliberation.trace_authority_laundering.requires_review",
      "module": "AsiStackProofs.DeliberationRefinement",
      "formal_target": "Raw scores, traces, and a planning handoff cannot grant support or execution authority.",
      "status": "implemented",
      "outline_line": 5752,
      "module_path": "lean/AsiStackProofs/DeliberationRefinement.lean"
    },
    {
      "chapter_id": "rankfold-neuralfold-and-artifact-compression",
      "chapter_title": "RankFold, NeuralFold, and Artifact Compression",
      "tag": "lean:compression.artifacts.operational_invariant",
      "module": "AsiStackProofs.ArtifactCompressionRefinement",
      "formal_target": "A reachable artifact-to-consumption lifecycle requires full-source custody, exact identities, reconstruction checks, consumer probes, executable fallback, observed outcomes, and closure before a qualified use can complete.",
      "status": "implemented",
      "outline_line": 5826,
      "module_path": "lean/AsiStackProofs/ArtifactCompressionRefinement.lean"
    },
    {
      "chapter_id": "rankfold-neuralfold-and-artifact-compression",
      "chapter_title": "RankFold, NeuralFold, and Artifact Compression",
      "tag": "lean:compression.artifacts.failure_blocks_promotion",
      "module": "AsiStackProofs.ArtifactCompressionRefinement",
      "formal_target": "Failed probes route to fallback, exact-replay gaps block use, raw ratios cannot promote support, and missing evidence transitions block consumption.",
      "status": "implemented",
      "outline_line": 5827,
      "module_path": "lean/AsiStackProofs/ArtifactCompressionRefinement.lean"
    },
    {
      "chapter_id": "rankfold-neuralfold-and-artifact-compression",
      "chapter_title": "RankFold, NeuralFold, and Artifact Compression",
      "tag": "lean:compression.artifacts.admission_lifecycle_route",
      "module": "AsiStackProofs.ArtifactCompressionRefinement",
      "formal_target": "Eight stages and 53 independently consumed routes govern registration, encoding, verification, probing, fallback, admission, observed consumption, and closure without support or external-effect authority.",
      "status": "implemented",
      "outline_line": 5828,
      "module_path": "lean/AsiStackProofs/ArtifactCompressionRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resources.budgets.operational_invariant",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "A reachable allocation lifecycle requires a scoped request, explicit resource inventory and units, direct, displaced, verification, and uncertainty costs, protected floors, bounded capacity, reviewer and verifier capacity, queue policy, observed spend, useful-outcome accounting, verification, reconciliation, and closure. Arbitrary accepted runs preserve nine bound identities and zero support/external-effect authority, account for exactly one receipt per event, keep resource-bill and reconciliation receipts monotone, compose across event batches, and admit no event after closure; an independent consumer rejects 170/170 mutations.",
      "status": "implemented",
      "outline_line": 5925,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resources.budgets.failure_blocks_promotion",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "Missing protected floors, reviewer capacity, failure retention, or evidence-transition accounting blocks the corresponding allocation stage; raw resource proxies cannot promote support.",
      "status": "implemented",
      "outline_line": 5926,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resources.costed_route.fixture_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "The stronger lifecycle digest-binds the bounded four-route cost fixture while preserving its two eligible and two rejected routes and its fixture-specific 66.98% arithmetic without inferring economic optimality.",
      "status": "implemented",
      "outline_line": 5927,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resources.workflow_trace.trace_property_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "The stronger lifecycle digest-binds the three-step workflow result and requires queue policy, high-risk priority, protected overhead, residual ownership, actual spend, verification outcome, variance, incidents, descendants, and closure.",
      "status": "implemented",
      "outline_line": 5928,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resources.capacity_smoothing.reviewer_trace_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "Reservation and scheduling require capacity, reviewer and verifier capacity, protected overhead, debt expiry, an owner, high-risk priority, tenant isolation, tail policy, fallback, and later variance and opportunity-cost reconciliation.",
      "status": "implemented",
      "outline_line": 5929,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resources.serving_memory.separation_guard",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "Observed resource bills and useful outcomes remain separate, and raw throughput, memory, or cost proxies cannot promote support without verification and evidence-transition accounting.",
      "status": "implemented",
      "outline_line": 5930,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resource.governance_tax.tradeoff_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "The lifecycle digest-binds the three-scenario governance-tax fixture while keeping its two governed choices and one low-risk shortcut explicitly synthetic, cost-complete only within the fixture, and non-promotional.",
      "status": "implemented",
      "outline_line": 5931,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:simulation.fidelity.operational_invariant",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "Transported simulation claims require explicit scope, fidelity, temporal semantics, resource bills, omissions, and a transfer decision before reconciliation.",
      "status": "implemented",
      "outline_line": 5932,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:simulation.fidelity.failure_blocks_promotion",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "A simulated claim above its declared fidelity support is blocked before reconciliation, and missing simulation scope, fidelity, temporal semantics, resource bills, omissions, or transfer decisions cannot pass.",
      "status": "implemented",
      "outline_line": 5933,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resource.simulation_fidelity.theseus_receipt_suite.fixture_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "The lifecycle digest-binds the sanitized five-scenario, six-receipt Theseus simulation result while preserving its seven invalid controls and excluding physical-feasibility, benchmark-transfer, native-parity, deployment, and support claims.",
      "status": "implemented",
      "outline_line": 5934,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "resource-economics-and-token-budgets",
      "chapter_title": "Resource Economics and Token Budgets",
      "tag": "lean:resource.simulation_fidelity.theseus_rlds_minari_trace_export.fixture_bridge",
      "module": "AsiStackProofs.ResourceEconomicsRefinement",
      "formal_target": "The lifecycle digest-binds the sanitized one-ready-export, three-format, seven-field Theseus trace result while preserving its seven invalid controls and excluding dataset-quality, replay-success, deployment, and support claims.",
      "status": "implemented",
      "outline_line": 5935,
      "module_path": "lean/AsiStackProofs/ResourceEconomicsRefinement.lean"
    },
    {
      "chapter_id": "physical-compute-infrastructure-energy-and-environmental-constraints",
      "chapter_title": "Physical Compute Infrastructure, Energy, and Environmental Constraints",
      "tag": "lean:physical-compute-infrastructure-energy-and-environmental-constraints.admission_boundary",
      "module": "AsiStackProofs.PhysicalComputeInfrastructureReview",
      "formal_target": "A reachable six-transition physical-infrastructure review admits only dossiers that bind workload, site, interval, hardware, topology, workload version, and meter version; separate requested, nameplate, available, delivered, and useful compute; account capacity, energy, cooling, water, materials, community, uncertainty, resilience, retirement, rebound, and residual ownership; and reject broad availability, sustainability, resilience, community-acceptability, support, and release claims. All 44 admission-axis mutations reject with exact repairs. Finite workload demand and attributed energy compose; demand growth, capacity loss, expiry, and hidden backup energy remain rejecting; five scope changes invalidate receipts; two signal collisions prove that energy headlines cannot recover useful delivery and unit efficiency cannot recover total impact; and missing physical capacity rejects the Resource Economics budget gate. No theorem establishes delivered performance, sustainability, resilience, community acceptance, deployment, support, or transfer.",
      "status": "implemented",
      "outline_line": 5995,
      "module_path": "lean/AsiStackProofs/PhysicalComputeInfrastructureReview.lean"
    },
    {
      "chapter_id": "mathematical-and-search-substrates",
      "chapter_title": "Mathematical and Search Substrates",
      "tag": "lean:substrates.search.operational_invariant",
      "module": "AsiStackProofs.SearchSubstrates",
      "formal_target": "A substrate adoption record missing a baseline reference, measured target, or falsification criterion fails the finite adoption-fields predicate.",
      "status": "implemented",
      "outline_line": 6056,
      "module_path": "lean/AsiStackProofs/SearchSubstrates.lean"
    },
    {
      "chapter_id": "mathematical-and-search-substrates",
      "chapter_title": "Mathematical and Search Substrates",
      "tag": "lean:substrates.search.failure_blocks_promotion",
      "module": "AsiStackProofs.SearchSubstrates",
      "formal_target": "A substrate record marked qualified without passing evidence fails the finite core-adoption predicate.",
      "status": "implemented",
      "outline_line": 6057,
      "module_path": "lean/AsiStackProofs/SearchSubstrates.lean"
    },
    {
      "chapter_id": "mathematical-and-search-substrates",
      "chapter_title": "Mathematical and Search Substrates",
      "tag": "lean:substrates.search.adoption_trace_bridge",
      "module": "AsiStackProofs.SearchSubstrates",
      "formal_target": "A reachable formal substrate-adoption classifier derives four accepted non-promoting states and eight exact rejecting controls from concrete trace inputs; consumer permission is reserved to measured-positive routes, while failed controls, theorem spillover, missing fallback, support promotion, and incomplete boundaries reject.",
      "status": "implemented",
      "outline_line": 6058,
      "module_path": "lean/AsiStackProofs/SearchSubstrates.lean"
    },
    {
      "chapter_id": "circle-calculus-and-proof-carrying-ai-contracts",
      "chapter_title": "Circle Calculus and Proof-Carrying AI Contracts",
      "tag": "lean:circle_contracts.receipt_requires_boundary.operational_invariant",
      "module": "AsiStackProofs.ProofCarryingContracts",
      "formal_target": "A finite proof-contract receipt missing theorem references, deterministic fields, or an explicit non-claim boundary is rejected from downstream use.",
      "status": "implemented",
      "outline_line": 6123,
      "module_path": "lean/AsiStackProofs/ProofCarryingContracts.lean"
    },
    {
      "chapter_id": "circle-calculus-and-proof-carrying-ai-contracts",
      "chapter_title": "Circle Calculus and Proof-Carrying AI Contracts",
      "tag": "lean:circle_contracts.consumer_gate.failure_blocks_promotion",
      "module": "AsiStackProofs.ProofCarryingContracts",
      "formal_target": "A downstream claim cannot be promoted solely from contract readiness without a workload, baseline, metric, and evidence artifact.",
      "status": "implemented",
      "outline_line": 6124,
      "module_path": "lean/AsiStackProofs/ProofCarryingContracts.lean"
    },
    {
      "chapter_id": "circle-calculus-and-proof-carrying-ai-contracts",
      "chapter_title": "Circle Calculus and Proof-Carrying AI Contracts",
      "tag": "lean:circle_contracts.public_consumer_gate.fixture_bridge",
      "module": "AsiStackProofs.ProofCarryingContracts",
      "formal_target": "Any record satisfying the finite Circle public-consumer acceptance contract loses acceptance when promotion/deployed-transport overclaims or required mutation-control rejections are present; an independent replay validator separately computes one valid receipt and four invalid controls.",
      "status": "implemented",
      "outline_line": 6125,
      "module_path": "lean/AsiStackProofs/ProofCarryingContracts.lean"
    },
    {
      "chapter_id": "circle-calculus-and-proof-carrying-ai-contracts",
      "chapter_title": "Circle Calculus and Proof-Carrying AI Contracts",
      "tag": "lean:circle_contracts.versioned_transport.descendant_revocation",
      "module": "AsiStackProofs.ProofCarryingContracts",
      "formal_target": "The finite versioned transport state machine preserves theorem, parent, consumer, support, and external-effect custody plus zero-authority and revocation coherence across arbitrary event lists; rejects invalid events without state change; composes traces; confines revoked descendants across arbitrary suffixes; and preserves unrelated-lineage availability.",
      "status": "implemented",
      "outline_line": 6126,
      "module_path": "lean/AsiStackProofs/ProofCarryingContracts.lean"
    },
    {
      "chapter_id": "coil-attention-cyclic-memory-and-recurrence-contracts",
      "chapter_title": "Coil Attention, Cyclic Memory, and Recurrence Contracts",
      "tag": "lean:coil_memory.alias_boundary.operational_invariant",
      "module": "AsiStackProofs.CoilAttentionMemory",
      "formal_target": "A reused cyclic slot with missing residue or winding and no visible alias residual fails the finite alias-boundary predicate.",
      "status": "implemented",
      "outline_line": 6204,
      "module_path": "lean/AsiStackProofs/CoilAttentionMemory.lean"
    },
    {
      "chapter_id": "coil-attention-cyclic-memory-and-recurrence-contracts",
      "chapter_title": "Coil Attention, Cyclic Memory, and Recurrence Contracts",
      "tag": "lean:coil_attention.coverage_not_quality.failure_blocks_promotion",
      "module": "AsiStackProofs.CoilAttentionMemory",
      "formal_target": "A retrieval-quality record that promotes from sparse coverage and freshness while semantic-quality evidence is absent fails the finite quality-promotion predicate.",
      "status": "implemented",
      "outline_line": 6205,
      "module_path": "lean/AsiStackProofs/CoilAttentionMemory.lean"
    },
    {
      "chapter_id": "coil-attention-cyclic-memory-and-recurrence-contracts",
      "chapter_title": "Coil Attention, Cyclic Memory, and Recurrence Contracts",
      "tag": "lean:coil_memory.versioned_freshness_and_recurrence.lifecycle",
      "module": "AsiStackProofs.CoilAttentionMemory",
      "formal_target": "A finite cyclic-memory lifecycle proves residue-only addressing non-injective and complete residue-plus-winding encoding injective; preserves custody, budget safety, zero support/effect authority, freshness-stage coherence, and recurrence monotonicity across arbitrary event lists; composes traces; confines stale classifications away from fresh consumption across arbitrary suffixes; and makes closure absorbing.",
      "status": "implemented",
      "outline_line": 6206,
      "module_path": "lean/AsiStackProofs/CoilAttentionMemory.lean"
    },
    {
      "chapter_id": "coilra-multicoil-rope-and-cyclic-mixers",
      "chapter_title": "CoilRA, MultiCoil RoPE, and Cyclic Mixers",
      "tag": "lean:cyclic_mixers.structural_not_quality.operational_invariant",
      "module": "AsiStackProofs.CyclicMixers",
      "formal_target": "A cyclic mixer review missing any structural, quality, runtime, memory, or parameter partition fails the finite structural-claim predicate.",
      "status": "implemented",
      "outline_line": 6323,
      "module_path": "lean/AsiStackProofs/CyclicMixers.lean"
    },
    {
      "chapter_id": "coilra-multicoil-rope-and-cyclic-mixers",
      "chapter_title": "CoilRA, MultiCoil RoPE, and Cyclic Mixers",
      "tag": "lean:cyclic_mixers.baseline_required.failure_blocks_promotion",
      "module": "AsiStackProofs.CyclicMixers",
      "formal_target": "A promoted cyclic substrate missing baseline references or tradeoff metrics fails the finite promotion predicate.",
      "status": "implemented",
      "outline_line": 6324,
      "module_path": "lean/AsiStackProofs/CyclicMixers.lean"
    },
    {
      "chapter_id": "executable-specifications-and-lean-proof-envelope",
      "chapter_title": "Executable Specifications and Lean Proof Envelope",
      "tag": "lean:proofs.envelope.operational_invariant",
      "module": "AsiStackProofs.ProofEnvelope",
      "formal_target": "An exact formal-artifact authority lease preserves target, proposition, verifier, consumer, implementation, environment, expiry, support, and effect custody over arbitrary runs; artifact versions increase only on explicit change; a ten-event witness invalidates, re-verifies, rebinds, reissues, and revokes.",
      "status": "implemented",
      "outline_line": 6470,
      "module_path": "lean/AsiStackProofs/ProofEnvelope.lean"
    },
    {
      "chapter_id": "executable-specifications-and-lean-proof-envelope",
      "chapter_title": "Executable Specifications and Lean Proof Envelope",
      "tag": "lean:proofs.envelope.failure_blocks_promotion",
      "module": "AsiStackProofs.ProofEnvelope",
      "formal_target": "Lease issuance rejects mismatched identity, missing artifact, adequacy, consumer, limitation, or non-claim boundaries, expiry, support promotion, or external-effect authority; rejected events are noninterfering, revoked states absorb suffixes, thin summaries cannot recover boundary-sensitive issue decisions, and complete transport preserves steps.",
      "status": "implemented",
      "outline_line": 6471,
      "module_path": "lean/AsiStackProofs/ProofEnvelope.lean"
    },
    {
      "chapter_id": "benchmark-ratchets-and-anti-goodhart-evidence",
      "chapter_title": "Benchmark Ratchets and Anti-Goodhart Evidence",
      "tag": "lean:benchmarks.ratchet.operational_invariant",
      "module": "AsiStackProofs.BenchmarkRatchets",
      "formal_target": "Every arbitrary finite ratchet run preserves instrument, dataset, harness, claim, authority, evidence-policy, support, and effect custody plus stage/outcome coherence; every accepted trace accounts for exactly one receipt per event and composes across batches; clean evidence reaches only a non-authorizing independent-review candidate.",
      "status": "implemented",
      "outline_line": 6599,
      "module_path": "lean/AsiStackProofs/BenchmarkRatchets.lean"
    },
    {
      "chapter_id": "benchmark-ratchets-and-anti-goodhart-evidence",
      "chapter_title": "Benchmark Ratchets and Anti-Goodhart Evidence",
      "tag": "lean:benchmarks.ratchet.failure_blocks_promotion",
      "module": "AsiStackProofs.BenchmarkRatchets",
      "formal_target": "The finite ratchet lifecycle quarantines suspected contamination, preserves quarantine across arbitrary finite suffixes, routes saturated clean instruments to regression-floor status, rejects missing transfer or preserved-evidence records without state change, makes closure absorbing, and proves that an aggregate pass count cannot exactly classify modeled promotion admissibility.",
      "status": "implemented",
      "outline_line": 6600,
      "module_path": "lean/AsiStackProofs/BenchmarkRatchets.lean"
    },
    {
      "chapter_id": "benchmark-ratchets-and-anti-goodhart-evidence",
      "chapter_title": "Benchmark Ratchets and Anti-Goodhart Evidence",
      "tag": "lean:benchmarks.ratchet.fixture_bridge",
      "module": "AsiStackProofs.BenchmarkRatchets",
      "formal_target": "An independent benchmark anti-Goodhart consumer computes two valid fixtures and five rejected controls, recompiles the exact 29-declaration Lean surface, executes clean, saturated, and contaminated witnesses, checks all seven clean-trace splits, explores 19 reachable states through 114 transitions, checks 12 quarantine suffixes, and rejects 15 lifecycle plus 11 semantic mutations; executable totals remain separate from quantified Lean semantics.",
      "status": "implemented",
      "outline_line": 6601,
      "module_path": "lean/AsiStackProofs/BenchmarkRatchets.lean"
    },
    {
      "chapter_id": "white-box-evidence-interpretability-and-activation-governance",
      "chapter_title": "White-Box Evidence, Interpretability, and Activation Governance",
      "tag": "lean:white_box.evidence_never_grants_authority",
      "module": "AsiStackProofs.WhiteBoxEvidence",
      "formal_target": "Every successful finite governance run preserves exact packet/model/checkpoint/method/population/version identity, never increases active authority, never gains support or external-effect authority, has a valid trace, composes across event batches, and cannot route to an authority-widening grant.",
      "status": "implemented",
      "outline_line": 6705,
      "module_path": "lean/AsiStackProofs/WhiteBoxEvidence.lean"
    },
    {
      "chapter_id": "white-box-evidence-interpretability-and-activation-governance",
      "chapter_title": "White-Box Evidence, Interpretability, and Activation Governance",
      "tag": "lean:white_box.invalid_packet_rejected",
      "module": "AsiStackProofs.WhiteBoxEvidence",
      "formal_target": "Policy routing requires an admissible current packet with fresh lineage, method assumptions, negative controls, and bounded-causal checks; consumption requires complete receipts and zero residuals, while stale or incomplete packets cannot route.",
      "status": "implemented",
      "outline_line": 6706,
      "module_path": "lean/AsiStackProofs/WhiteBoxEvidence.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.crossed.missing_verified_safeguards_blocks_release",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "A crossed-threshold lifecycle cannot reach control completion without a safeguard package, verifier, bypass test, and rollback plan.",
      "status": "implemented",
      "outline_line": 6802,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.missing_evaluation_envelope.requires_reevaluation",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "Missing evaluation envelope, elicitation, baseline, uncertainty, independent-evaluator, or assessment-result custody blocks assessment.",
      "status": "implemented",
      "outline_line": 6803,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.complete_crossed.reaches_readiness_review",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "A fully recorded crossed-threshold assessment can emit only a readiness handoff after control, monitoring, residual, authority, and release-path custody.",
      "status": "implemented",
      "outline_line": 6804,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.complete_non_crossing.reaches_readiness_review",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "A recorded non-crossing may bypass crossed-only safeguard gates but still requires monitoring, residual, authority, and release-path custody before readiness review.",
      "status": "implemented",
      "outline_line": 6805,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.missing_baseline.requires_reevaluation",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "Missing baseline blocks the scoped-to-assessed transition without mutating threshold state.",
      "status": "implemented",
      "outline_line": 6806,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.missing_uncertainty.requires_reevaluation",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "Missing assessment or decision uncertainty blocks lifecycle progress without converting absence into a non-crossing.",
      "status": "implemented",
      "outline_line": 6807,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.missing_residual_owner.requires_exception",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "Missing residual ownership blocks adjudication or readiness; an exception additionally requires owner, expiry, compensating controls, and a review trigger.",
      "status": "implemented",
      "outline_line": 6808,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "capability-thresholds-and-deployment-commitments",
      "chapter_title": "Capability Thresholds and Deployment Commitments",
      "tag": "lean:capability_thresholds.crossed.missing_safeguard_record.blocks_release",
      "module": "AsiStackProofs.CapabilityThresholdRefinement",
      "formal_target": "A crossed threshold without the complete safeguard-verification envelope remains blocked, while later envelope change requires descendant invalidation and a successor assessment version.",
      "status": "implemented",
      "outline_line": 6809,
      "module_path": "lean/AsiStackProofs/CapabilityThresholdRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.complete_to_promotion_review",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "A reachable, prospectively bound observation lifecycle can emit only a bounded decision-review handoff after complete observation, independent-probe, alternative-hypothesis, discrepancy, uncertainty, residual, expiry, and authority-separation custody.",
      "status": "implemented",
      "outline_line": 6878,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.missing_selection_context",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "Missing selection context blocks observation admission without mutating lifecycle state.",
      "status": "implemented",
      "outline_line": 6879,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.missing_reward_provenance",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "Missing reward provenance blocks observation admission without converting absence into behavioral evidence.",
      "status": "implemented",
      "outline_line": 6880,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.missing_monitor_provenance",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "Missing monitor provenance blocks observation admission without treating an unobserved trace as negative evidence.",
      "status": "implemented",
      "outline_line": 6881,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.missing_independent_evaluation",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "Missing independent evaluation or evaluator separation blocks adjudication.",
      "status": "implemented",
      "outline_line": 6882,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.missing_cross_context_probe",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "Missing cross-context or matched-access comparison blocks adjudication.",
      "status": "implemented",
      "outline_line": 6883,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.unresolved_discrepancy",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "An unresolved discrepancy requires explicit quarantine custody and cannot take the favorable promotion-review route.",
      "status": "implemented",
      "outline_line": 6884,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "adversarial-evaluation-sandbagging-and-training-time-deception",
      "chapter_title": "Adversarial Evaluation, Sandbagging, and Training-Time Deception",
      "tag": "lean:adversarial_evaluation.integrity.intent_laundering",
      "module": "AsiStackProofs.AdversarialEvaluationRefinement",
      "formal_target": "An observation lifecycle rejects intent inference and cannot assign support or an external decision effect.",
      "status": "implemented",
      "outline_line": 6885,
      "module_path": "lean/AsiStackProofs/AdversarialEvaluationRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.complete_case.reaches_readiness_review",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "A reachable case lifecycle binds exact case, context, hazard, evidence, challenge, review, authority, and residual identity before emitting a readiness handoff that assigns no release authority.",
      "status": "implemented",
      "outline_line": 6970,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.missing_context.retains_draft",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "Missing deployment context blocks the draft-to-scoped transition without mutating case state.",
      "status": "implemented",
      "outline_line": 6971,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.missing_hazard.requires_case_repair",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "Missing hazard or argument structure blocks scope admission without mutating case state.",
      "status": "implemented",
      "outline_line": 6972,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.stale_evidence.requires_repair",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "Missing, stale, or assumption-free evidence blocks the scoped-to-evidenced transition.",
      "status": "implemented",
      "outline_line": 6973,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.missing_countercase.requires_review",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "Missing countercase review or defeater disposition blocks challenge closure.",
      "status": "implemented",
      "outline_line": 6974,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.missing_independent_review.requires_review",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "Missing competence records, conflict disclosure, or independent review blocks reviewed status.",
      "status": "implemented",
      "outline_line": 6975,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.unresolved_defeater.blocks_affected_release",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "An unresolved defeater blocks progression, while later invalidation requires cause, affected paths, and complete descendant invalidation before returning a readiness-bound case to challenge.",
      "status": "implemented",
      "outline_line": 6976,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "safety-cases-and-structured-assurance",
      "chapter_title": "Safety Cases and Structured Assurance",
      "tag": "lean:safety_cases.case_status.cannot_authorize_release",
      "module": "AsiStackProofs.SafetyCaseRefinement",
      "formal_target": "Case status cannot assign support or an external effect, and missing separation between case status and decision authority rejects the readiness handoff.",
      "status": "implemented",
      "outline_line": 6977,
      "module_path": "lean/AsiStackProofs/SafetyCaseRefinement.lean"
    },
    {
      "chapter_id": "content-authenticity-watermarking-and-synthetic-media-integrity",
      "chapter_title": "Content Authenticity, Watermarking, and Synthetic Media Integrity",
      "tag": "lean:content-authenticity-watermarking-and-synthetic-media-integrity.admission_boundary",
      "module": "AsiStackProofs.ContentAuthenticityReview",
      "formal_target": "An eight-transition finite authenticity-envelope review preserves identity, typed evidence, transformation, current trust, conflict/remedy, accessible-disclosure, and non-authority invariants; 42 exact mutation repairs, receipt/staleness invalidation, transformation rejection, semantic-truth and origin-from-absence impossibility results, and a rejecting communication-consumer bridge prove only authored record and information-loss properties before Project Theseus evaluation.",
      "status": "implemented",
      "outline_line": 7012,
      "module_path": "lean/AsiStackProofs/ContentAuthenticityReview.lean"
    },
    {
      "chapter_id": "governed-operations-incident-command-and-graceful-degradation",
      "chapter_title": "Governed Operations, Incident Command, and Graceful Degradation",
      "tag": "lean:operations.degradation_never_widens_authority",
      "module": "AsiStackProofs.GovernedOperations",
      "formal_target": "Every finite degraded-mode transition preserves or narrows capability, data, tool, and duration authority.",
      "status": "implemented",
      "outline_line": 7130,
      "module_path": "lean/AsiStackProofs/GovernedOperations.lean"
    },
    {
      "chapter_id": "governed-operations-incident-command-and-graceful-degradation",
      "chapter_title": "Governed Operations, Incident Command, and Graceful Degradation",
      "tag": "lean:operations.recovery_requires_complete_state",
      "module": "AsiStackProofs.GovernedOperations",
      "formal_target": "Normal-service recovery is rejected when any required internal-state component, external-effect disposition, acceptance check, or emergency-authority expiry is missing.",
      "status": "implemented",
      "outline_line": 7131,
      "module_path": "lean/AsiStackProofs/GovernedOperations.lean"
    },
    {
      "chapter_id": "governed-operations-incident-command-and-graceful-degradation",
      "chapter_title": "Governed Operations, Incident Command, and Graceful Degradation",
      "tag": "lean:operations.incident_lifecycle_refines_static_contracts",
      "module": "AsiStackProofs.GovernedOperationsRefinement",
      "formal_target": "A reachable eight-stage incident lifecycle preserves exact state on rejection, refines the existing degradation and recovery predicates at accepted boundaries, expires emergency authority before restoration, and re-enters incident control on modeled recurrence without assigning support or external authority.",
      "status": "implemented",
      "outline_line": 7132,
      "module_path": "lean/AsiStackProofs/GovernedOperationsRefinement.lean"
    },
    {
      "chapter_id": "adjudicated-persistence-and-the-adaptive-commit-boundary",
      "chapter_title": "Adjudicated Persistence and the Adaptive Commit Boundary",
      "tag": "lean:persistence.outcome_only_placement_nonidentifiability",
      "module": "AsiStackProofs.AdjudicatedPersistence",
      "formal_target": "Two experiences with the same observed outcome but different latent defects can require different admissible persistence loci, so outcome alone cannot identify a correct placement rule.",
      "status": "planned",
      "outline_line": 7245,
      "module_path": "lean/AsiStackProofs/AdjudicatedPersistence.lean"
    },
    {
      "chapter_id": "adjudicated-persistence-and-the-adaptive-commit-boundary",
      "chapter_title": "Adjudicated Persistence and the Adaptive Commit Boundary",
      "tag": "lean:persistence.commitment_dominance_evidence_monotonicity",
      "module": "AsiStackProofs.AdjudicatedPersistence",
      "formal_target": "If one finite commitment profile dominates another on every governed dimension, admission of the stronger profile cannot require a weaker evidence class under a monotone policy.",
      "status": "planned",
      "outline_line": 7246,
      "module_path": "lean/AsiStackProofs/AdjudicatedPersistence.lean"
    },
    {
      "chapter_id": "adjudicated-persistence-and-the-adaptive-commit-boundary",
      "chapter_title": "Adjudicated Persistence and the Adaptive Commit Boundary",
      "tag": "lean:persistence.transaction_requires_distinct_qualification_authority",
      "module": "AsiStackProofs.AdjudicatedPersistence",
      "formal_target": "A realized artifact lacking either qualification or authority cannot reach the finite admitted-use state.",
      "status": "planned",
      "outline_line": 7247,
      "module_path": "lean/AsiStackProofs/AdjudicatedPersistence.lean"
    },
    {
      "chapter_id": "adjudicated-persistence-and-the-adaptive-commit-boundary",
      "chapter_title": "Adjudicated Persistence and the Adaptive Commit Boundary",
      "tag": "lean:persistence.meta_compiler_non_self_ratification",
      "module": "AsiStackProofs.AdjudicatedPersistence",
      "formal_target": "A placement-compiler change is rejected when the candidate controls its own sole evidence, evaluation, and promotion authority.",
      "status": "planned",
      "outline_line": 7248,
      "module_path": "lean/AsiStackProofs/AdjudicatedPersistence.lean"
    },
    {
      "chapter_id": "adjudicated-persistence-and-the-adaptive-commit-boundary",
      "chapter_title": "Adjudicated Persistence and the Adaptive Commit Boundary",
      "tag": "lean:persistence.descendant_invalidation_residual_closure",
      "module": "AsiStackProofs.AdjudicatedPersistence",
      "formal_target": "Revoking an ancestor realization reaches every modeled descendant through removal, deoptimization, compensation, or an explicit residual disposition.",
      "status": "planned",
      "outline_line": 7249,
      "module_path": "lean/AsiStackProofs/AdjudicatedPersistence.lean"
    },
    {
      "chapter_id": "policy-optimization-and-learning-from-feedback",
      "chapter_title": "Policy Optimization and Learning from Feedback",
      "tag": "lean:policy_optimization.update.operational_invariant",
      "module": "AsiStackProofs.PolicyOptimizationRefinement",
      "formal_target": "A versioned governed-update lifecycle binds target, baseline, objective, data, feedback, full optimizer/checkpoint/RNG and descendant state, evaluation, adjudication, bounded consumption, rollback, and readmission without assigning support or an external effect.",
      "status": "implemented",
      "outline_line": 7358,
      "module_path": "lean/AsiStackProofs/PolicyOptimizationRefinement.lean"
    },
    {
      "chapter_id": "policy-optimization-and-learning-from-feedback",
      "chapter_title": "Policy Optimization and Learning from Feedback",
      "tag": "lean:policy_optimization.reward_boundary.failure_blocks_promotion",
      "module": "AsiStackProofs.PolicyOptimizationRefinement",
      "formal_target": "Missing target evaluation, causal ablation, reward-hacking probes, regression, forgetting, safety/rights, uncertainty, or independent evaluation blocks a policy update before bounded-lease adjudication.",
      "status": "implemented",
      "outline_line": 7359,
      "module_path": "lean/AsiStackProofs/PolicyOptimizationRefinement.lean"
    },
    {
      "chapter_id": "policy-optimization-and-learning-from-feedback",
      "chapter_title": "Policy Optimization and Learning from Feedback",
      "tag": "lean:policy_optimization.promotion_route.failure_routes",
      "module": "AsiStackProofs.PolicyOptimizationRefinement",
      "formal_target": "All finite update-lifecycle routes reject or redirect incomplete scope, state, update, evaluation, adjudication, lease, rollback, or readmission records before bounded use.",
      "status": "implemented",
      "outline_line": 7360,
      "module_path": "lean/AsiStackProofs/PolicyOptimizationRefinement.lean"
    },
    {
      "chapter_id": "policy-optimization-and-learning-from-feedback",
      "chapter_title": "Policy Optimization and Learning from Feedback",
      "tag": "lean:policy_optimization.lease_probe_fixture_bridge",
      "module": "AsiStackProofs.PolicyOptimizationRefinement",
      "formal_target": "The independently consumed six-sample/five-candidate lease probe and the reachable lifecycle preserve three rejected controls, experimental-only use, versioned readmission, and no support or external-effect authority.",
      "status": "implemented",
      "outline_line": 7361,
      "module_path": "lean/AsiStackProofs/PolicyOptimizationRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.provenance_authority.failure_blocks_admission",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing bound provenance, rights, or authority blocks the reachable custody lifecycle before data admission.",
      "status": "implemented",
      "outline_line": 7535,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.contamination.failure_routes",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing split exclusions or a contamination-check record blocks the reachable custody lifecycle before admission.",
      "status": "implemented",
      "outline_line": 7536,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.complete_receipt.eligibility_invariant",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "A complete admission record advances only to full-state binding and does not establish data quality, training, deletion, or support.",
      "status": "implemented",
      "outline_line": 7537,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.complete_reaches_evidence_review",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Complete declared full-state custody and a prospectively fixed selection rule advance only to an update receipt, not promotion.",
      "status": "implemented",
      "outline_line": 7538,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_optimizer_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing optimizer state blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7539,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_scheduler_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing scheduler state blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7540,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_rng_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing RNG state blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7541,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_cache_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing cache state blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7542,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_backup_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing backup state blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7543,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_descendant_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing descendant state blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7544,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.missing_checkpoint_authority_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Missing prospective checkpoint authority or selection rule blocks full-state binding.",
      "status": "implemented",
      "outline_line": 7545,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.full_state.rollback_mismatch_requires_repair",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "A declared-surface rollback mismatch blocks the update record and cannot be generalized to semantic or production recovery.",
      "status": "implemented",
      "outline_line": 7546,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.unlearning.behavior_cannot_launder_influence",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Behavioral cohort change cannot serve as evidence of causal influence reduction in deletion-claim adjudication.",
      "status": "implemented",
      "outline_line": 7547,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.unlearning.behavior_cannot_launder_privacy",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Behavioral cohort change cannot serve as evidence of privacy protection or erasure in deletion-claim adjudication.",
      "status": "implemented",
      "outline_line": 7548,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "data-engines-continual-learning-and-unlearning",
      "chapter_title": "Data Engines, Continual Learning, and Unlearning",
      "tag": "lean:data_engines.unlearning.lineage_cannot_launder_storage",
      "module": "AsiStackProofs.DataEngineLifecycleRefinement",
      "formal_target": "Lineage propagation or invalidation cannot serve as evidence of physical storage or backup erasure in deletion-claim adjudication.",
      "status": "implemented",
      "outline_line": 7549,
      "module_path": "lean/AsiStackProofs/DataEngineLifecycleRefinement.lean"
    },
    {
      "chapter_id": "scientific-discovery-and-experimental-governance",
      "chapter_title": "Scientific Discovery and Experimental Governance",
      "tag": "lean:scientific-discovery-and-experimental-governance.admission_boundary",
      "module": "AsiStackProofs.ScientificExperimentReview",
      "formal_target": "An eight-transition experiment review admits only dossiers that bind hypothesis ancestry, exploration versus confirmation, preregistered design, instrument authority, complete attempts, analysis, replication, correction, dual-use custody, expiry, and explicit non-authority. All 54 admission-axis mutations reject with exact repairs. Finite attempt identity composes and preserves every member, omitted attempts and outcome-exposed confirmatory branches reject completeness, expiry and denominator or replication gaps remain rejecting under adverse changes, seven scope changes invalidate receipts, significance cannot recover preregistration integrity, replication counts cannot recover independence, missing independent replication blocks Evidence States empirical promotion, and missing null results reject Benchmark Ratchet promotion. No theorem establishes hypothesis truth, causal identification, instrument accuracy, reproducibility, discovery, laboratory safety, support, release, or external effect.",
      "status": "implemented",
      "outline_line": 7619,
      "module_path": "lean/AsiStackProofs/ScientificExperimentReview.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.work_contract.operational_invariant",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A reachable steward dispatch model derives contract repair, refusal, or approval when objective, authority, tool, verification, budget, rollback, or non-claim boundaries are missing; arbitrary-length runs reach dispatch readiness only from a complete modeled contract.",
      "status": "implemented",
      "outline_line": 7753,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.treasury_boundary.failure_blocks_promotion",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A finite steward lifecycle decision with requested treasury spend outside policy routes to approval.",
      "status": "implemented",
      "outline_line": 7754,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.release_gate.operational_invariant",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A reachable steward release model derives repair, refusal, or approval when artifact, test, evidence, changelog, residual, approval, no-promotion, or non-claim records are missing; arbitrary-length runs reach external-review readiness only from a complete modeled packet.",
      "status": "implemented",
      "outline_line": 7755,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.sunset_review.failure_blocks_promotion",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A finite steward lifecycle decision with sunset criteria met and no open review routes to sunset review.",
      "status": "implemented",
      "outline_line": 7756,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.lifecycle_route.failure_blocks_promotion",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A steward lifecycle route sends tainted unreviewed events to quarantine, sunset criteria without review to sunset review, autonomy escalation without charter approval to approval, and over-policy treasury spend to approval.",
      "status": "implemented",
      "outline_line": 7757,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.contribution_ledger.operational_invariant",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A steward contribution ledger keeps authorship, review, evidence, compensation, reputation, governance effect, and conflicts separated; collapsed governance scoring is rejected and support-state changes require evidence-transition records.",
      "status": "implemented",
      "outline_line": 7758,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "artifact-steward-agents-and-living-project-governance",
      "chapter_title": "Artifact Steward Agents and Living Project Governance",
      "tag": "lean:artifact_stewards.federation_contract.operational_invariant",
      "module": "AsiStackProofs.ArtifactStewardAgents",
      "formal_target": "A steward federation contract requires scoped work contracts, bounded worker authority, tool/data/budget gates, external-spend approval, and evidence-bundle requirements before dispatch.",
      "status": "implemented",
      "outline_line": 7759,
      "module_path": "lean/AsiStackProofs/ArtifactStewardAgents.lean"
    },
    {
      "chapter_id": "integrated-reference-architecture",
      "chapter_title": "Integrated Reference Architecture",
      "tag": "lean:reference_architecture.trace.operational_invariant",
      "module": "AsiStackProofs.IntegratedReferenceTrace",
      "formal_target": "Every accepted finite cross-layer run joins exact parent artifacts and canonical state at each typed handoff, preserves the authority ceiling and non-increasing active authority, advances logical time monotonically, preserves effect-accounting and residual-conservation invariants, composes across event batches, and rejects suffixes after a terminal or quarantine state.",
      "status": "implemented",
      "outline_line": 7903,
      "module_path": "lean/AsiStackProofs/IntegratedReferenceTrace.lean"
    },
    {
      "chapter_id": "integrated-reference-architecture",
      "chapter_title": "Integrated Reference Architecture",
      "tag": "lean:reference_architecture.trace.failure_blocks_promotion",
      "module": "AsiStackProofs.IntegratedReferenceTrace",
      "formal_target": "A cross-layer transition with a parent/state fork, missing governance gate, residual erasure, effect after revocation, unacknowledged terminal effect, missing receipt, or incomplete rollback is rejected or contained in quarantine.",
      "status": "implemented",
      "outline_line": 7904,
      "module_path": "lean/AsiStackProofs/IntegratedReferenceTrace.lean"
    },
    {
      "chapter_id": "integrated-reference-architecture",
      "chapter_title": "Integrated Reference Architecture",
      "tag": "lean:reference_architecture.governed_trace.four_invariants",
      "module": "AsiStackProofs.IntegratedReferenceTrace",
      "formal_target": "The source-anchored finite consumers compose approved, blocked, rolled-back, quarantined, and concurrent effect traces while preserving joined artifact/state lineage, authority and epoch monotonicity, effect acknowledgement or explicit terminal disposition, evidence, residual, terminal-receipt, and no-promotion boundaries; the authored one-effect projection agrees across the layer and effect models.",
      "status": "implemented",
      "outline_line": 7905,
      "module_path": "lean/AsiStackProofs/IntegratedReferenceTrace.lean"
    },
    {
      "chapter_id": "project-theseus-as-report-first-implementation-reference",
      "chapter_title": "Project Theseus as Report-First Implementation Reference",
      "tag": "lean:theseus.reference.report_contract.operational_invariant",
      "module": "AsiStackProofs.TheseusReference",
      "formal_target": "A finite implementation-reference claim that lacks both a report and a config-or-tool reference, or relies on dashboard prose alone, is rejected.",
      "status": "implemented",
      "outline_line": 8001,
      "module_path": "lean/AsiStackProofs/TheseusReference.lean"
    },
    {
      "chapter_id": "project-theseus-as-report-first-implementation-reference",
      "chapter_title": "Project Theseus as Report-First Implementation Reference",
      "tag": "lean:theseus.reference.gate_before_promotion.failure_blocks_promotion",
      "module": "AsiStackProofs.TheseusReference",
      "formal_target": "A capability or self-evolution promotion is blocked when required gate reports are absent or failing.",
      "status": "implemented",
      "outline_line": 8002,
      "module_path": "lean/AsiStackProofs/TheseusReference.lean"
    },
    {
      "chapter_id": "project-theseus-as-report-first-implementation-reference",
      "chapter_title": "Project Theseus as Report-First Implementation Reference",
      "tag": "lean:theseus.reference.report_bundle_audit.fixture_bridge",
      "module": "AsiStackProofs.TheseusReference",
      "formal_target": "A public-safe Theseus report-bundle audit fixture is accepted only when bundle components, replay-readiness rows, crosswalk rows, gate mappings, work-board contract fields, visible artifact gaps, intervention-ladder ordering, and no-promotion boundaries are complete.",
      "status": "implemented",
      "outline_line": 8003,
      "module_path": "lean/AsiStackProofs/TheseusReference.lean"
    },
    {
      "chapter_id": "prototype-roadmap",
      "chapter_title": "Prototype Roadmap",
      "tag": "lean:roadmap.phases.operational_invariant",
      "module": "AsiStackProofs.PrototypeRoadmap",
      "formal_target": "Strict finite dependency order and a dependency-aware execution lifecycle preserve exact phase, plan, dependency, artifact, authority, and gate custody across arbitrary runs; only a complete non-promoting trace reaches integration.",
      "status": "implemented",
      "outline_line": 8063,
      "module_path": "lean/AsiStackProofs/PrototypeRoadmap.lean"
    },
    {
      "chapter_id": "prototype-roadmap",
      "chapter_title": "Prototype Roadmap",
      "tag": "lean:roadmap.phases.failure_blocks_promotion",
      "module": "AsiStackProofs.PrototypeRoadmap",
      "formal_target": "Missing dependency completion, rollback, evaluator, acceptance, debt-retirement, evidence-transition, or non-claim gates reject without state change; integration, evidence review, and rollback are terminal under arbitrary finite suffixes.",
      "status": "implemented",
      "outline_line": 8064,
      "module_path": "lean/AsiStackProofs/PrototypeRoadmap.lean"
    },
    {
      "chapter_id": "prototype-roadmap",
      "chapter_title": "Prototype Roadmap",
      "tag": "lean:roadmap.phases.fixture_gate_bridge",
      "module": "AsiStackProofs.PrototypeRoadmap",
      "formal_target": "The fixture bridge and independent consumer retain the public-safe route suite, reconstruct both transaction branches, and demonstrate that dependency and receipt counts alone cannot classify integration.",
      "status": "implemented",
      "outline_line": 8065,
      "module_path": "lean/AsiStackProofs/PrototypeRoadmap.lean"
    },
    {
      "chapter_id": "living-book-methodology",
      "chapter_title": "Living Book Methodology",
      "tag": "lean:living_book.methodology.operational_invariant",
      "module": "AsiStackProofs.LivingBook",
      "formal_target": "A finite manifest review with a present chapter but missing outline targets or claim placeholders is rejected.",
      "status": "implemented",
      "outline_line": 8129,
      "module_path": "lean/AsiStackProofs/LivingBook.lean"
    },
    {
      "chapter_id": "living-book-methodology",
      "chapter_title": "Living Book Methodology",
      "tag": "lean:living_book.methodology.failure_blocks_promotion",
      "module": "AsiStackProofs.LivingBook",
      "formal_target": "A finite structural update marked valid while either the scaffold or proof manifest is unsynchronized is rejected.",
      "status": "implemented",
      "outline_line": 8130,
      "module_path": "lean/AsiStackProofs/LivingBook.lean"
    },
    {
      "chapter_id": "living-book-methodology",
      "chapter_title": "Living Book Methodology",
      "tag": "lean:living_book.methodology.change_packet_boundary",
      "module": "AsiStackProofs.LivingBook",
      "formal_target": "A public-surface change packet requires validation, changelog, support-state, non-claim, derivative-boundary, and evidence-transition discipline.",
      "status": "implemented",
      "outline_line": 8131,
      "module_path": "lean/AsiStackProofs/LivingBook.lean"
    },
    {
      "chapter_id": "living-book-methodology",
      "chapter_title": "Living Book Methodology",
      "tag": "lean:living_book.methodology.reader_release_candidate_bridge",
      "module": "AsiStackProofs.LivingBook",
      "formal_target": "A current reader release-candidate route cannot treat local format evidence as approval while accessibility, audio, release-approval, or non-claim blockers remain.",
      "status": "implemented",
      "outline_line": 8132,
      "module_path": "lean/AsiStackProofs/LivingBook.lean"
    },
    {
      "chapter_id": "open-research-agenda-and-bibliography-plan",
      "chapter_title": "Open Research Agenda and Bibliography Plan",
      "tag": "lean:bibliography.plan.operational_invariant",
      "module": "AsiStackProofs.BibliographyPlan",
      "formal_target": "A source-derived claim with neither a source note nor an ingested artifact fails the finite source-evidence predicate.",
      "status": "implemented",
      "outline_line": 8213,
      "module_path": "lean/AsiStackProofs/BibliographyPlan.lean"
    },
    {
      "chapter_id": "open-research-agenda-and-bibliography-plan",
      "chapter_title": "Open Research Agenda and Bibliography Plan",
      "tag": "lean:bibliography.plan.failure_blocks_promotion",
      "module": "AsiStackProofs.BibliographyPlan",
      "formal_target": "An accepted new-source assignment to a nonexistent chapter fails the finite assignment predicate.",
      "status": "implemented",
      "outline_line": 8214,
      "module_path": "lean/AsiStackProofs/BibliographyPlan.lean"
    }
  ]
}
